Skip to content

Pennington County cyber incident disrupts offices

Summary

Pennington County, South Dakota logo

Pennington County identified a cybersecurity incident by July 5, 2026, closing most public-facing offices July 6 before staged reopening. Recovery remained incomplete August 31, when network service was still unavailable at some remote locations and the Wall Treasurer’s satellite office was expected to remain closed throughout September. Some employees told not to report July 6 had to use accrued leave or take unpaid time because the county did not formally declare an emergency closure, and commissioners voted September 1 against making an exception; data impact, ransomware and attribution remain unresolved.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Staff sent home or placed on leave

    Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that a cybersecurity incident affected portions of Pennington County, South Dakota’s government network by July 5, 2026. The county closed most public-facing offices July 6 and reopened them July 7 with limited services while investigators and responders restored systems in a remediated environment.

July 5 is the earliest supported identification and public cyber-disclosure date, not a confirmed intrusion-start date. The public record does not establish when malicious activity began or identify the initial access vector, malware family or specific attack mechanism.

Operational significance

The incident caused a material county-government disruption. Most public-facing offices closed July 6, then reopened July 7 while core administrative functions remained constrained. Vehicle registrations, payments, lien processing, real-estate recording, permits and property-record access were among the affected functions. Residents were directed to state systems, kiosks, online vital-record services and neighboring counties, while staff used manual workarounds.

Critical continuity was preserved. The county repeatedly said 911 dispatch, the jail, Juvenile Services Center, Care Campus, emergency response, courts, the 24/7 Program and early voting remained operational. The evidence supports substantial administrative disruption, not a countywide public-safety shutdown.

The effects extended beyond county offices. KOTA reported that Rapid City temporarily disabled online utility payments and slowed building-permit processing while reviewing shared infrastructure, although city officials said there was no indication its systems were compromised.

County records also establish a direct workforce and financial consequence from the initial shutdown. A countywide notice told employees not to report July 6 and to contact their supervisors while the network remained offline. County leaders nevertheless did not formally invoke the Emergency Facility Closure policy, and the board chair later said he had not intended to declare one. That procedural distinction meant the policy did not automatically provide qualifying nonexempt employees with paid closure leave or qualifying employees who worked with time-and-a-half pay. Under the ordinary payroll treatment, affected employees instead had to use accrued leave or take the time unpaid.

A Sept. 1 memorandum estimated up to $32,500 in accrued leave used and up to $10,500 in unpaid time; those figures were directional because the county lacked a centralized scheduling record for the review. Staff presented four choices balancing existing policy, employee equity, administrative feasibility, cost and stewardship of public funds. The options ranged from retaining the $0 existing treatment to targeted restoration of leave and wages estimated at $43,000, emergency-closure compensation of up to $88,000 or a broader administrative-leave remedy illustrated at $133,000.

The Rapid City Journal reported that commissioners selected the no-change option 3-2 on Sept. 1. Supporters argued that paying employees who stayed home could be unfair to the estimated 75% who reported and that time-and-a-half for employees performing regular work was also inappropriate; the chair cited the county’s existing leave and vacation benefits. State’s Attorney Lara Roetzel supported relief, emphasizing that employees had been told not to report and that losing even one day of leave or wages mattered to workers living paycheck to paycheck. A narrower proposal to restore used leave and compensate unpaid hours without time-and-a-half failed 2-3. The decision therefore left the documented leave and wage losses with affected employees despite the countywide instruction not to report.

The county’s service document, originally published July 27 and marked updated Aug. 12, showed substantial but incomplete recovery. Its revised introduction said all county offices were open and operational, but a few services remained limited and processing could take longer as systems were safely restored. Because the page did not identify which individual bullets changed Aug. 12, DysruptionHub treats that date as general continuing-impact evidence without assuming every listed constraint was reconfirmed then.

Later reporting established that recovery remained incomplete. South Dakota Searchlight reported Aug. 24 that residents still could not access some services. On Aug. 31, KOTA reported that county network service had not been restored at some remote locations and the Wall Treasurer’s satellite office was expected to remain closed throughout September. The main Treasurer’s Office in Rapid City remained open, and some motor vehicle transactions were available through state online services and four Rapid City kiosks.

Current status

The operational incident remains active. A Sept. 14 NewsCenter1 report said PulsePoint remained unavailable and county information technology staff were coordinating restoration, while 911 response remained uncompromised. Sept. 14 is the latest supported operational-impact date. No countywide restoration notice or final all-clear was found through the Sept. 20 research cutoff.

Disclosure posture

Pennington County directly confirmed the incident and issued service updates, while withholding technical and investigative details. Its communications distinguished continuing critical services from disrupted administrative functions and said analysis of possible personal-information effects remained underway. This affected-organization-first sequence supports OC-OD classification.

Confidence and uncertainty

Confidence is high that malicious or unauthorized cyber activity caused material disruption because the county confirmed the cybersecurity incident and tied closures, system restoration and service limitations to it. Confidence is high that operational impact continued Aug. 31 because two local reports attributed the remote network outage and Wall office closure to county officials, and one quoted Pennington County Treasurer Annette Brant.

Confidence is high that the July shutdown affected employee leave and wages because the county’s own memoranda document the notice not to report, the absence of a formal emergency closure and estimated accrued-leave and unpaid-time losses, while the Rapid City Journal documented the commission’s decision and competing rationales. The record does not establish how many employees were affected or the final aggregate losses.

Data impact, ransomware and threat-actor attribution remain unresolved. No reviewed source establishes encryption, a ransom note, an extortion demand, data exfiltration, data publication, payment or a named actor.

Analytic gaps

The public record does not establish the intrusion start, dwell time, initial access vector, compromised account or host, exploited vulnerability, malware family, persistence method, affected-system inventory or technical root cause. It does not disclose whether personal information was accessed, copied or removed, which data categories were reviewed or how many people might be affected.

The public record also does not identify every remote location still lacking network service, provide a reopening date for the Wall satellite office or establish when every county service will return to normal. It does not quantify the employees affected by the July 6 work directive or establish final leave and wage losses. No public source establishes ransomware or extortion, a threat actor, demand or payment, recovery cost or the restoration method for individual systems.

Organizations involved

Impacted locations

Sources

Pennington County SD offices close amid cyber incident

Pennington County closed most public-facing offices during a cybersecurity response while critical public-safety, jail, court, election and selected registration services continued.

Pennington County Responding to Cybersecurity Incident

On August 18, Pennington County’s live homepage still stated that some services were unavailable because of the cybersecurity incident and directed residents to the current service notice.

Rapid City reviewing systems after Pennington County cybersecurity incident

KOTA reported that Rapid City reviewed systems because it shares some infrastructure with the county. The precaution temporarily disabled online utility payments, slowed permit processing and required manual receipts, although officials said there was no indication city systems were compromised.

Responding to Devastation

Gov. Larry Rhoden said July 10 that the South Dakota National Guard and Bureau of Information and Technology were assisting Pennington County through the cybersecurity incident and that the investigation remained underway.

Pennington County Responding to Cybersecurity Incident

The county’s consolidated notice documents the July 6 closure, July 7 reopening with limited services, staged restoration through July 14, continuing security validation and monitoring, and an ongoing assessment of whether personal information was affected.

Pennington County Provides Update on County Services During Cybersecurity Response

The county service page is dated July 27 and visibly marked ‘Updated on August 12, 2026.’ Its revised introduction says all county offices remain open and operational, but a few services remain limited and processing times may be longer as systems are safely restored. The page lists restored motor-vehicle and real-estate access alongside continuing limitations involving online real-estate payments, lien payments, real-estate recording, property-record access, processing times and a 4-H telephone line.

South Dakota's cybersecurity program running out of time, money as local governments face attacks

South Dakota Searchlight reported on August 24 that Pennington County residents still could not access some services after the July cyberattack. The report did not identify the unavailable services.

Wall Treasurer’s Office to Remain Closed During Cybersecurity Recovery

News Radio KOTA reported Aug. 31 that the Pennington County Treasurer’s satellite office in Wall would remain closed throughout September because network services had not been fully restored at some remote locations. The main Rapid City office, some state online services and four Rapid City kiosks remained available.

Wall Treasurer’s Office to remain closed through September following cyber incident

KOTA reported Aug. 31 that county network services had not been restored at some remote locations and that the Wall Treasurer’s satellite office would remain closed throughout September. County Treasurer Annette Brant apologized for the inconvenience; officials gave no reopening date.

July 6 Facility Closure Update

A Sept. 1 county memorandum says the countywide direction not to report July 6 did not qualify automatically for Emergency Facility Closure benefits because no authorized formal closure had been declared. Staff estimated up to $32,500 in accrued leave used and $10,500 in unpaid time and presented four options: no changes at $0; targeted leave and wage restoration at about $43,000; emergency-closure compensation up to $88,000; or broader administrative leave illustrated at $133,000.

Pennington County employees told to stay home after cyberattack will lose vacation time or go without pay

The Rapid City Journal reported that commissioners chose the no-change payroll option 3-2 on Sept. 1. Supporters cited fairness to the estimated 75% of employees who worked, objections to time-and-a-half for regular work and the county’s existing leave benefits. A proposal to restore leave and compensate unpaid hours without time-and-a-half failed 2-3; State’s Attorney Lara Roetzel supported relief because employees had been told not to report and a one-day loss mattered to workers living paycheck to paycheck.

See something that needs correction?

Signed-in members can report an error, update, or missing source.