The city of Mitchell, South Dakota, shut down part of its network Friday while investigating a potential cybersecurity incident, though officials said critical and emergency services remained operational.
The investigation surfaced amid conflicting accounts about city email. Davison County staff received an internal warning Friday telling them not to open messages from anyone with the city, according to an email obtained by the Mitchell Republic. The message said Tech Solutions had advised county employees to avoid city emails even if they were expected.
In a statement provided to the newspaper, Mayor Jordan Hanson said the city had “no indication that our email environment has been affected.” Hanson described the matter as a “potential cybersecurity incident” affecting a limited portion of the city’s network environment.
Hanson said the city “immediately shut down the environment as a precaution” and brought in forensic experts to determine the scope of the incident and restore operations in a safe and remediated network environment. He said critical and emergency services remained fully operational.
As of Friday evening, Mitchell had not publicly identified which systems were affected, what triggered the investigation or whether anyone gained unauthorized access to city data. Officials also had not disclosed an attack type, confirmed data theft, reported a ransom demand or identified a threat actor.
The city and Davison County websites remained accessible Friday evening. The county had not posted a public cybersecurity warning, and its directive to avoid Mitchell emails came from an internal message obtained by the Mitchell Republic.
Mitchell, a city of about 15,800 people, is roughly 65 miles west of Sioux Falls and is best known for the Corn Palace, a local landmark decorated with murals made from corn and other grains.
The city warned residents in February about fraudulent invoices sent by people impersonating Mitchell officials. That notice said legitimate city emails would come from the cityofmitchellsd.gov domain and showed examples using a different domain. The city has not linked that impersonation effort to Friday’s incident.
The Mitchell investigation comes amid other recent cybersecurity incidents involving South Dakota local governments.
Pennington County disclosed a cybersecurity incident in July that affected portions of its network and limited some public-facing services. Critical services remained operational, but the county is still recovering.
Rapid City disclosed a separate cyber incident July 31 involving a wastewater lift station. The incident was contained without disrupting water or wastewater service. It involved operational technology and came amid federal warnings about Iranian-affiliated targeting of internet-connected industrial systems and a coordinated campaign against municipal water systems in Minnesota.
Mitchell officials have not said how many systems were isolated, whether any information was compromised or when normal operations will be fully restored. The city said it would provide additional updates as more information becomes available.