Skip to content

Rapid City, South Dakota, reports cyber incident at wastewater lift station

Officials said the attempt was detected quickly and did not jeopardize water or wastewater systems; federal agencies warned of incidents in at least seven states.

Aerial view of a white water tower marked “Rapid City,” with neighborhoods and green hills in the background.
A Rapid City water tower overlooks neighborhoods in Rapid City, South Dakota. (Photo by Zach Shenkin)

Officials in Rapid City, South Dakota, said they quickly detected an attempted cyber intrusion involving a wastewater lift station and took precautions. The city said its water and wastewater systems remained safe.

The city disclosed the incident July 31 as federal agencies issued a nationwide warning about attacks on internet-connected industrial controllers used by water utilities. Rapid City operates eight wastewater lift stations as part of its sewer system.

The city said its drinking water supply remained safe. Its Facebook post did not identify the targeted station or say when the attempt occurred.

Rapid City said it was working with the Cybersecurity and Infrastructure Security Agency and other federal agencies.

“We want to assure residents our city water system remains safe,” Rapid City Public Works Director Mike Theis said in the release.

Rapid City said in a July 31, 2026, Facebook post that officials quickly detected a cyber incident involving a wastewater lift station and that the city’s water and wastewater infrastructure remained safe. (Screenshot by DysruptionHub)

The FBI and Environmental Protection Agency said Thursday that water and wastewater utilities in at least seven states had reported incidents since July 27, some of which degraded operations.

The agencies said attackers remotely changed network addresses and passwords on internet-facing programmable logic controllers, industrial computers that automate equipment. Some operators lost monitoring or control. Reported effects included pressure loss and flooding.

Minnesota officials said a coordinated cyberattack targeted operational technology at more than 30 community water systems July 26 and 27.

In Plymouth, a suspected cyberattack disrupted cellular communications at two water towers and multiple wastewater lift stations, forcing crews to use manual procedures. Maple Plain and South St. Paul also reported incidents affecting automated utility controls. All three cities said water service and quality were unaffected.

Braham reported a more substantial disruption. Officials said a malicious cyberattack disabled computerized controls and briefly shut down the city’s well and water treatment plant before crews restored operations about two hours later.

Officials have not publicly linked Rapid City to the Minnesota cases or identified a shared attacker, device, technology provider or vulnerability. Braham called its incident a cyberattack, Plymouth said it suspected one, and Maple Plain and South St. Paul did not identify an attack method.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The New York Times, citing U.S. officials and investigators reviewing the matter, reported that hackers linked to Iran were likely behind the Minnesota attacks. The newspaper said Iran’s role had not been confirmed and that investigators were considering whether the attackers could have been posing as Iranian. Rapid City did not connect its incident to Minnesota or any threat actor.

Separately, Rapid City, the Pennington County seat, reviewed its municipal systems after the county government reported a cybersecurity incident earlier in July. Because the two governments share some technology infrastructure, the precaution temporarily disabled online utility payments and slowed building permit processing. The city said there was no sign its systems had been compromised.

The county incident initially closed most public-facing offices, while 911 dispatch, jail operations, courts, early voting and other critical services remained available. By July 27, all county offices had reopened, although some systems remained limited and county email was still unavailable.

Officials have not publicly linked the Pennington County incident to the wastewater attempt.

Rapid City has not disclosed how the attempt was made, whether system settings or data were accessed or altered, or whether investigators have identified a responsible party. The city has not reported ransomware or a ransom demand.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all