Pennington County Cyberattack Highlights Growing Threat to U.S. Local Governments
On July 5, Pennington County, South Dakota, fell victim to a cyber‑attack that rattled its computer network, forcing the county to shut down public access to government services for an entire day. While investigators worked to restore communications and other computer‑based systems, essential functions—such as the sheriff’s office, courts, 911 dispatch, and jail operations—remained online.
County officials said that, although the sheriff’s office, courts, 911 dispatch and jail operations stayed operational, computer‑based communications, internet access and public record‑keeping were slowed or otherwise affected. The county’s State Attorney’s Office, represented by spokeswoman Katy Urban, confirmed that the investigation is ongoing and that residents whose personal information may have been compromised will be notified directly.
Cybersecurity experts John Strand of Black Hills Information Security and Bryce Austin of TCE Strategy both pointed to a foreign adversary as the likely culprit. Strand explained that U.S. government entities are typically targeted by either organized‑crime groups seeking ransom or state actors seeking intelligence or disruption. Because no ransom demand has been made, he believes a state actor—most likely Iran, Russia or China—is responsible. He added that such actors often aim to “dwell” within a system, staying long enough to gather intelligence on vulnerabilities, and warned that a more aggressive attack could compromise critical services such as water, medical records or traffic control, potentially leading to loss of life.
The Pennington County incident is part of a broader pattern of cyber threats to local governments. In May, the Cybersecurity & Infrastructure Security Agency (CISA) warned that programmable‑logic‑controller systems and internet‑connected operational technology were increasingly vulnerable. A July CISA bulletin expanded the threat to include “ongoing Iranian‑affiliated cyber targeting of internet‑connected operational technology,” noting that attacks could occur through malicious project files and data manipulation.
The Environmental Protection Agency (EPA) has also highlighted the risk to water systems. In May, the EPA issued an alert that attacks were likely to come from Iran’s Islamic Revolutionary Guard, as well as state‑sponsored actors in Russia or China. The agency cited the potential for attackers to manipulate operational technology, damaging pumps, valves or chemical levels.
These federal warnings were followed by a real‑world example in Minnesota. On July 28, officials announced that a coordinated cyberattack had targeted computerized operating systems at more than 30 municipal water systems, disrupting processes in at least five communities. The city of Braham, about 70 miles north of Minneapolis, reported that its water treatment plant was shut down for about two hours on July 27. The attack did not affect water quality; the city was able to maintain service using stored water.
Minnesota’s IT Services department said it was working with state and federal partners to investigate the incident and strengthen security. Assistant Commissioner John Israel emphasized that the response demonstrated the importance of strong cybersecurity capabilities and partnerships.
The pattern of attacks underscores a broader vulnerability among county governments. A 2025 study of nearly 3,100 U.S. counties found significant gaps in cybersecurity, including poor password practices and single‑login access. County governments often hold large amounts of personal and financial data and provide essential services, making them attractive targets.
Experts say that the frequency and severity of attacks on local infrastructure are increasing. They urge that local, state and federal agencies invest in stronger systems protection, employee training and larger IT workforces. While perfect security is unattainable, they argue that making systems significantly harder to hack is essential.
At present, Pennington County is still restoring services and cooperating with investigators. The incident, along with the Minnesota water system attacks, illustrates the growing risk that foreign state actors pose to critical local infrastructure. The federal government’s warnings and the recent incidents suggest that cyberattacks on local governments will become more common, and local agencies are urged to review their security posture and prepare for potential future threats.