The federal government has warned state and local agencies in the U.S. that cyberattacks by Iran, Russia or China are increasingly likely and that steps to improve security should be taken. "I think we’re cannon fodder in the Iran war."

Bart Pfankuch
Bart Pfankuch
Content Director
605-937-9398
bart.pfankuch@sdnewswatch.org

RAPID CITY, S.D. – Based on information released by authorities so far, two cybersecurity experts said it is likely that a malicious foreign entity is behind the recent cyberattack that crippled communications and other computer-based systems in Pennington County government.

Two federal agencies, meanwhile, have recently warned state and local governments across the U.S. that cyberattacks are increasingly likely, and that such attacks are likely to originate in Iran, China or Russia.

On July 5, Pennington County announced that a "cybersecurity incident" had occurred and affected parts of the county's computer network. The county shut down public access to government services for a day and has since embarked on a major multi-agency investigation. The county continues efforts to bring back communication and other computer-based systems.

"The biggest concern that I have is a cyberattack that leads directly to a loss of life or multiple people losing their lives. There needs to be a prioritization of security across all government entities and health entities."
– John Strand, owner of Black Hills Information Security, a Sturgis-based company that is an industry leader in cybersecurity

County officials said critical county services such as the sheriff's office, courts, 911 dispatch and jails have remained operational since the incident. Several county functions such as computer-based communications, internet access and providing record keeping and registration services to the public were slowed or otherwise affected by the incident and response.

Pennington County State's Attorney's Office spokeswoman Katy Urban, who is handling all media contacts during the investigation, told News Watch that the county is not discussing the incident or the subsequent investigation and is limiting public statements to those related to how residents can access government services.

"Unfortunately, there's not a lot I can say because it's an ongoing investigation," Urban told News Watch. "If anyone's personal information has been compromised, we will contact them directly as required by state law."

Likelihood a foreign government is behind it

Elements of the cyberattack point to an adversarial foreign government as the responsible party, said John Strand, owner of Black Hills Information Security, a Sturgis-based company that is an industry leader in cybersecurity.

Strand told News Watch in an interview that cyberattacks on American government entities typically originate from one of two sources: international organized crime groups that seek money from victims or international adversaries that either seek intelligence on U.S. networks and systems or intend to disrupt daily life in America.

Since county officials have not discussed any demands for ransom from the cyberattacker, it is more likely that a foreign adversary of the U.S. is behind the attack, Strand said.

"So then you're looking at Iran, you're looking at Russia, you're looking at China," Strand said. "Most of the time, they want to dwell (within the system) and to gain access to critical infrastructure, and they want to maintain access for as long as they possibly can."

A line of about three dozen people waited to obtain in-person services from the Treasurer's Office at the Pennington County Administration Building in Rapid City, S.D., on July 28, 2026. (Photo: Bart Pfankuch / South Dakota News Watch)

The New York Times on July 30 quoted anonymous state and federal sources in an article indicating that Iran is the likely culprit of a major cybersecurity attack that sought to disrupt water systems in more than 30 communities across Minnesota in late July. The Times said federal officials were concerned the cyberattacks could be a new salvo by Iran in its ongoing war with the United States.

The goal of a dwell is to gain access to a system, stay there as long as possible and gain intelligence about how American systems work or where vulnerabilities may lie, Strand said.

"If you're looking at Iran, though, right now because we are in a hot conflict, their motivations would be very different," he said. "They may want to gain access and cause immediate damage to get the press around what they were able to do in the United States."

Get free, fact-based South Dakota news and information in a weekday email. No spam. Cancel any time.

Subscribe

A more aggressive cyberattack could not only disrupt critical services in the U.S. but could interfere with systems that keep people safe, Strand said.

For example, a cyberattacker could contaminate or limit access to drinking water, send sewage to places it shouldn't go, disrupt medical or prescription drug information or even affect safe operation of traffic lights, he said.

"The biggest concern that I have is a cyberattack that leads directly to a loss of life or multiple people losing their lives," Strand said. "There needs to be a prioritization of security across all government entities and health entities."

Minnesota water systems suffer cyberattack

On July 28, Minnesota officials announced that a "coordinated cyberattack" had targeted computerized operational systems at more than 30 municipal water systems in the state, disrupting processes in at least five communities.

The city of Braham, about 70 miles north of Minneapolis, told residents that the city water system was offline for about two hours on July 27 due to a "malicious cyberattack of computerized operating systems by unknown actors."

The city reported that the attack did not affect water quality and that the city was able to maintain uninterrupted service.

"This attack did not alter or cause any issue to the physical water plant or water quality or safety," the city said in a press release. "Rather, the attackers shut down the operating controls which shut down the well and water treatment plant, causing the city to provide water to residents with only water held in the water tower."

"I think we’re cannon fodder in the Iran war. It's like they're trying to send a message that they can attack us from halfway around the world."
– Bryce Austin, a cybersecurity expert and the CEO of TCE Strategy

No water quality issues or use restrictions arose as a result of the attack, the state said. The Minnesota IT Services (MNIT) department said it is working with a wide range of state and federal partners to investigate the attack and bolster security against future incidents.

"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," John Israel, MNIT assistant commissioner and state chief information security officer, said in a July 28 news release.

"This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services.”

Federal agencies raise increasing concerns

The South Dakota and Minnesota cyberattacks came amid warnings by a pair of federal agencies about the increased risk of cyberattacks on critical infrastructure systems, including local drinking water and wastewater systems.

In May, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) warned that infrastructure systems that use programmable logic controller systems and which rely on the internet for communication or control were under increasing threat of cyberattack.

An updated CISA bulletin in July expanded the scope of the concern to "urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology."

The advisory said attacks could occur "through malicious project file interactions and manipulation of data."

A television that was offline at the Pennington County Administration Building in Rapid City, S.D., on July 28, 2026. (Photo: Bart Pfankuch / South Dakota News Watch)

As far back as May 2024, the federal government issued warnings about potential cyberattacks on U.S. water systems and lax security systems in place at community water systems. An Environmental Protection Agency alert noted that attacks were likely to come from the Iran government's Islamic Revolutionary Guard and state-sponsored bad actors in Russia or China.

"Cyberattacks against (community water systems) are increasing in frequency and severity across the country," the EPA said at the time. "Based on actual incidents we know that a cyberattack on a vulnerable water system may allow an adversary to manipulate operational technology, which could cause significant adverse consequences for both the utility and drinking water consumers. Possible impacts include disrupting the treatment, distribution, and storage of water for the community, damaging pumps and valves, and altering the levels of chemicals to hazardous amounts."

The EPA said previous inspections found "alarming cybersecurity vulnerabilities at drinking water systems across the country" that included poor password usage, single login access to the system and failure to properly lock out former employees.

Vulnerabilities found in county governments

County governments in particular may be highly vulnerable to attack for a number of reasons, including a high amount of information held within systems that are often understaffed and may not have sufficient system protections in place.

A January 2025 article in the Journal of Cybersecurity drew upon a University of Maryland study that examined security risks at nearly 3,100 county governments in the U.S. – including those in South Dakota – and found worrisome gaps on cybersecurity.

County governments need greater cyber protection systems and improved employee processes because counties are often responsible for providing water, policing, education and elections, and possess significant personal and financial information about residents.

"The consequences of poor cybersecurity at the local level can be disastrous," the authors concluded. "Given their impact on society, documented gaps in county government cybersecurity are alarming," the authors wrote.

'Cannon fodder' in the ongoing war?

Both governments and private industry should expect more cyberattacks in the future as more public services and commerce are conducted online and through computer networks, said Bryce Austin, a cybersecurity expert and the CEO of TCE Strategy, a Minnesota-based firm that provides cybersecurity protection and compliance services.

The "one-two punch" of cyberattacks in South Dakota and Minnesota within the same month is concerning but not overly surprising, he said.

Several signs point to cyberattacks by Iran, which may be trying to make a statement as it continues to battle the U.S. in war, Austin said.

"I think we’re cannon fodder in the Iran war," he said. "It's like they're trying to send a message that they can attack us from halfway around the world."

"We better get used to it because this is the new normal."
– John Strand, owner of Black Hills Information Security

Russia tends to seek disruptions of American systems for political or military purposes while China often seeks intelligence that can help its economy or competitiveness in the global marketplace, Austin said.

Federal, state and local government agencies need to invest in stronger systems protections, employee training and larger IT workforces to potentially prevent future attacks, he said.

"You don’t need your county infrastructure to have perfect cybersecurity," Austin said. "It just needs to be significantly more difficult to hack than many other counties."

Strand, who launched his family-run company in his basement near Deadwood in 2008, has grown the firm to 160 employees who conduct 950 security assessments annually across the world.

He complimented Pennington County on how it has handled the security breach so far but said it would be a "tragic mistake" if the county doesn't release a full accounting of the attack and its response at some point.

"Just trying to hide it and bury it is almost always the wrong answer, and I'm hoping with these other breaches that we're seeing they will release information so that this can get fed back into the broader ecosystem, so everyone can learn," Strand said. "We better get used to it because this is the new normal."

South Dakota News Watch is an independent nonprofit. Read, subscribe for free and donate at sdnewswatch.orgContact content director Bart Pfankuch: 605-937-9398/bart.pfankuch@sdnewswatch.org.