Recent security hacks on local governments in South Dakota are latest of more than 1,000 in the state over past five years.
South Dakota turned down millions of dollars in federal cybersecurity grants and instead is spending more than $7 million in state taxpayer funds to battle what has become a constant threat of attacks on computer systems used by government, industry and individuals.
In addition to recent high-profile cyberattacks on government operations in Pennington County, Rapid City and Mitchell, the South Dakota Attorney General's Office receives frequent reports of digital information breaches.
Over the past five years, the agency has had 1,062 online security breaches reported to its Consumer Affairs Division, including 127 so far in 2026, according to agency data.
Get free, fact-based South Dakota news and information in a weekday email. No spam. Cancel any time.
Those breaches include data hacks perpetuated on individuals, businesses and government entities, according to AG spokesman Tony Mangan, who responded to a News Watch request. State law prevents the public release of where or upon whom those breaches took place, Mangan said.
But the frequency at which data and systems are being infiltrated illustrates the increasing risk of storing important personal and government information online at a time when experts say nefarious actors are constantly trying to hack into computer systems across the U.S., including in South Dakota.
"We are always under a constant threat, and we are always mitigating something somewhere," said Mike Waldner, director of SecureSD and Project Boundary Fence, the state's two main cyber security prevention programs operated out of Dakota State University in Madison. "We always have an active case that we're working on."
South Dakota attacks renew focus on security
Recent cyberattacks on local governments have only heightened concerns that systems are being targeted by either organized crime groups seeking ransom or by foreign adversaries such as Russia, China or Iran, which is currently engaged in a war with the United States.
Experts theorize that Iran-backed hackers are responsible for large-scale cyberattacks on communication systems in Pennington County and the city of Mitchell as well as breaches into water systems in Minnesota and possibly up to a dozen more states.

Public-facing systems in Pennington County such as treasurer payment systems are still slowly coming online after a debilitating cyberattack that took place in early July. The Rapid City sewer system also suffered an attempted cyberattack in mid-July, but it did not interrupt services.
The cyber incident in Mitchell involved a hack of the city's email system in early August, causing some city meetings to be postponed and email systems to remain unreliable.

The frequency of recent attacks on government systems only highlights the need for strengthening of prevention systems and better employee training, Waldner said.
"It's ongoing, almost a daily process because the bad actor only needs to be right once while we need to be right every time (to prevent them)," he said.
Noem rejected federal assistance
South Dakota lost out on at least $5 million and likely much more in federal funding for cybersecurity efforts by cities and counties when former Gov. Kristi Noem declined to apply for part of a $1 billion federal grant program in fiscal year 2023.
Ian Fury, a spokesman for Noem at the time, said the funding from the Biden administration was wasteful and required the state to use one-time funding to create a long-term program.
Some lawmakers, including Republicans, decried the decision by South Dakota, which was one of only two states to reject the funding that was allocated over a four-year period.
"Like it or not, as a government employee, you are under constant threat, and the expectation from citizens is that you are protecting their data and information like they expect it to be protected." – Mike Waldner, director of SecureSD and Project Boundary Fence
“If we’re not going to accept the grant, then we’ll legislate an appropriation on a similar program and use South Dakota taxpayer money to do it instead because it’s so important,” Sen. Randy Deibert, a Republican from Spearfish, told a legislative summer study committee in 2023.
Instead, state lawmakers allocated $7 million to cybersecurity prevention efforts that include SecureSD and the Project Boundary Fence, both programs aimed at preventing and mitigating hacks on state, county and local governments as well as utilities.
Gov. Larry Rhoden on Aug. 11 appropriated $500,000 in Future Fund money to the South Dakota Department of the Military to boost efforts of the Governor's Resilience and Infrastructure Task Force, of which cybersecurity is one objective.
"The GRIT Task Force is bringing together government, industry, and critical infrastructure partners to better understand the risks we face and how we prepare for them," Mark Morrell, adjutant general of the South Dakota National Guard and vice chair of the task force, said in a press release.
Costly attacks not new to South Dakota
The first high-profile cyberattack on a municipal government in South Dakota took place in Brown County in August 2021. Officials in Aberdeen discovered that an unknown external actor had installed malware on county computers in an apparent attempt to collect information that could be used as leverage to collect ransom money.
The breach occurred when a county employee mistakenly clicked on an email link that opened the door to the attacker. The county completely shut down its systems and remained offline for 10 days. No ransom was paid and no sensitive county or resident information was apparently lost, but the county lost access to some backup data and a few departments were disrupted for months during the response and investigation.
More recently, in October, someone working in Tripp County government was caught up in an email "phishing" scam and mistakenly sent more than $826,000 in taxpayer money to a fake account.
"The Tripp County Auditor’s Office was deceived into authorizing a transfer to a bank account controlled by external criminal actors," according to a January press release. "The perpetrators utilized a 'spoofed' email address designed to mimic a legitimate vendor and redirect a substantial payment."
The South Dakota Division of Criminal Investigation is working with federal agencies on an investigation into the incident, the release said. To date, the funds have not been recovered.
Tripp County State’s Attorney Zachary Pahlke said in January that the county was working on strengthening internal systems and expanding employee training to reduce future risks of hacks or attempted financial impropriety.
"Updates to county protocols, combined with additional staff training, are designed to intercept and prevent fraudulent attempts and better protect the resources of Tripp County taxpayers," Pahlke said in the release.

Rapid City technology staffers quickly contained an attempted hack on a sewage lift station monitoring system in late July, IT director Jim Gilbert said. No system interruption took place and movement of wastewater was not affected, he said.
Gilbert said the city computer system has redundancies built in to notify system regulators and stave off implications of attacks if they occur. Creating a secure system requires a delicate balance between safety and usability, Gilbert said.
"Anything that connects to the internet or is connected to a system that is connected to the internet is under constant attack," he said. "We can make every system completely secure, but then it's probably not usable by our employees or the citizens."
State programs offer help to local governments
For the past few years, the state has funded two separate but aligned efforts to prevent cybersecurity attacks under the auspices of Dakota State University in Madison.
SecureSD and Project Boundary Fence both seek to combat cyber attacks and data breaches at municipalities, counties, and nonprofit entities providing drinking water and sewer utilities across the state. Funding for the programs was approved by the Legislature in 2024 at $7 million.
SecureSD is a voluntary program in which public entities receive training and support in email and data security, enhancement of security and mitigation efforts and cybersecurity training and planning, said Waldner, who runs both programs from his office at DSU.

Emails systems are the most likely target and easiest entry point of a cyberattack, so security efforts place a strong focus on protecting electronic communications, Waldner said.
In one component of Project Boundary Fence, the state sends bogus "phishing" emails to employees of governments that participate.
If a fake malicious link is opened, the employee and the state receive notice that security could have been breached and additional security training is provided. That comes on top of a review of email passwords, system firewalls and security procedures.
If any security deficiencies are found, the state pays independent IT contractors to fix the problem and mitigate any future issues, Waldner said.
The program also provides cybersecurity training and planning to participating managers and employees to reduce the risk of an attack, he said.
A secondary goal of cybersecurity efforts within state and local government is that safety protocols will propagate and be implemented by businesses and individuals, Waldner said.
Government employees have a responsibility to maintain the security of information of individuals, who often have no choice but to provide personal data and information to state, county and local agencies, he said.
"We're trying to build that cybersecurity culture and secure what we call the 'human firewall,'" Waldner said. "Like it or not, as a government employee, you are under constant threat, and the expectation from citizens is that you are protecting their data and information like they expect it to be protected."
The program is voluntary and has had more than 100 government agencies participate so far, including about 54 of South Dakota's 66 counties.
"That may seem like a lot, but it's not because it should be everybody," Waldner said.
Much more needs to be done, including in rural areas where an attack may seem unlikely but which can portend a larger breach into state government or even local businesses, he said.
Resistance to paying for cybersecurity at the local level often comes down to a shortage of staff, a feeling that attacks will always happen to someone else, and a lack of public support for funding of prevention, Waldner said.
"With cybersecurity, it's hard for commissioners and elected officials to write that check because nobody sees it, unlike buying a new fire truck or fixing potholes," he said. "But they'll certainly know if a compromise happens or a breach happens, then they certainly know about it, because we'll all feel that pain and have to pay for the losses."
South Dakota News Watch is an independent nonprofit. Read, subscribe for free and donate at sdnewswatch.org. Contact content director Bart Pfankuch: 605-937-9398/bart.pfankuch@sdnewswatch.org.

