Pennington County suffered a serious cyberattack in July, leading to security upgrades and a desire to help others learn from the experience. Mitchell also was hit.
RAPID CITY, S.D – Michael Iversen has spent the past three months doing anything and everything he can to prevent another workplace nightmare like the one inflicted upon him and his staff on July 4.
On that day, unknown hackers broke into and disrupted major elements of the government computer system in Pennington County, where Iversen serves as information technology director.
Get free, fact-based South Dakota news and information in a weekday email. No spam. Cancel any time.
The ransomware attack forced the county to shut down many systems, including communications and several public-facing services, though law enforcement, emergency operations and jail facilities remained largely operational.
Nearly all services are back online, but the attack thrust Iversen into a posture of crisis management that he remains immersed in to this day.
“You see something like this come in, and your brain is going a million miles an hour,” Iversen told News Watch in an interview. “It’s one of the worst things I’ve ever dealt with, and I wouldn’t wish this on my worst enemy.”
In the roughly 90 days since, Iversen has had two major goals — to bring county systems back online and to prevent or prepare for another attack – and he hopes other local governments can learn from Pennington County's experience.
Improvements made since the attack
While security protocols prevent him from being too specific, Iversen said he and other county officials have already implemented many new or improved measures to combat another attack. Among them:
- Rebuilding the entire county IT system with enhanced security at the forefront
- Increasing the depth and frequency of employee training, including requiring all county employees to change every password they were using prior to the attack
- Making preparations to hire a new full-time IT employee specifically assigned to strengthen security and monitor possible intrusions
- Implementing a SIEM, or Security Information and Event Management system, that centralizes all IT data and makes it easier to both analyze and protect
- Working with state cyberattack prevention officials at Secure SD to move to a government cloud storage system that is more safe and secure
- Switching the county operating systems to a .gov suffix, which stiffens security due to federal requirements to use the government domain system
Iversen said he has received strong support for the changes from employees and the Pennington County Commission but still doesn't know if or how much more funding might be required to stiffen cyber defenses.
“We’ve basically rebuilt our network from the ground up and redone all our security policies,” said Iversen, whose department has a staff of 13 and an annual budget of about $1.5 million. “The public probably won’t notice and the functionality will be there, but the county will not be the same as it was before.”
Several attacks in South Dakota and other states
The cyberattack on Pennington County was one of several that took place in a period of about a month this summer.
Rapid City fought off a brief attack on its wastewater systems, and the city of Mitchell dealt with a hack of some of its municipal computer systems. Around that same time, a major cybersecurity attack that sought to disrupt water systems in more than 30 communities across Minnesota.
South Dakota has been battling cyberattacks for years. Officials in Aberdeen found destructive malware installed on city systems in 2021. And last year, an employee in Tripp County was fooled by a hacker into sending more than $800,000 in municipal funds to a fake account.

Gov. Larry Rhoden on Sept. 30 declared October as Cybersecurity Awareness month in South Dakota with a theme of "Don't make it easy for them."
In a press release, the governor's office said, "Cybercriminals succeed most often when people skip small safety steps, so implementing secure habits is of utmost importance. Cybersecurity is not about making a single perfect choice, but about a series of daily choices that collectively make it harder for attackers to succeed."
The state Attorney General's Office told News Watch in August that over the past five years, the agency has had 1,062 online security breaches reported to its Consumer Affairs Division, including more than 125 so far in 2026.
Got a story idea, tip or question about something we should look into? Email at the link below. We won't share your ID without permission.
John Strand, owner of Black Hills Information Security, told News Watch that the attacks this summer in South Dakota, Minnesota and elsewhere probably originated from one of two sources: international organized crime groups that seek money from victims or international adversaries that either seek intelligence on U.S. networks and systems or intend to disrupt daily life in America.
Since county officials have not discussed any demands for ransom from the cyberattacker, it is more likely that a foreign adversary of the U.S. is behind the attack, Strand said.
"So then you're looking at Iran, you're looking at Russia, you're looking at China," Strand said in July.
Mayor: Only minor impacts in Mitchell breach
Citing a desire to stay ahead of potential attackers, government officials in areas that were attacked have declined to speculate on the location or nature of the perpetrators.
Mitchell Mayor Jordan Hanson told News Watch that even though the city was well-positioned to prevent a cyberattack, their systems were hacked nevertheless.
Hanson said the city’s systems were briefly infiltrated but that the damage was minimal and no emergency services or city finances were affected.
“It’s very common across the United States, and my speculation is that there’s people out there trying this constantly and it just takes the tiniest little opening for them to get in,” Hanson said. “Hopefully, like us, other cities have an experienced staff that is prepared to handle things.”

The city issued an update on the attack in a press release on Sept. 28, indicating that “we engaged both breach counsel and forensic specialists to help us in the response to this event.”
Hanson said the city has since taken several steps to bolster cybersecurity, but he declined to release specifics.
“There’s always room for improvement,” he said.
Iversen praised the cooperation that took place when Pennington County was hit, including assistance from the South Dakota National Guard, the South Dakota Fusion Center, the federal Department of Homeland Security and the FBI.
Iversen said he hopes other municipal government IT officials will contact him if they have questions about what happened in Pennington County, the response and how to prevent attack attempts almost everyone believes will come in the future.
"The amount of knowledge we’ve picked up in the past three months on cybersecurity has been amazing," Iversen said. "I really do want to use what happened as a positive to make sure that others don’t go through the same situation or if they do get hit, that they're better prepared to respond."

In an email, Iversen spelled out his advice to other municipal IT officers in South Dakota.
"Reach out your local fusion centers, even if you feel you have a really good understanding and are prepared, make those contacts, find out what resources are available that you can utilize in the event of an incident or before one occurs to help you find the exploits that could open you up to an attack," he wrote.
"The cybersecurity landscape is changing and adapting so quickly with new technology we all need to be proactive in keeping ourselves secure."
South Dakota News Watch is an independent nonprofit. Read, subscribe for free and donate at sdnewswatch.org. Contact content director Bart Pfankuch: 605-937-9398/ bart.pfankuch@sdnewswatch.org.


