Radio Silence: Pennington County Stopped Updating It’s Own Incident Page Three Weeks Ago

The seal of Pennington County

Rapid City SD – Pennington County has a dedicated page for its cybersecurity incident. It’s the county’s own words, posted by its own spokesperson, with timestamps. It’s also been silent since July 20 — even as the county kept talking to reporters about the same recovery.

The Official Record

The county disclosed the incident on July 5 and closed most public-facing offices the next day.

Its first detailed update, posted July 6 at 1:56 p.m., already put the essentials on the record: 911 dispatch, the jail, the Juvenile Services Center, the Care Campus, court operations, and the 24/7 Program all stayed fully operational throughout.

Media inquiries were directed to Katy Urban, public information officer for the State’s Attorney’s Office — the same spokesperson who has fielded questions from other outlets since.

From there, the page logged five more posts: a second update later on July 6, one on July 7, one on July 9, one on July 14, and a final one on July 20 describing a two-step process for Treasurer’s Office title transfers.

Every single entry gives essentially the same explanation for what isn’t being said: this is an active investigation, and the county can’t discuss specifics while it’s ongoing.

Nowhere in six weeks of updates does the county cite an insurance NDA, an operational-security rationale, or any other specific mechanism — that language exists elsewhere, but it isn’t the county’s own explanation.

July 20 is also the last entry. As of this writing — more than three weeks and several more rounds of visible recovery later — the county’s dedicated incident page hasn’t been updated again.

The Silence vs. The Reality

That’s notable because the recovery didn’t stop on July 20.

Coverage since then has described the Treasurer’s Office resuming full motor vehicle transactions in late July, and on Aug. 8, Commission Chair Ron Weifenbach told the Black Hills Pioneer directly that “most county services are now available again.”

Those updates reached the public — just not through the channel the county built for exactly that purpose. Whether that’s an oversight or a choice, it means anyone relying on the county’s own posted record is currently reading information that’s over three weeks stale.

One likely explanation for the gap turns up in the Board of Commissioners’ own agendas. “Operational Updates from Treasurer” appears as a standing agenda item for the first time on Aug. 4 — it isn’t on the July 7 or July 21 agendas.

That’s four days before Weifenbach’s comment to the Black Hills Pioneer. The recovery narrative may simply be circulating verbally, at the Board table, rather than through the page the county actually built to carry it to the public.

What the Agendas Give Away

While the incident page went quiet, the Board of Commissioners’ written agendas kept building a record — one that goes further than anything the county has said in public.

The clearest example: six separate zoning variance cases, filed by Charles and Cheryl Grosche, Hills West LLC (four separate applications), and Thomas Reher, were pulled from the July 21 agenda with an identical staff note: “Staff recommends continuing this item to the August 4, 2026 meeting due to ongoing County network issues.”

That’s Planning staff, in writing, attributing a specific delay in specific land-use cases directly to the cyberattack — sixteen days after the county first said it was investigating.

The same July 21 agenda shows the outage reaching two more corners of county government.

A “Facility Closure Policy” item has the Board weighing payroll and leave adjustments for staff affected by “the County’s operational disruption on July 6, 2026” — the county’s own internal date for when the disruption began, and a cost nobody outside the building has reported.

And the 2027 provisional budget item states plainly that “network issues throughout the County had limited staff’s ability to prepare budget figures and analysis,” forcing commissioners to build in a contingency: repurposing a scheduled July 29 planning workshop as a backup budget hearing if the numbers weren’t ready in time.

Then, on Aug. 4, the Board went into executive session for two reasons: a personnel matter, and an item titled “Emergency Management – Cybersecurity,” cited under SDCL 1-25-2(6) — the same statute the City of Rapid City cited a day earlier, on Aug. 3, for its own cybersecurity executive session.

Neither body’s closed-door session has produced a public accounting of what was discussed. County and city went behind closed doors on the same subject within 24 hours of each other, and neither has said why.

Separating Fact from Speculation

No federal agency has publicly named a suspect in the attack.

What’s on the record is an assessment from cybersecurity experts, reported by South Dakota News Watch, that the absence of a ransom demand makes a financially motivated actor less likely and points toward a state-linked one.

The New York Times, citing anonymous state and federal sources, reported Iran as a likely candidate on July 30. Neither is the same as a county or federal statement naming a foreign adversary.

The county has also never said, on the record, whether residents’ personal information was accessed — only that it will notify affected individuals directly if its ongoing forensic review finds that it was.

The Lingering Blind Spots

Two items have surfaced on the Rapid City side of the ledger that the county’s messaging — on or off its incident page — hasn’t touched.

While the cyberattack was strictly a county incident, the financial and operational fallout appears to be quietly bleeding into city government.

The Aug. 3 City Council consent agenda included a contract, not to exceed $36,250, with Kroll Associates for “Emergency Cybersecurity Assessments.” That item doesn’t explain its own connection to the county’s ongoing incident.

There’s also a hard contradiction to the Aug. 8 “most services are back” framing.

As of this writing — five weeks after the breach, and three weeks after the county’s own incident page stopped updating — the Equalization Department’s own page still carries a notice: “Due to a current cybersecurity incident affecting portions of our network,” both Property Search and “Public Access” remain unavailable. That’s not secondhand; it’s the county’s own site, live, right now.

Property Search itself, at property.pennco.org, doesn’t even return a graceful outage page — it returns a connection reset, meaning the server is refusing the connection outright rather than serving up a “temporarily unavailable” notice.

It’s also the same records system a rezoning review or a land transfer would ordinarily lean on.

A six-parcel agricultural rezoning batch this outlet has covered separately had its City Council second reading scheduled for Aug. 17, built on staff reports citing setbacks, easements, and non-conforming-use history — exactly the kind of detail Property Search exists to verify.

Separately, the roughly 22.65-acre Pete Lien land donation behind the city’s planned Sports Complex — a gift carrying a 20-year right of first refusal and covenants that bind future owners only once properly recorded — was approved before the outage began.

Whether its deed has been recorded since, with the county’s own public-access tools still down, isn’t something this outlet has been able to confirm.

The Outstanding Questions

  • Why did the county’s own incident page stop updating on July 20 while recovery, and public statements about it, continued?
  • What does the Kroll contract cover, and why did it come to a City Council vote — not a county one — on this timeline?
  • What was discussed in the City’s Aug. 3 and the county’s Aug. 4 cybersecurity executive sessions — cited under the identical statute, a day apart — and when, if ever, will either become public?
  • Did the six COVA variance cases actually get resolved at the Aug. 4 meeting once the “network issues” cited on July 21 had presumably eased, and were there other county business items quietly delayed the same way that never surfaced in an agenda note?
  • The county’s Equalization Department still lists Property Search and Public Access as unavailable as of Aug. 13 — five weeks in.
  • How is the city verifying parcel history for pending rezonings in the meantime, and has the Pete Lien donation’s deed and right-of-first-refusal actually been recorded?
  • When the investigation concludes, will the county publish findings anywhere beyond individual breach notifications — or will “active investigation” simply give way to no update at all?

Sourcing

Incident timeline, department-by-department updates, and county spokesperson identification from Pennington County’s own incident page (pennco.org, State’s Attorney’s Office), July 6–20, 2026, accessed Aug. 13. Equalization Department outage status per pennco.org/services/equalization and property.pennco.org, live as of Aug. 13, 2026. Board of Commissioners agendas for July 7, July 21, and Aug. 4, 2026 (pennco.community.highbond.com). Ron Weifenbach’s Aug. 8 statement as reported by the Black Hills Pioneer. Attribution reporting from South Dakota News Watch (July 31) and The New York Times (July 30). City Council agenda items and committee meeting record per this outlet’s own reporting.


Discover more from THE RAPID CITY SENTINEL

Subscribe to get the latest posts sent to your email.