What We Know – and Don’t Know – About Rapid City’s Water Infrastructure Cyber Incident

Rapid city municipal government building

Rapid City SD- The City of Rapid City recently disclosed a cyber incident involving one of its lift stations, part of the city’s wastewater system.

According to the city, officials discovered the attempt quickly and took precautions to protect the system. The city says at no time was its water or wastewater infrastructure placed in jeopardy, and that the water supply remains safe.

Rapid City is working with the Cybersecurity and Infrastructure Security Agency (CISA) and other federal partners.

“We continually take steps to ensure the continued security and reliability of our water and wastewater systems,” Public Works Director Mike Theis said in the release, adding that the city remains vigilant in monitoring for cyber attacks across city systems. Officials say they cannot discuss specific details while the investigation is ongoing.

Not an Isolated Case

The timing puts this in a much bigger national picture.

On July 26 and 27, a coordinated cyberattack disrupted operational technology at more than 30 community water systems across Minnesota, with confirmed impacts in at least five communities.

In Braham, the water treatment plant went offline for roughly two hours after attackers shut down its operating controls, leaving the city to rely on water already held in its tower.

Plymouth reported disruptions to communications at water towers and multiple lift stations — the same type of facility involved in Rapid City’s incident.

Maple Plain’s city council declared a local state of emergency in response.

State and city officials in Minnesota have consistently said drinking water quality was never compromised and that manual operating procedures kept services running throughout.

A Federal Warning that came Just Before

CISA, the FBI, and the EPA had already warned in April — and updated that warning on July 22, days before the Minnesota attacks — that Iranian-affiliated actors were targeting internet-facing industrial controllers used by water utilities.

CISA’s acting director, Nick Anderson, said the agency is “currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” and urged operators to remove those controllers from direct internet exposure entirely.

The Iran Question

Multiple national outlets, citing anonymous U.S. officials, have reported that intelligence agencies assess Iran is likely behind the Minnesota attacks.

Officials are careful to note the attribution isn’t confirmed and could change as more evidence comes in — investigators are also examining whether the actor deliberately mimicked known Iranian tactics to inflame tensions during the ongoing U.S.–Iran war, a conflict now in its fifth month with strikes traded on both sides and American service members killed.

There is precedent for the Iran theory: in 2023, hackers affiliated with Iran’s Islamic Revolutionary Guard Corps breached water authority equipment in Aliquippa, Pennsylvania, by exploiting internet-connected controllers left on default passwords.

Seven States, Unnamed

The FBI says water and wastewater utilities in at least seven states have reported similar incidents this week.

As of this writing, neither the FBI nor any news organization covering the story has identified which seven states.

That means it is currently unknown — and not something this outlet or any other can confirm — whether South Dakota is among them. Any connection between Rapid City’s lift station incident and the broader seven-state pattern is, right now, a matter of timing and shared target type, not a confirmed link.

Pennington County’s Separate Incident

Rapid City’s lift station disclosure comes amid an already-running story: Pennington County government announced its own “cybersecurity incident” on July 5, affecting the county’s computer network, including services at the Treasurer’s Office.

That investigation continues, involving the South Dakota National Guard Cyber Incident Response Team, the SD Fusion Center, and CISA.

South Dakota News Watch reported that two independent cybersecurity experts — John Strand of Black Hills Information Security in Sturgis, and Bryce Austin of TCE Strategy — believe the pattern of that attack points toward a foreign adversary rather than a criminal group, largely because no ransom demand has surfaced.

Strand named Iran, Russia, and China as the plausible sources of that kind of activity. Austin was blunter: “I think we’re cannon fodder in the Iran war.”

Two Systems, not necessarily one Incident

It’s worth being precise about what is and isn’t the same thing.

Pennington County’s incident affected county government IT systems — the kind used to run a treasurer’s office and internal communications.

Rapid City’s incident affected a piece of the city’s wastewater operational technology — a physically different kind of system, run by a different unit of government.

They emerged in the same region within the same few weeks, but nothing publicly available yet ties them to the same actor or the same intrusion. Treating them as two separate threads, for now, is the accurate way to report it.

What Isn’t Known Yet

Whether South Dakota is among the FBI’s seven affected states.

Who is responsible for either the county or the city incident.

Whether the two local incidents are connected to each other.

Whether either incident is connected to the broader Minnesota campaign

Sourcing

City of Rapid City press release, cyber incident involving a wastewater lift station.

South Dakota News Watch, “Experts: Cyberattack on Pennington County likely by foreign adversary,” July 30, 2026.

CBS News, “U.S. investigating if Iran was behind cyberattack on water systems in 7 states, including Minnesota,” July 30, 2026.

NBC News, “Hackers targeted municipal water systems in 7 states this week, FBI says,” July 30, 2026.
The Washington Post, “U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities,” July 30, 2026.

CISA public advisory, July 22, 2026, on Iranian-affiliated targeting of internet-connected operational technology.


Discover more from THE RAPID CITY SENTINEL

Subscribe to get the latest posts sent to your email.