County update on July cybersecurity incident
Pennington County is providing additional information regarding the cybersecurity incident first identified July 4 as the investigation, data review and recovery process continues.
On July 4, Pennington County identified unauthorized activity within portions of its information technology environment. Threat actors had gained access to county systems and deployed ransomware, prompting the Pennington County Information Technology Department to take servers and systems offline to contain the threat, protect county information, and begin evaluating the affected environment.
Since the incident was identified, the county’s Information Technology Department, employees across county departments, outside cybersecurity professionals and state and federal partners continue to work extensively to investigate the attack, safely restore systems and strengthen the county’s cybersecurity environment.
During the earlier stages of the response, the county was limited in the information it could publicly provide. As the ongoing investigation continues to progress, the commission believes the county has reached a point where additional information can and should be shared with the public.
“From the beginning, our responsibility has been to protect the integrity of the investigation, restore services safely and make decisions based on verified information,” said Pennington County commission chair Ron Weifenbach. “There were details we could not responsibly share at the time, and we understand that created questions and concerns in our community. We have now reached a point where we can provide a clearer understanding of what occurred. The commission believes the public deserves that information, and we will continue to be as transparent as we can while the investigation continues.”
All Pennington County departments are currently operational. However, some systems and public-facing services continue to experience limitations as the Information Technology Department works through the careful process of restoring remaining services. Because restoration work is complex and must be completed securely, the county is not providing a specific date by which every system will be fully restored.
The nature and sophistication of cyber threats continue to evolve, and the county is using the findings from this incident to further strengthen its security posture. Improvements are already underway, including continued investments in technology, employee training and additional security measures designed to better protect county systems and public information.
“This has been an extraordinary undertaking for our IT staff and employees throughout Pennington County government,” Weifenbach said. “We know the disruption has also been frustrating for the citizens who depend on county services. We appreciate the public’s patience as our employees continue this work. Our priority is not simply getting systems back online—it is making sure we restore them safely and take what we have learned from this incident to make Pennington County stronger going forward.”
Pennington County extends its appreciation to the South Dakota National Guard Cyber Incident Response Team, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, the South Dakota Fusion Center, outside cybersecurity professionals and others who have assisted the county throughout the response and recovery effort.




