Pennington County has restored operations in all departments after a ransomware attack on July 4. Some public services are still limited as IT teams rebuild and upgrade security.
On July 4, Pennington County's IT network went dark. Hackers broke in and launched ransomware. Officials had to pull the plug on critical systems. The shutdown hit during the holiday. It was a scramble to contain the threat.
Now, every county department is back at work. But not everything is fixed. Some public services are still running at half speed. The digital backbone is being rebuilt piece by piece. Recovery is slow.
Investigators first spotted the breach on July 4. They found unauthorized activity in the network. Hackers had slipped in and deployed ransomware. The IT team moved fast. They shut down servers and isolated parts of the network. That included old Windows Server setups and endpoints with outdated firmware. These weak spots are common in public sector tech.
Since then, county staff have worked with cybersecurity experts and government agencies. The South Dakota National Guard Cyber Incident Response Team, the Cybersecurity and Infrastructure Security Agency, the FBI, and the South Dakota Fusion Center all joined the effort. Their help was key. The county says these partners made recovery possible. The attack forced a review of NIST SP 800-53 compliance. Multi-factor authentication is now required for all admin accounts. This matches the ACN guidelines for public sector security.
County Commission Chairman Ron Weifenbach said officials kept details quiet at first. Now, he confirms all departments are open. But there is no date for full restoration. Some systems are still degraded. IT teams are still working. Updates from September 24 to 29, 2026, show core operations are back. But online records and payment portals are throttled. Downtime is common. Forensic checks and patching are still underway.
L'incidente di Pennington County dimostra come la resilienza informatica delle amministrazioni pubbliche dipenda dall'adozione tempestiva di misure di sicurezza avanzate e dalla collaborazione con enti specializzati nella risposta agli incidenti.
Pennington County is spending on new cybersecurity tools. Staff are getting more training. Extra security steps are in place to block future attacks. The county is learning from this breach. Resilience and speed matter most. IT leaders have rolled out next-generation endpoint detection and response. Critical workloads are moving to cloud platforms certified under ISO/IEC 27001. This fits with new European and Italian rules.
Public agencies everywhere face these threats. Ransomware keeps finding weak spots. Recovery plans only prove themselves under real pressure. As reported earlier, paper plans are not enough.
Pennington County's story is blunt. Fast action and outside help are not a magic fix. Full recovery takes time. The county is choosing transparency and long-term upgrades. That's a practical path for local governments. Ransomware is not going away. Only those who adapt and learn will keep services running.