Rejected Grant Leads to Millions in Cyberattack Costs for South Dakota Taxpayers

0
1

Key Takeaways

  • South Dakota has recorded 1,062 reported cybersecurity breaches over the past five years, with 127 incidents already in 2026.
  • The state rejected $5 million+ in federal cybersecurity grants (Governor Kristi Noem’s administration) and instead allocated $7 million in state taxpayer funds to its own prevention programs.
  • Recent high‑profile attacks have hit Pennington County, Rapid City, and Mitchell, compromising treasurer payment systems, email services, and attempting to infiltrate a sewage lift‑station.
  • Experts suspect foreign adversary‑backed groups (Iran, Russia, China) are behind many of the intrusions, echoing federal warnings about rising state‑sponsored cyber threats.
  • The state’s two main initiatives—SecureSD and Project Boundary Fence—provide voluntary training, phishing simulations, password and firewall reviews, and contractor‑based remediation for participating governments and utilities.
  • Despite these programs, adoption remains uneven; only about 54 of 66 counties have joined, hampered by budget constraints, low perceived risk, and the invisible nature of cybersecurity investments.
  • State leaders continue to stress the need for a “human firewall” and are expanding efforts through the Governor’s Resilience and Infrastructure Task Force (GRIT), which includes cybersecurity as a core objective.

Overview of South Dakota’s Cybersecurity Landscape
South Dakota has become a frequent target of cyberattacks, with the Attorney General’s Office logging 1,062 online security breaches reported to its Consumer Affairs Division over the last five years. The data encompasses incidents affecting individuals, businesses, and government entities, though state law bars public disclosure of specific victims. The sheer volume underscores a persistent threat environment that shows no sign of abating, especially as adversaries refine tactics ranging from ransomware to sophisticated phishing schemes.


Recent High‑Profile Attacks on Local Governments
In mid‑2026, a series of cyber intrusions struck South Dakota’s municipal infrastructure. Pennington County’s treasurer payment systems were knocked offline after a debilitating attack in early July, forcing residents to seek in‑person services while systems were slowly restored. The Rapid City sewer system faced an attempted breach of a sewage lift‑station monitoring station in late July, though quick containment prevented service disruption. Meanwhile, Mitchell’s city email system was compromised in early August, postponing meetings and leaving communications unreliable. These events highlighted how even seemingly modest systems can become entry points for larger disruptions.


Attribution to Foreign Adversaries
Cybersecurity experts and federal officials have warned that state‑sponsored actors—particularly those linked to Iran, Russia, or China—are increasingly likely to target U.S. state and local networks. Analysts speculate that Iran‑backed hackers may be responsible for the Pennington County and Mitchell incidents, as well as breaches into water systems in Minnesota and potentially a dozen other states. The sentiment was echoed by a local official who remarked, “I think we’re cannon fodder in the Iran war,” reflecting the perception that South Dakota’s relatively modest digital footprint makes it an attractive testing ground for adversaries seeking to refine their capabilities.


State’s Decision to Decline Federal Funding
Despite the rising threat, former Governor Kristi Noem’s administration declined to apply for a portion of a $1 billion federal cybersecurity grant program in fiscal year 2023, forfeiting at least $5 million (and likely more) in potential aid. A spokesperson for Noem characterized the funding as wasteful and argued that it would have required the state to rely on one‑time money to sustain a long‑term program. The decision drew criticism from both parties, with lawmakers noting that South Dakota was one of only two states to reject the allocation. In response, the Legislature opted to appropriate $7 million in state taxpayer funds to cybersecurity initiatives, aiming to replace the lost federal support with a home‑grown solution.


Funding the Governor’s Resilience and Infrastructure Task Force (GRIT)
Building on the state‑funded effort, Governor Larry Rhoden directed $500,000 from the Future Fund to the South Dakota Department of the Military on August 11, 2026, to bolster the Governor’s Resilience and Infrastructure Task Force (GRIT). GRIT brings together government, industry, and critical‑infrastructure partners to assess risks and develop preparedness strategies, with cybersecurity designated as a core objective. Adjutant General Mark Morrell emphasized that the task force’s collaborative approach aims to close gaps between disparate sectors and improve overall resilience against cyber threats.


Historical Context: Early Attacks and Lessons Learned
South Dakota’s experience with cyber threats is not new. The first major municipal breach occurred in Brown County (Aberdeen) in August 2021, when an employee clicked a malicious email link, allowing malware to infiltrate county computers. The attack prompted a 10‑day system shutdown, though no ransom was paid and no apparent data loss was reported. The incident revealed vulnerabilities in employee awareness and backup procedures. More recently, in October 2023, a Tripp County employee fell victim to a phishing scam, erroneously transferring over $826,000 in taxpayer money to a fraudulent account. The funds remain unrecovered, and the county has since tightened internal protocols and expanded staff training to prevent recurrence.


State‑Run Programs: SecureSD and Project Boundary Fence
To address these weaknesses, South Dakota funds two complementary programs administered through Dakota State University in Madison: SecureSD and Project Boundary Fence. With a combined $7 million legislative allocation (approved in 2024), the initiatives offer voluntary assistance to counties, municipalities, nonprofit water and sewer utilities, and other public entities. SecureSD provides training on email and data security, helps enhance security policies, and assists with cyber‑incident planning. Project Boundary Fence focuses on proactive defenses: it conducts simulated phishing campaigns, reviews passwords and firewalls, and contracts independent IT firms to remediate any discovered deficiencies. Both programs aim to cultivate a “human firewall” by reinforcing employee vigilance and institutional best practices.


Implementation Challenges and Cultural Barriers
Despite the programs’ availability, adoption remains uneven. As of 2026, roughly 54 of the state’s 66 counties have participated, a figure Waldner describes as insufficient given the universal nature of cyber risk. Resistance often stems from limited IT staff, a belief that attacks will affect “someone else,” and insufficient public appetite for spending on invisible safeguards. Waldner notes that elected officials find it difficult to justify cybersecurity expenditures when the benefits are not immediately visible—unlike a new fire truck or repaired pothole—yet the consequences of a breach are felt acutely by taxpayers when services falter or data are compromised.


Conclusion: Toward a More Secure Future
South Dakota’s cybersecurity struggle reflects a broader national challenge: balancing limited resources against an ever‑evolving threat landscape. The state’s choice to invest state funds rather than pursue federal grants underscores a commitment to self‑reliance, but the success of that approach hinges on widening participation in SecureSD and Project Boundary Fence, enhancing employee training, and fostering a culture where cybersecurity is viewed as essential as any other public safety function. Continued collaboration through the GRIT task force, coupled with transparent reporting and sustained funding, will be critical to protecting the personal data of residents, the integrity of municipal services, and the state’s overall resilience against both criminal and nation‑state cyber actors.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here