Wastewater Cyberattack: Rapid City Water Utility Hack 2026
Hackers hit a Rapid City wastewater lift station amid a 7-state water utility cyberattack wave linked to Iranian hackers. See what happened and how to respond.

At 2 a.m. on a Friday in late July, a lift station on the edge of Rapid City, South Dakota, sat doing what lift stations do. Pumps cycled. Sensors reported levels. Somewhere in a control room across the city, a screen tracked the numbers, unremarkable, unwatched by human eyes at that hour, trusted to the automation that runs almost every municipal water system in the country.
Then something reached in that wasn't supposed to be there.
City officials would later confirm that a cyberattack had targeted the lift station, a critical node in Rapid City's wastewater infrastructure responsible for pumping sewage uphill toward treatment when gravity alone can't do the job. It is the kind of asset nobody thinks about until it stops working, or until someone else starts thinking about it first.
This time, it did not stop working. Rapid City's I.T. Director, Jim Gilbert, said the city's existing security measures held. Wastewater operations continued without interruption. The drinking water supply, officials were careful to clarify, was never touched. Public Works Director Mike Theis noted that the city runs regular protective measures across its water and wastewater systems and will keep watching for the next attempt, because there almost always is one.
On paper, this is a containment success story. In practice, it is a warning shot, and the surrounding evidence suggests Rapid City was not chosen at random.
A Water Utility Cyberattack Pattern, Not an Isolated Incident
Security teams have a phrase for events like this: not an incident, a data point. Rapid City's lift station attack landed in the same window as a wider campaign hitting water and wastewater utilities across at least seven US states. Thirty water facilities in Minnesota alone were struck the weekend before, in what investigators believe to be the work of Iranian state-linked hackers.
Seven states. Dozens of utilities. A shared method, a shared timeframe, and by most accounts, a shared origin. That is not the profile of opportunistic cybercrime looking for a quick payout. It is the profile of a coordinated probe against the physical systems that keep American cities running, executed by an actor with the patience and resources to hit many targets at once and see what gives.
Rapid City was careful to note that its incident is unrelated to a separate cyberattack that struck neighboring Pennington County on July 5. Two breaches, two systems, three weeks apart, in the same corner of South Dakota. Whether or not the attackers are connected, the message to defenders is the same either way: this sector is being tested, repeatedly, from multiple directions, and the testing is not going to stop because one attack failed.
Why Water and Wastewater Utilities Keep Showing Up as Cyberattack Targets
Water and wastewater systems sit in an uncomfortable position in the world of critical infrastructure. They are essential, which makes them attractive targets for anyone looking to cause disruption or send a geopolitical signal. They are also, in many cities, chronically under-resourced when it comes to cybersecurity, run by small I.T. teams managing decades-old operational technology that was never designed with today's threat landscape in mind.
Lift stations and treatment plants often rely on industrial control systems and remote monitoring tools that were built for reliability, not resilience against a modern attacker. Many of these systems were installed long before ransomware groups or state-sponsored actors saw municipal infrastructure as worth the effort. That gap between design era and threat era is exactly what campaigns like the one unfolding across Minnesota, South Dakota, and beyond are built to exploit.
The fact that Rapid City held the line matters. It suggests that baseline defenses, segmentation between operational and business networks, monitoring on critical assets, and a team that knew how to respond fast, can still stop an attack before it becomes a headline about contaminated water rather than a contained one. But it also means the attackers will adjust and try again, on this system or the next one.
Water Utility Cybersecurity: What Operators Should Be Doing Right Now
For water and wastewater operators watching this campaign unfold from the outside, the Rapid City incident offers a few clear priorities.
Isolate operational technology from business IT networks wherever possible, so that a phishing email in the front office can never become a foothold in a pump station. Monitor remote access points closely, since lift stations and treatment facilities are often managed through remote connections that make convenient entry points for attackers as well as engineers. Build an incident response plan specific to OT environments, tested before an attack happens rather than improvised during one. And treat every attack on a peer utility, even one three states away, as intelligence about what is coming next, not as someone else's problem.
Rapid City's I.T. team had that discipline in place when it mattered. The lift station kept pumping. The water stayed safe. Not every utility targeted in this campaign will be able to say the same, which is exactly why the ones that haven't been hit yet need to start preparing as though they already have been.
Voice-based fraud is proving just as dangerous to critical infrastructure operators as network intrusions. Attackers are increasingly pairing technical breaches like the one in Rapid City with social engineering tactics that exploit trust rather than code, including AI-generated voice calls impersonating executives, vendors, or emergency contacts to pressure staff into fast, unverified action. To understand how these scams work and how to build defenses against them, read our guide on How AI Voice Cloning Scams Target Businesses.
Closing Thought
Critical infrastructure attacks rarely announce themselves with fireworks. They arrive quietly, at 2 a.m., inside a system nobody was watching closely enough. Rapid City caught this one. The next city on the list may not be so fortunate, unless it starts treating incidents like this one as a rehearsal rather than a footnote.
Frequently Asked Questions
What happened in the Rapid City wastewater cyberattack?
Hackers targeted a municipal lift station that is part of Rapid City's wastewater system. The city said the attack was contained quickly, wastewater operations were not disrupted, and drinking water was never affected.
Is the Rapid City attack connected to the wider water utility hacking campaign?
Rapid City's incident coincided with a broader wave of attacks on water and wastewater utilities across at least seven US states, including 30 Minnesota facilities, believed to be linked to Iranian state hackers. City officials said the Rapid City incident is separate from a July 5 cyberattack on neighboring Pennington County.
Why are water and wastewater utilities frequent cyberattack targets?
They are essential infrastructure, making disruption highly visible and impactful
Many run legacy operational technology (OT) not built with modern cyber threats in mind
Smaller municipal I.T. teams often have limited cybersecurity resources compared to their attack surface
Remote access tools used for monitoring pumps, valves, and treatment systems can become entry points if not tightly secured
How can water utilities protect themselves from similar attacks?
Segment operational technology networks from business IT networks
Monitor and restrict remote access to critical systems
Build and test an OT-specific incident response plan before an attack happens
Treat attacks on peer utilities as early warning intelligence, not unrelated news
WhiteKnight helps critical infrastructure operators build the detection, response, and OT security posture that turns an attempted breach into a footnote instead of a headline.
If your utility hasn't stress-tested its incident response plan against a scenario like this, now is the time. Reach out to WhiteKnight today.


