A ransomware attack on the Nevada state government was enabled by a state employee's accidental download of a trojanized system administration tool from a fraudulent website in May. The attackers established a backdoor, conducted lateral movement, and infiltrated the state's password vault server over several months. By August, they had exfiltrated sensitive data, deleted backup volumes, and deployed ransomware, disrupting services at more than 60 state agencies, including health benefits, public safety records, and DMV operations. The incident forced critical systems offline for up to 28 days, with recovery efforts requiring a full rebuild of Active Directory and significant overtime from IT staff. The state did not pay a ransom, and most recovery costs were covered by cyberinsurance, totaling at least $1.5 million.
The after-action report from Nevada's technology office highlighted the attacker's use of search ads to distribute malware disguised as legitimate admin tools, a growing trend in initial access techniques. Despite the extensive impact, Nevada was commended for its accelerated response and transparency in reporting, restoring 90% of impacted data within a month. The incident underscores the risks of supply chain and user-driven compromises, as well as the importance of robust detection, backup, and identity management practices in defending against sophisticated ransomware campaigns targeting government infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Multiple outlets reported that the Nevada incident stemmed from a breach dating back to May 2025, with attackers evading detection until the ransomware attack was uncovered. These reports added technical and timeline detail to the public understanding of the case.
Following the ransomware attack, Nevada chose not to pay the attackers' ransom demand. This decision was highlighted in subsequent reporting on the state's response to the incident.
Nevada officials discovered that government systems had been encrypted in a ransomware attack after attackers had already been inside the environment for months. The discovery marked the public emergence of the incident.
After the initial breach, the threat actors reportedly maintained access inside Nevada government systems for several months without being detected. Later reporting characterized this dwell time as a key factor in the eventual ransomware impact.
Reporting says the cyberattack against the State of Nevada was traced back to an initial compromise in May 2025, indicating attackers had access months before the incident was discovered. The intrusion reportedly went undetected for an extended period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityboulevard.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.