Nevada said a statewide ransomware attack that disrupted multiple government services began when a state employee installed a malware-laced system administration tool, giving attackers an initial foothold on May 14 before the intrusion was discovered on Aug. 24. Investigators found the attackers used remote monitoring software, an encrypted tunnel, and compromised credentials to move laterally, access more than 26,000 files, and pull passwords from 26 accounts, including a password vault server. State officials later confirmed data was stolen, though the final incident report said more than 3,200 files were exposed and found no evidence that packaged sensitive data was successfully exfiltrated or published; only one document queued for removal contained personal data, and the affected individual was notified. Nevada restored operations within 28 days and said it did not pay the ransom.
The response cost the state about $1.5 million, including more than $1.3 million for outside vendors and over $200,000 in employee overtime, with Mandiant leading the investigation and recovery efforts. Officials prioritized payroll, public welfare systems, and phased restoration of critical services, then launched follow-on security projects and a new statewide data-classification policy aimed at tightening monitoring, detection, and incident response. The post-incident review concluded that the recovery was successful but underscored gaps in continuous visibility and defensive controls across Nevada's environment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Months after the ransomware incident, Nevada unveiled a new statewide data classification policy. The policy was presented as a post-incident measure to improve how state agencies identify and protect sensitive information.
Nevada published a detailed report concluding that the attacker had not successfully exfiltrated or published packaged sensitive data, though one document slated for removal contained personal data and the affected person was notified. The report said the response cost more than $1.5 million, including over $1.3 million for external vendors and more than $200,000 in employee overtime, with Mandiant overseeing the investigation.
In the aftermath of the incident, Nevada launched two new cybersecurity projects aimed at strengthening state defenses and improving resilience. These initiatives were reported as direct follow-on actions spurred by the attack.
Nevada restored operations in phases, prioritizing payroll, public welfare systems, and other critical services, and recovered fully within 28 days of discovering the attack. The state did not pay the ransom demand.
By late August, Nevada officials publicly confirmed that data had been stolen during the ransomware incident. Subsequent investigation found the attacker had accessed more than 26,000 files and exposed more than 3,200 files.
Nevada discovered the ransomware incident on 2025-08-24 after multiple state services were disrupted. The attack affected statewide government operations and triggered a large-scale incident response.
Investigators later determined the intrusion began on 2025-05-14, when a Nevada state employee downloaded malware disguised as a system administration tool. The attacker then established persistence and began moving through the state environment using remote monitoring software, an encrypted tunnel, and compromised credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
apnews.com
Open sourcestatescoop.com
Open sourcethenevadaindependent.com
Open sourcestatescoop.com
Open sourcestatescoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.