logo

How a ransomware gang encrypted Nevada government's systems

ID: 15dd501c-14a1-5891-b2b6-b96e8d77ca97

STIX ID: report--15dd501c-14a1-5891-b2b6-b96e8d77ca97

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-06

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Executive summary: The State of Nevada published a transparent after-action report detailing a multi-month intrusion that began when an employee downloaded a trojanized admin tool via a malicious search advertisement; attackers persisted despite endpoint removal, installed remote-monitoring tools, used a custom encrypted tunnel and RDP for lateral movement, extracted credentials from a password vault (26 accounts), wiped logs, deleted backup volumes, and deployed ransomware across VM hosts—impacting more than 60 state agencies. Nevada restored ~90% of required data over 28 days without paying ransom, incurred significant internal overtime and ~$1.3M in external vendor costs, and implemented corrective security measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.