How a ransomware gang encrypted Nevada government's systems
ID: 15dd501c-14a1-5891-b2b6-b96e8d77ca97
STIX ID: report--15dd501c-14a1-5891-b2b6-b96e8d77ca97
Feed Name: Bleeping Computer
Executive summary: The State of Nevada published a transparent after-action report detailing a multi-month intrusion that began when an employee downloaded a trojanized admin tool via a malicious search advertisement; attackers persisted despite endpoint removal, installed remote-monitoring tools, used a custom encrypted tunnel and RDP for lateral movement, extracted credentials from a password vault (26 accounts), wiped logs, deleted backup volumes, and deployed ransomware across VM hosts—impacting more than 60 state agencies. Nevada restored ~90% of required data over 28 days without paying ransom, incurred significant internal overtime and ~$1.3M in external vendor costs, and implemented corrective security measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
