Executive Summary
In August 2025, the State of Nevada experienced a significant ransomware attack that disrupted the operations of over 60 state agencies, including those responsible for health and public safety. Attackers gained unauthorized access to internal systems, likely through a compromised credential or exposed remote access service. They rapidly deployed ransomware across the network, encrypting critical data and rendering multiple state services inaccessible while officials initiated emergency response protocols. The impact included delayed or suspended services for residents and a comprehensive recovery process lasting several weeks.
This incident underscores a persistent trend: ransomware threat actors are increasingly targeting government entities, leveraging lateral movement and broad access to cripple essential public services. As attacks escalate and recovery costs rise, organizations face greater pressure to modernize segmentation, detection, and incident response strategies.
Why This Matters Now
Ransomware groups are intensifying their focus on government infrastructure, where disruptions cause outsized societal impact and prompt fast ransom negotiations. As attackers increasingly exploit lateral movement and unsegmented networks, urgent investment in zero trust architecture and proactive anomaly detection is required to protect critical functions.
Attack Path Analysis
Attackers likely gained initial access through a compromised credential or exposed service, then escalated privileges within Nevada’s cloud or hybrid environment. They moved laterally across network segments and workloads, establishing command and control channels to remote infrastructure. Sensitive agency data may have been exfiltrated, and finally, ransomware was deployed, disrupting services and encrypting critical systems.
Kill Chain Progression
Initial Compromise
Description
Attackers obtained access via stolen credentials, phishing, or an unpatched remote service exposed to the internet.
Related CVEs
CVE-2025-49704
CVSS 9.8A critical vulnerability in Microsoft SharePoint Server allows remote code execution via specially crafted API requests.
Affected Products:
Microsoft SharePoint Server – 2019, 2022
Exploit Status:
exploited in the wildCVE-2025-22457
CVSS 9A buffer overflow vulnerability in Ivanti Connect Secure VPN appliances allows remote code execution by unauthenticated attackers.
Affected Products:
Ivanti Connect Secure – 9.X, 22.7R2.5
Exploit Status:
exploited in the wildCVE-2025-59718
CVSS 9.8A critical vulnerability in Fortinet FortiOS allows unauthenticated remote attackers to gain administrative access via crafted SAML messages.
Affected Products:
Fortinet FortiOS – 7.0.0, 7.0.1, 7.0.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Obfuscated Files or Information
Command and Scripting Interpreter
Data Encrypted for Impact
System Services
Remote Services
Windows Management Instrumentation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 10(2)
CISA ZTMM 2.0 – Identity Verification and Access Control
Control ID: Identity Pillar: 3.2
NIS2 Directive – Operational Continuity: Business Continuity/Backup
Control ID: Art. 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct ransomware target with 60 agencies affected, requiring zero trust segmentation, encrypted traffic protection, and enhanced threat detection for critical infrastructure resilience.
Health Care / Life Sciences
Critical health services disrupted by government ransomware attack, exposing HIPAA compliance gaps in east-west traffic security and multicloud visibility requirements.
Public Safety
Public safety services compromised during Nevada ransomware incident, highlighting need for secure hybrid connectivity and egress security policy enforcement capabilities.
Information Technology/IT
IT infrastructure vulnerabilities exposed through ransomware attack vectors, requiring cloud native security fabric and inline IPS protection against lateral movement threats.
Sources
- How a ransomware gang encrypted Nevada government's systemshttps://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/Verified
- Nevada completes 28-day recovery from statewide cyber incident; refuses ransom and releases After-Action Reporthttps://gov.nv.gov/Newsroom/PRs/2025/2025-11-05_nevada-completes-28-day-recovery-from-statewide-cyber-incident/Verified
- Nevada ransomware attack started months before it was discovered, per reporthttps://apnews.com/article/8729e274ef1270d0c9a866ba487197deVerified
- Microsoft says China-based hackers exploiting critical SharePoint vulnerabilities to deploy Warlock ransomwarehttps://www.tomshardware.com/tech-industry/cyber-security/microsoft-says-china-based-hackers-exploiting-critical-sharepoint-vulnerabilities-to-deploy-warlock-ransomware-three-china-affiliated-threat-actors-seen-taking-advantageVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, east-west traffic controls, and egress policy enforcement would have detected or limited attacker movement, command & control, and ransomware propagation. CNSF controls, especially workload segmentation and inline policy enforcement, could have significantly reduced the blast radius and prevented data loss or widespread encryption.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline access policy and real-time inspection could have blocked risky connections or untrusted entry attempts.
Control: Zero Trust Segmentation
Mitigation: Role- and identity-based microsegmentation would have restricted movement between workloads and sensitive resources.
Control: East-West Traffic Security
Mitigation: East-west policy controls stop unauthorized workload-to-workload and inter-region communication.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound filtering and application-aware controls block suspicious C2 traffic.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring and policy enforcement alert on and block unauthorized data exfiltration.
Real-time threat and anomaly detection may have alerted on ransomware tactics and initiated response before widespread encryption.
Impact at a Glance
Affected Business Functions
- Health Services
- Public Safety
- Licensing
- Background Checks
Estimated downtime: 28 days
Estimated loss: $1,500,000
Evidence indicates that data was moved outside of Nevada’s state networks by malicious actors during the ransomware attack. The specific nature of the data has not been identified, but there is no current evidence that personal information was compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and least privilege principles to prevent attacker lateral movement.
- • Implement east-west traffic security with fine-grained policies for workload-to-workload flows.
- • Apply inline IPS and egress filtering to detect and block command & control and exfiltration activity.
- • Increase centralized visibility and automated enforcement across multi-cloud and hybrid environments.
- • Continuously baseline network traffic patterns and employ real-time anomaly detection for rapid incident response.



