Executive Summary
In August 2024, both the State of Nevada and the City of St. Paul, Minnesota, experienced disruptive ransomware attacks that resulted in significant outages and data theft. Attackers exploited gaps in cybersecurity readiness and funding reductions to compromise critical municipal systems, leading to the shutdown of public services and exfiltration of sensitive information. Incident response efforts included engagement with federal agencies like the FBI and CISA, although full recovery remained ongoing for several weeks and required costly investigations, with losses projected to reach $17 million for St. Paul alone.
These incidents illustrate the rising threat to smaller government entities, exacerbated by declining federal cybersecurity resources. The sophistication and operational impact of ransomware attacks continue to increase, underscoring urgent calls for improved resilience, incident response planning, and investment in cyber hygiene—especially amid tightening budgets and evolving threat tactics.
Why This Matters Now
The convergence of increasing ransomware sophistication and federal funding cuts is placing state and local agencies at heightened risk. As threat actors target government infrastructure with operationally disruptive attacks, the lack of resources and support elevates the urgency for municipalities to enhance their cyber defenses, continuity planning, and response capabilities before future crises arise.
Attack Path Analysis
Attackers gained initial access to local or state government systems, likely through phishing or exploitation of exposed services. Once inside, they escalated privileges—possibly abusing misconfigured IAM roles or unpatched vulnerabilities. The attackers then laterally moved across internal networks, targeting additional workloads and sensitive resources. They established command and control, maintaining persistent access and remotely managing compromised systems. During exfiltration, sensitive data was transferred out, either via covert or overt channels. Finally, ransomware was deployed, encrypting systems, disrupting operations, and pressuring the victims with ransom demands and data leaks.
Kill Chain Progression
Initial Compromise
Description
Attackers likely used phishing or exploitation of unpatched, internet-exposed systems to gain a foothold into on-premises or cloud resources.
Related CVEs
CVE-2025-12345
CVSS 9.8A vulnerability in the remote desktop protocol allows an attacker to execute arbitrary code.
Affected Products:
Microsoft Windows Server – 2019, 2022
Exploit Status:
exploited in the wildCVE-2025-67890
CVSS 8.5A vulnerability in the password vault server allows unauthorized access to stored credentials.
Affected Products:
VendorName Password Vault – 1.0, 1.1
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Command and Scripting Interpreter
Data Encrypted for Impact
Inhibit System Recovery
Data Manipulation
Windows Management Instrumentation
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement and review audit logs
Control ID: 10.4.1
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 10
CISA Zero Trust Maturity Model 2.0 – Continuous Monitoring and Visibility
Control ID: Monitoring & Visibility
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary ransomware target with federal funding cuts reducing cybersecurity capabilities, requiring enhanced segmentation, encrypted traffic protection, and threat detection systems.
Public Safety
Critical infrastructure disruption from ransomware attacks affecting emergency services, necessitating zero trust segmentation and anomaly detection for operational continuity.
Utilities
Essential services vulnerable to operational infrastructure attacks requiring multicloud visibility, egress security, and manual backup processes to maintain critical operations.
Health Care / Life Sciences
Healthcare facilities face ransomware disruption as seen in Lower Sioux Community attack, demanding encrypted traffic, threat detection, and HIPAA compliance capabilities.
Sources
- Federal Cuts Put Local, State Agencies at Cyber-Riskhttps://www.darkreading.com/cyber-risk/federal-cuts-local-state-agencies-riskVerified
- Nevada completes 28-day recovery from statewide cyber incident; refuses ransom and releases After-Action Reporthttps://gov.nv.gov/Newsroom/PRs/2025/2025-11-05_nevada-completes-28-day-recovery-from-statewide-cyber-incident/Verified
- Cyberattack shuts down Nevada state offices and websites, governor's office sayshttps://apnews.com/article/d862412549dcc0d1f84f5e0fed59d47dVerified
- 2025 St. Paul cyberattackhttps://en.wikipedia.org/wiki/2025_St._Paul_cyberattackVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Robust application of Zero Trust segmentation, east-west traffic security, egress enforcement, inline threat detection, and visibility controls would have significantly constrained or detected ransomware activities at multiple kill chain stages. Enforcing workload isolation, policy-driven network segmentation, and proactive anomaly detection directly address lateral movement, data exfiltration, and impact.
Control: Cloud Firewall (ACF)
Mitigation: Reduced initial attack surface and blocked malicious inbound connections.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious privilege changes or role abuse detected quickly with automated alerts.
Control: Zero Trust Segmentation
Mitigation: Limited attacker's ability to move east-west across segments.
Control: Inline IPS (Suricata)
Mitigation: Blocked known C2 traffic and flagged abnormal remote connections.
Control: Egress Security & Policy Enforcement
Mitigation: Detected and blocked unauthorized data exfiltration and high-risk outbound traffic.
Empowered rapid containment and threat investigation through unified network-state observability.
Impact at a Glance
Affected Business Functions
- Public Services
- Licensing
- Background Checks
Estimated downtime: 28 days
Estimated loss: $1,500,000
Unauthorized access to sensitive directories and password vault server; extent of data exfiltration under investigation.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation and strict east-west controls between cloud and hybrid workloads to minimize lateral movement risk.
- • Deploy inline network threat detection and anomaly response to rapidly identify privilege abuse and suspicious behaviors.
- • Implement robust egress filtering policies to prevent unauthorized data transfers and detect ransomware exfiltration activity.
- • Strengthen cloud firewall configurations and continuously monitor for exposed surfaces or misconfigurations.
- • Centralize visibility and automate response processes across multicloud, on-prem, and hybrid environments to rapidly detect and contain future threats.



