State of Nevada
Incident posture
Linked entities
- Victim
- State of Nevada
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A ransomware attack disrupted operations at roughly 60 state offices, crippling certain systems for several weeks before recovery was completed without paying the threat actor. The response required more than 4,200 hours of overtime and involved multiple technology partnerships, with state leaders later publishing a public after-action report to share lessons learned. Following the incident, the Governor's Technology Office rolled out a new statewide data classification policy establishing four sensitivity tiers to standardize how agencies categorize and protect information. Officials noted the policy had been in development before the attack but reflected broader efforts to unify IT practices and strengthen cybersecurity across the state.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In late August 2025, the State of Nevada fell victim to a ransomware attack that disrupted state government operations and required a prolonged recovery effort. The incident impacted systems at approximately 60 state offices, crippling certain state systems for weeks. According to Nevada CIO Timothy Galluzi, the attack struck just one month after the state established the Office of Information Security and Cyber Defense in July 2025, a new division under the Governor's Technology Office (GTO) that was designed to support state cyber strategy, including building a statewide Security Operations Center (SOC) that local governments could opt into at no cost. The attack took place during a period in which Nevada was continuing to mature its cybersecurity posture following the elevation of its IT agency to the GTO in 2023 under a new governor.
The recovery from the ransomware attack was described as nearly monthlong and required multiple technology partnerships and more than 4,200 hours of overtime. Despite the severity and scope of the intrusion, the state did not pay the threat actor. Nevada's response was characterized as transparent and deliberate, including the publication of a public after-action report that served as an important resource for other states refining their cyber strategies. The incident also prompted the state to accelerate and expand its broader cybersecurity and data governance initiatives. Following the attack, officials noted that a new statewide data classification policy had been in development long before the cyberattack occurred, but the timing of its rollout reflected Nevada's ongoing efforts to set uniform IT policies across agencies, building on prior actions such as 2023 guidance on the use of artificial intelligence.
In February 2026, months after the late-August cyberattack, Nevada's Governor's Technology Office announced the new statewide data classification policy, marking the first time the state established clear-cut categories for data sensitivity. The policy standardized how state data is categorized and protected, moving beyond simply denoting information as "sensitive" or "personal" and ensuring private data is not treated the same as public information. According to a release announcing the policy, "Agencies can now rely on a shared baseline for how information is categorized and protected, reducing uncertainty and hesitation when exchanging data." The policy was designed to allow agencies to have a shared baseline for data handling while supporting responsible data sharing across the state government.
Under the new framework, data is classified into one of four categories: "public," "sensitive," "confidential," or "restricted." Individual agencies are responsible for determining the proper category for the data they handle, and when classification is unclear, the data must be placed in the more restrictive category. The "public" classification indicates there are no restrictions or potential harms from disclosure. The "sensitive" tier relates to data not intended for proactive distribution, such as internal agency correspondence, but which can still be released following review to ensure it does not include confidential information. The "confidential" tier includes personally identifiable information and health records, where unauthorized disclosure might result in substantial harm. The "restricted" classification refers to information only available to personnel with specific clearances, such as national security and financial account information, where unauthorized disclosure could threaten public safety or violate federal security rules.
The policy also explicitly accounted for the "mosaic effect," recognizing that data might appear harmless on its own but can become sensitive when combined with certain other data. Under Nevada's public records law, information is by default a public record unless specific confidentiality provisions apply, and the policy did not change what is considered a public record. Agency leaders were designated as responsible for ensuring compliance with the policy, while lower-level data officials determine which classification data falls under. Failure to comply could lead to remediation mandates or escalation to higher-ups. The state indicated that the policy would serve as the "foundation" for future efforts to improve state cybersecurity, including initiatives such as multifactor authentication. Together, these measures were intended to strengthen Nevada's overall digital resilience while enabling responsible data sharing across agencies, in the wake of the ransomware incident that had disrupted state operations weeks earlier.
Sources
Sources available to members: 2 sources.