Desk live·
ForensicPost
Ransomware/Public sector/File 25-0516

Nevada Intrusion Started When an Employee Downloaded a Spoofed Admin Tool

The intrusion that took sixty Nevada state agencies offline in August began on 14 May 2025, when a state employee downloaded a malware-laced admin tool from a spoofed website.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNevada state government
ActorUnattributed
D. Kennedy12 min readConfidence: high2 sources reviewed

Investigation into the ransomware attack that disrupted Nevada state government traced initial access to 14 May 2025, when a state employee downloaded a system administration tool carrying malware from a spoofed website. Ransomware was deployed on 24 August, the incident recorded at 25-0824.

The Target Was The Person Maintaining The Systems

A great deal of security awareness training addresses the general employee: do not click the link, do not open the attachment, verify the sender.

This targeted an IT worker looking for a legitimate administrative utility — someone whose job requires downloading and running system-level software, on a machine with the privileges to do it, in a workflow the training does not describe.

The corpus recorded the same inversion at 25-0105, where the route into a platform serving 18,000 schools was the support portal rather than the customer application. Operational tooling is repeatedly the weak point, and it is repeatedly classified as internal.

And The Download Was Not A Mistake In The Usual Sense

The employee was doing their job. They searched for a tool they had a legitimate reason to use, found a site that looked like the source, and downloaded from it.

This desk filed at 25-0311 that a control which is correct 999 times out of 1,000 teaches people to stop reading it, and that this is not user failure. The same applies here: the action was correct in every previous instance.

The controls that address it are technical rather than behavioural — allow-listed software sources, an internal package repository, execution restrictions on administrative endpoints. All are available. None depend on an employee correctly identifying a spoofed domain under time pressure.

How we reported this

Compiled from published reporting of an incident investigation, listed below. The account of initial access follows the published findings. Corrections: corrections@forensicpost.com.

Sources
  1. Nevada ransomware attack traced back to malware download by employeeCybersecurity Dive
  2. Report blames Nevada hack on employee downloading malwareRoute Fifty
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary