Desk live·
ForensicPost
Ransomware/Method/File 25-0924

Six Files Exist Because Nevada Published an After-Action Report

Everything in the preceding six files — the date of first access, the vector, the dwell, the refusal, the outage, the cost — exists because Nevada published an after-action account.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetIncident disclosure practice
ActorUnattributed
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

This file records what the Nevada disclosure demonstrates about the rest of this database.

Count What The Corpus Knows Here

Initial access date. The vector, in detail, including the delivery channel. The dwell interval. The number of agencies. The outage duration. The payment decision and its reasoning. The recovery proportion. The response cost.

Now count what this corpus knows about a typical corporate incident: an affected number, a month, and a sentence about sophisticated actors.

Nevada is not a more instructive incident than the 398 others in this database. It is a better documented one, and the difference is entirely in what was published.

It Confirms The Argument At 25-1107 With A Worked Example

That file recorded the practice of public after-action reporting and observed that companies structurally cannot do it, because a candid technical account hands a plaintiff’s firm its case against the 1,900 class actions at 25-1228.

This is what the corpus gains when the constraint is absent. Six analytical files, each resting on a fact nobody was obliged to disclose — and none of them available for the commercial incidents that make up most of this database.

And It Exposes What The Corpus Has Been Doing

This desk has written extensively about detection failures, dwell time, payment decisions and recovery across hundreds of files, largely by inference from thin public reporting.

Where a detailed account exists, several of those inferences hold — dwell is long, the initial vector is mundane, preparation determines the outcome. That is reassuring and it is a sample of one.

The honest position, consistent with 25-1225: this corpus is mostly built on organisations that told the public very little, and its confidence should scale accordingly.

What Would Change It

A protected-disclosure regime — candid technical accounts inadmissible in litigation, as exist in other safety-critical fields — appears nowhere in the 2025 reforms at 25-1113 or 25-0117.

Graded medium: this desk has not reviewed the underlying Nevada report and works from published accounts of it.

This is an analysis file

It describes what the Nevada disclosure provided, drawing on the reporting listed below. This desk has not reviewed the report itself. Corrections: corrections@forensicpost.com.

Sources
  1. Nevada ransomware attack offers lessons in statewide cyber resilienceBarracuda
  2. Report blames Nevada hack on employee downloading malwareRoute Fifty
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary