The interval between initial access to Nevada state systems on 14 May 2025 and ransomware deployment on 24 August is roughly 102 days.
The Delay Is The Operation
Fourteen weeks is not hesitation. It is the time required to move from one compromised workstation to a position from which sixty agencies can be encrypted simultaneously: credential harvesting, privilege escalation, mapping the estate, identifying backups, and waiting for a moment of low staffing.
The corpus filed the same shape at 25-0820, where five months separated foothold from theft, and at 26-0620, where an ERP was occupied for ten months. The deployment is the last act, and by then the outcome is already decided.
Which Means Detection Had A Hundred And Two Days
That is the finding, and it is more useful than the initial access story at 25-0516. A single employee downloading a trojanised tool is a failure that will recur in any large organisation.
Fourteen weeks of lateral movement, credential use and reconnaissance across sixty agencies without detection is a different category of gap — and it is the one the corpus keeps identifying as unfunded rather than unknown, at 25-1211 and 25-0918.
And It Inverts The Usual Response Priority
After an incident, the visible question is how they got in. It produces a nameable cause, a lesson, and a control to buy.
The more consequential question is why nobody saw them afterwards. Prevention will fail — the corpus establishes that at 25-0810, where the best-resourced organisation in the database was reached anyway. Detection is what determines whether a failed prevention becomes a state government offline for 28 days.
Built on published investigation reporting, listed below. The dwell interval is our arithmetic on the two reported dates. Corrections: corrections@forensicpost.com.