Las Vegas/ Crime & Emergencies

One Year After Ransomware Attack, Nevada Strengthens Cyber Defenses With Zero Trust Plans

AI Assisted Icon
Published on September 19, 2026
One Year After Ransomware Attack, Nevada Strengthens Cyber Defenses With Zero Trust PlansArroyo Crossing Pkwy., Suite 220 — Nevada DMV Recovery Site
Google Street View

One year after a ransomware attack froze Nevada state services for nearly a month, officials say the crisis reshaped how the state defends its networks — and thousands of residents who couldn't get help during the outage are the reason why. The August 2025 attack disrupted government operations across Nevada, and it took close to a month to bring systems fully under control, with repercussions stretching into September 2025.

According to KLAS 8 News Now, Nevada has since invested roughly $14 million in cybersecurity upgrades following the breach. Tim Galluzi, chief information officer of the Governor's Technology Office, told the station that awareness has been the biggest change to come out of the ordeal, as the state raced to respond to a fresh wave of cyberattack attempts in the months after the initial incident.

A Backdoor That Sat Undetected for Months

The attack's roots trace back further than most people realized at the time. A state employee unknowingly downloaded malware from a spoofed website through a malicious search ad on May 14, 2025, according to The Record, which reported that the download installed a hidden backdoor that persisted even after Symantec antivirus software quarantined the original installation tool in late June 2025. Threat actors sat undetected inside state networks for more than three months before detonating ransomware in late August.

The state ultimately refused to pay the ransom the hackers demanded. The Governor's Technology Office revealed that decision was rooted in confidence in backups, and the office's after-action report shows essential services were restored within 28 days, with roughly 90% of impacted state data recovered without any payment to the extortionists.

Overtime Shifts and a $1.3 Million Recovery Bill

Getting there wasn't cheap, but it cost far less than what the hackers wanted. Nevada spent about $1.3 million on outside vendors for forensics, recovery, legal work, and engineering, per the after-action report, and that outside vendor support cost less than the ransom the 2025 hackers had demanded. The state also paid more than $259,000 in direct overtime to 50 state IT employees who logged 4,212 overtime hours combined, working 18-to-20-hour shifts during the early weeks of containment to rebuild systems safely.

The disclosure of the breach itself triggered a second wave of trouble. In the 72 hours after Nevada went public with the incident in late August 2025, state firewalls saw a 300% surge in attack attempts, registering roughly 150 million hits, according to StateScoop. The period also included phishing attempts and a statewide password reset.

Gun Sales and DMV Lines Ground to a Halt

The disruption reached well beyond back-office IT systems. The attack knocked out Nevada's point-of-contact firearms background check system for nearly three weeks, halting commercial gun sales statewide because Nevada relies on its own state Brady system rather than federal databases, as Hoodline reported in its coverage of the background-check shutdown. State police couldn't process electronic or phone background checks until connectivity was restored.

DMV offices were hit too, with essential in-person services resuming as systems came back online. The agency waived late fees accrued during the shutdown and honored canceled appointments as walk-ins through mid-September 2025, and Governor Lombardo confirmed at the time that no driver's license numbers or vehicle registration records were compromised, according to Hoodline's earlier reporting on the DMV's reopening.

Rebuilding With Zero Trust and a Statewide Data System

In the year since, Nevada has overhauled how it classifies and protects information. Agencies previously maintained their own separate data protections, but the state has now standardized information into four categories — public, sensitive, confidential, and restricted — under a unified statewide system, per KLAS's reporting. The state also tightened internal login requirements, expanded multi-factor authentication, and established a third-party review process for any cloud-based technology before it touches state networks.

Those changes sit alongside a broader technical overhaul. Nevada identified Zero Trust architecture as a modernization priority, according to TechTables.

Lawmakers also moved on the legislative front. Nevada introduced Assembly Bill 1 to create a centralized statewide Security Operations Center, and the measure passed unanimously, as StateScoop reported.

The 2025 breach also landed amid a broader push to strengthen Nevada's technology infrastructure. Enterprise hardening, as Nevada officials describe the broader push to tighten defenses across every agency, is part of that effort.

The anniversary also arrives amid a shifting federal approach to cybercrime. A federal memorandum authorizes vetted companies to conduct operations against foreign cyber-enabled transnational criminal organizations, as Hoodline reported.