A small Ohio county government paid roughly $1 million in Bitcoin to keep stolen files off a leak site, in an extortion case that involved no encryption, no locker binary, and no decryption key. The case was reconstructed by researcher Rakesh Krishnan for Ransom-ISAC from a leaked negotiation transcript and blockchain tracing, and reported by SecurityWeek, SecurityAffairs, and others. The threat group, Kairos, opened at $3 million and claimed to hold more than 2 terabytes of data across 1,602,775 files. The payment of approximately 9.44 BTC landed on 13 June 2025. Ransom-ISAC did not name the victim, but file names in the proof-of-theft samples (Union.xlsx, 1 union co psi template.doc, and a post-payment archive called union.rar) point to Union County, Ohio, which separately notified 45,487 people that their data was stolen in a May 2025 incident. Neither the county nor Kairos has publicly confirmed the link.
What Happened
Ransom-ISAC's reconstruction places the intrusion on 19 May 2025, with the victim listed on Kairos's leak site two days later on 21 May. SecurityWeek and iSec News both frame it as a May 2025 intrusion; Rescana is the outlier, dating the intrusion to May 2026 and the payment to June 2026, which conflicts with every other account and with the June 13 payment date that the transcript and blockchain trail support. Treat the 2025 timeline as the reliable one.
The negotiation itself is where accounts diverge slightly. SecurityWeek and Security Curated describe a three-week standoff; iSec News, TheNextWeb, and Neuracy Bintel describe roughly four weeks or "about a month." The substance is consistent either way: Kairos opened at $3 million in cryptocurrency, the victim countered at $100,000 and inched upward to $430,000, and Kairos eventually imposed a hard deadline at $1 million. Neuracy Bintel is the only source recording an intermediate $255,000 offer; TheNextWeb is the only one recording that Kairos dropped to $2 million before fixing the final $1 million figure. Both are single-source details and should be held loosely.
The victim paid roughly ten times its opening offer. Ransom-ISAC's read of the transcript is that the county's slow-walking was deliberate: "The affected entity's responses are consistent with an organization buying time while legal, leadership, financial, and communications decisions were coordinated."
Crucially, Ransom-ISAC found no encryption event. In its words: "No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos." The county's own public notice, however, described the incident as ransomware. That gap between what the victim called it and what the evidence supports is the single most important detail in this case.
What Was Taken
Kairos claimed more than 2 TB of data totalling 1,602,775 files before it ever made contact. Ransom-ISAC assessed the file listings as "consistent with a real file-server scrape," so the volume claim is credible rather than the usual inflated leak-site boast.
Union County's own September notification, cited by SecurityWeek and iSec News, put the affected population at 45,487 residents and staff. The disclosed categories include names, dates of birth, driver's license and state ID numbers, passport numbers, Social Security numbers, financial account details, and fingerprints. Rescana additionally lists medical information and payment card details; that expansion appears in only one lower-tier source and is not independently corroborated here.
TheNextWeb and Rescana both report that the attackers leaned hardest on a folder marked "prosecutors office," with Kairos warning that publication would help criminal defendants evade charges. For a county of roughly 70,000 residents, that is a leverage point with no technical remedy: prosecutorial case material cannot be un-leaked, rotated, or reissued the way a credential can.
Proof of deletion was provided, and it does not hold up. Ransom-ISAC noted the deletion evidence "appears selective, not comprehensive," that it could have been generated by erasing a single copy of the data, and that no mechanism to independently verify deletion was offered. The county paid $1 million for a promise it had no way to audit.
Why It Matters
This is a confirmed government-victim breach where the entire extortion mechanism was publication pressure. There was no downtime to recover from and no backups to restore. Most public-sector ransomware playbooks are built around restoration: rebuild endpoints, validate backups, resume operations. In a data-only case, every one of those steps can succeed while the actual problem remains completely untouched, because the attacker already has the files.
It also breaks the reporting taxonomy. Kairos's status as a "ransomware group" is unverified. As Ransom-ISAC put it, a U.S. government body "paid a seven-figure ransom to a threat actor whose 'ransomware group' status remains unverified and whose leverage appears to have been based on data-theft and publication pressure rather than demonstrated ransomware capability." When victims label data-theft extortion as ransomware in public notices, the aggregate statistics defenders and budget-holders rely on get quietly distorted.
The disclosure asymmetry deserves attention too. If the identification holds, the county notified 45,487 people about the theft but never publicly disclosed the $1 million payment. The payment became public only because a negotiation transcript leaked and a researcher traced the chain.
The Attack Technique
Kairos claimed it obtained access through a brute-force credential attack, mapping to MITRE ATT&CK T1110. iSec News characterises it more bluntly as the group guessing a password. Post-access activity described in the reporting includes file and directory discovery (T1083) to locate and aggregate sensitive shares before exfiltration. Rescana reports that the stolen data moved out via burner file-sharing services, specifically temp.sh; that detail is single-source and unconfirmed elsewhere.
The money trail is the best-documented part of the case. Ransom-ISAC's blockchain analysis found the ~9.44 BTC split into two major branches: one moving toward a Bybit-linked deposit address, another fragmenting through intermediary wallets before touching addresses associated with OKX and BELQI. Both iSec News and Neuracy Bintel describe the same exchange set.
Throughout, Kairos maintained control of deadlines and released proof-of-access artifacts to sustain pressure. There is no evidence of an encryption payload at any stage.
What Organizations Should Do
- Enforce phishing-resistant MFA on every externally reachable authentication surface. A brute-force credential attack succeeded against a county network. MFA, lockout thresholds, and rate limiting on remote access, VPN, and admin portals would likely have ended this before the discovery phase.
- Build a data-theft-only playbook separate from your ransomware playbook. Decide in advance who authorizes a payment, who talks to counsel and insurers, and what your public position is when there is nothing to restore. Restoration procedures do not address publication risk.
- Treat proof of deletion as worthless. Ransom-ISAC could not verify Kairos's deletion artifact and noted it could have been produced by wiping one copy. Model any exfiltrated data as permanently in adversary hands and notify accordingly, regardless of what you pay.
- Instrument egress, not just endpoints. 2 TB and 1.6 million files left the network. Volumetric egress alerting, and monitoring for uploads to burner file-sharing services, would have surfaced a scrape of that size well before the leak-site listing.
- Segment and tightly control high-sensitivity shares. Prosecutorial files, biometric records, and passport data made this county's leverage catastrophic. Restrict those shares to least-privilege access, log every read, and separate them from general file servers.
- Inventory what you hold, and dispose of what you do not need. Fingerprints and passport numbers on a general-purpose county file server converted a routine credential compromise into a seven-figure decision.
Sources: U.S. Government Pays $1 Million in Data-Theft Extortion Case: Insid... | County Government Reportedly Paid $1 Million to Cyber ... | A US government agency paid $1M to Kairos, a group ... | U.S. county linked to $1 million payment in data theft extortion ca... | Kairos Extortion Case Shows Why Ransomware No Longer ... | US government body paid $1M to hackers who never ... | Union County, Ohio Government Pays $1 Million Bitcoin ... | Union County Ohio Pays $1 Million Ransom to Kairos Group Security...