Cyber & AI intelligence
Wasteland.
Briefs indexed2986
Issues30
Published Mondays07:30 CT
▣ Breach US-COUNTY-KAIROS 2026-10-03

Unnamed U.S. County: $1M Paid to Kairos Data-Theft Extortion Group

"A U.S. local government entity paid about $1 million to the Kairos extortion group to stop the release of stolen files. The figure comes from a Ransom-ISAC case study by researcher Rakesh Krishnan, based on a leaked…"

A U.S. local government entity paid about $1 million to the Kairos extortion group to stop the release of stolen files. The figure comes from a Ransom-ISAC case study by researcher Rakesh Krishnan, based on a leaked negotiation chat and the payment's blockchain trail. The study does not name the victim. File names in the attacker's proof-of-theft samples point to Union County, Ohio, but neither the county nor Kairos has confirmed this. None of the eight sources supplied for this brief is a primary or established-press source. We checked the core claims against The Hacker News and Security Affairs, and both report the same $1M payment and the same Ransom-ISAC sourcing. No victim statement, regulator filing or CERT advisory confirms the payment.

What Happened

The Ransom-ISAC case study and the outlets that cover it describe the same sequence:

The link to Union County rests on sample file names such as union.rar, Union.xlsx and "1 union co psi template.doc". It also fits a known incident. In May 2025, Union County, Ohio disclosed that it had found ransomware on its network, and it later notified 45,487 people (TNW, The Hacker News).

There is one unresolved conflict. The county's own 2025 disclosure called the incident "ransomware". The case study says Kairos never encrypted anything. Either the county used "ransomware" loosely, or the 2025 incident and the Kairos payment are not the same event. The sources do not settle which.

What Was Taken

One rewrite (S5) says the first demand was $1M. TNW and The Hacker News say it was $3M, cut to $1M during the negotiation. We follow the outlets.

Why It Matters

The Attack Technique

We have no initial access vector for this incident. Aggregator profiles say Kairos buys access from initial access brokers, takes data without encrypting it, and demands payment in Bitcoin (CyberThreatIntelligence.net, CTIPilot). Brinztech says the group sometimes encrypts with AES-256/RSA and adds a ".kairos" file extension. That conflicts with Krishnan's findings and with CTIPilot, which says no encryptor has been confidently linked to Kairos. We consider the Brinztech claim unsupported.

What Organizations Should Do

  1. Check access from brokers. Audit external remote access (VPN, RDP, SSO) for stale or reused credentials. Require phishing-resistant MFA.
  2. Watch for bulk data leaving the network. Alert on large or unusual outbound transfers and archive creation (for example, .rar files) on file servers. Data-only extortion never triggers encryption alarms.
  3. Divide up sensitive shares. Separate prosecutor, law-enforcement and personnel data, and restrict who can access it.
  4. Decide on payment policy in advance. Settle the legal, insurance and public-disclosure approach before an incident. Assume that "deletion" cannot be verified.
  5. Monitor leak sites. Track Kairos and similar data-extortion leak sites for your organization's and vendors' names.
  6. Notify on data theft too. Treat data theft without encryption as a reportable breach and notify affected people quickly.

Sources: Unraveling the $1 Million Data Extortion: A U.S. Government's Battl... | US government body paid $1M to hackers who never locked a single file | Slate Valley Unified School District — KAIROS Ransomware Attack Br... | Unique Repair Services Ransomware Attack by Kairos (2026) Cyber Th... | U.S. Government Entity Pays $1 Million in Data Theft Extortion: The... | 2026 Midyear Data Breach Report Privacy Rights Clearinghouse | Kairos claims 77.6 GB from a second Madrid-region municipality in t... | Kairos Ransomware Syndicate Targets Spanish Municipal Government of...