A U.S. local government entity paid about $1 million to the Kairos extortion group to stop the release of stolen files. The figure comes from a Ransom-ISAC case study by researcher Rakesh Krishnan, based on a leaked negotiation chat and the payment's blockchain trail. The study does not name the victim. File names in the attacker's proof-of-theft samples point to Union County, Ohio, but neither the county nor Kairos has confirmed this. None of the eight sources supplied for this brief is a primary or established-press source. We checked the core claims against The Hacker News and Security Affairs, and both report the same $1M payment and the same Ransom-ISAC sourcing. No victim statement, regulator filing or CERT advisory confirms the payment.
What Happened
The Ransom-ISAC case study and the outlets that cover it describe the same sequence:
- Length: the negotiation ran for about a month.
- Opening demand: Kairos asked for $3 million. It said it held more than 2 TB of data, about 1.6 million files.
- Counteroffers: the victim offered $100,000 at first, then $255,000, then $430,000.
- Final demand: Kairos came down to $2 million, then set a "final" price of $1 million with a Friday deadline.
- Payment: The Hacker News reports that about 9.44 BTC arrived in a wallet linked to Kairos. Kairos then supplied a "proof of deletion."
The link to Union County rests on sample file names such as union.rar, Union.xlsx and "1 union co psi template.doc". It also fits a known incident. In May 2025, Union County, Ohio disclosed that it had found ransomware on its network, and it later notified 45,487 people (TNW, The Hacker News).
There is one unresolved conflict. The county's own 2025 disclosure called the incident "ransomware". The case study says Kairos never encrypted anything. Either the county used "ransomware" loosely, or the 2025 incident and the Kairos payment are not the same event. The sources do not settle which.
What Was Taken
- Volume: more than 2 TB and about 1.6 million files. This is Kairos's own claim, repeated by every source that covers the case, and it has not been independently checked.
- Data types: if this is the Union County incident, the county's 2025 notification listed Social Security numbers, financial details, fingerprints and passport numbers for 45,487 people. That would be most of a county of about 70,000.
- Pressure point: Kairos reportedly focused on a folder labeled "prosecutors office". It warned that publishing the files would help criminals avoid charges (TNW, S1, S5).
One rewrite (S5) says the first demand was $1M. TNW and The Hacker News say it was $3M, cut to $1M during the negotiation. We follow the outlets.
Why It Matters
- No encryption: if Krishnan's analysis holds, a small public body paid $1M without losing access to a single system. Data theft alone was enough leverage.
- Unclear disclosure: the payment has not been publicly disclosed. Taxpayers and the people whose data was stolen still don't know whether their records were bought back.
- Deletion can't be verified: the "proof of deletion" depends entirely on the criminals' word.
- Kairos keeps targeting the public sector:
- Velilla de San Antonio, a municipality in the Madrid region, confirmed a security incident in August 2026. It said it could not yet confirm that any data was accessed. Kairos claims 77.6 GB from it, and CTIPilot says this is the second Madrid-region town in three months.
- Breach House lists Slate Valley Unified School District (762 GB claimed) as a Kairos victim on 1 October 2026. That claim is unconfirmed.
- Victim counts are unreliable: CyberThreatIntelligence.net gives both "100 confirmed victims" and "95 victims since June 2024", and in the same profile says the group has been active "since late 2024". Treat all of these as approximate.
The Attack Technique
We have no initial access vector for this incident. Aggregator profiles say Kairos buys access from initial access brokers, takes data without encrypting it, and demands payment in Bitcoin (CyberThreatIntelligence.net, CTIPilot). Brinztech says the group sometimes encrypts with AES-256/RSA and adds a ".kairos" file extension. That conflicts with Krishnan's findings and with CTIPilot, which says no encryptor has been confidently linked to Kairos. We consider the Brinztech claim unsupported.
What Organizations Should Do
- Check access from brokers. Audit external remote access (VPN, RDP, SSO) for stale or reused credentials. Require phishing-resistant MFA.
- Watch for bulk data leaving the network. Alert on large or unusual outbound transfers and archive creation (for example, .rar files) on file servers. Data-only extortion never triggers encryption alarms.
- Divide up sensitive shares. Separate prosecutor, law-enforcement and personnel data, and restrict who can access it.
- Decide on payment policy in advance. Settle the legal, insurance and public-disclosure approach before an incident. Assume that "deletion" cannot be verified.
- Monitor leak sites. Track Kairos and similar data-extortion leak sites for your organization's and vendors' names.
- Notify on data theft too. Treat data theft without encryption as a reportable breach and notify affected people quickly.
Sources: Unraveling the $1 Million Data Extortion: A U.S. Government's Battl... | US government body paid $1M to hackers who never locked a single file | Slate Valley Unified School District — KAIROS Ransomware Attack Br... | Unique Repair Services Ransomware Attack by Kairos (2026) Cyber Th... | U.S. Government Entity Pays $1 Million in Data Theft Extortion: The... | 2026 Midyear Data Breach Report Privacy Rights Clearinghouse | Kairos claims 77.6 GB from a second Madrid-region municipality in t... | Kairos Ransomware Syndicate Targets Spanish Municipal Government of...