SYS::ONLINE
Wasteland.
Briefs1682
Issues22
SinceFeb 2026
LIVE
█ Ransomware US-COUNTY-KAIROS 2026-08-03

US County, Likely Union County Ohio: Kairos Data Theft Extortion

"A U.S. county government paid roughly $1 million in Bitcoin to the extortion group Kairos to stop the publication of data stolen in a May 2025 intrusion, according to a Ransom-ISAC case study by threat-intel researcher…"

A U.S. county government paid roughly $1 million in Bitcoin to the extortion group Kairos to stop the publication of data stolen in a May 2025 intrusion, according to a Ransom-ISAC case study by threat-intel researcher Rakesh Krishnan built from a leaked negotiation transcript, attacker-supplied artifacts, and blockchain payment tracing. Kairos claimed to hold more than 2 terabytes of data, put by Security Affairs at 1,602,775 files and rounded elsewhere to roughly 1.6 million. The group opened at $3 million and settled at $1 million, paid on 13 June 2025. Ransom-ISAC does not name the victim, citing privacy concerns. SecurityWeek reports the affected body "appears to be Union County, Ohio," and TNW, Cyber News Chronicle and Overcentral reach the same identification from filenames in the proof-of-theft samples. Neither the county nor Kairos has confirmed it.

What Happened

Per Ransom-ISAC as quoted by Security Affairs, the entity was targeted on 19 May 2025 and listed on Kairos's victim site on 21 May 2025. Kairos claimed it obtained access through a brute-force credential attack, then skipped encryption entirely in favour of exfiltration and public-exposure pressure.

Accounts of the negotiation's length differ. SecurityWeek and Biphoo describe a three-week back-and-forth; TNW, Cyber News Chronicle and OSINTSights describe roughly a month. The reported price movements are broadly consistent but not identical in detail. SecurityWeek and Biphoo record the victim moving from $100,000 to $430,000 before accepting a hard deadline and the $1 million figure. OSINTSights supplies a fuller timeline: a $100,000 counteroffer on 4 June 2025, rejected by Kairos with the line "You are wasting our time with such offers," followed by a two-day ultimatum; $255,000 on 6 June; $430,000 on 9 June; and a $1 million settlement the same day. TNW adds that Kairos dropped to $2 million before fixing the final $1 million demand. The intermediate $255,000 step appears only in the OSINTSights account and is not corroborated by the outlet-tier reporting.

The victim identifies itself in the transcript as "a small county with very limited resources." The Register quotes its opening position directly: "We have reviewed the situation with our leadership and financial teams... The most we have been able to identify at this time is $100,000." Ransom-ISAC assessed that the entity's responses were "consistent with an organization buying time while legal, leadership, financial, and communications decisions were coordinated."

In exchange for the payment, OSINTSights reports the county asked for three things: proof of deletion, a complete list of files taken, and an explanation of how the intruders got in. Kairos supplied a RAR archive it said proved deletion of all downloaded files. TNW reports the payment was roughly 9.44 bitcoin, matching about $1 million at that week's prices.

What Was Taken

Kairos claimed more than 2 TB across approximately 1.6 million files, with Security Affairs citing the precise figure of 1,602,775. Ransom-ISAC judged that the file listings the attackers provided were consistent with a real file-server scrape, and Kairos offered the county a full file list plus up to ten files of its choosing for inspection.

The proof-of-theft samples named in reporting include Union.xlsx, "1 union co psi template.doc," and a post-payment archive called union.rar. Multiple outlets treat those filenames as the basis for the Union County attribution.

If the identification holds, the exposure maps to a disclosed breach. SecurityWeek reports the county notified 45,487 individuals in September that their personal information was stolen, listing names, dates of birth, driver's license and state ID numbers, passport numbers and Social Security numbers. TNW and Cyber News Chronicle add fingerprints to that list, and Cyber News Chronicle also cites financial details. TNW and Cyber News Chronicle both put the county's population at roughly 70,000.

The attackers concentrated pressure on one folder in particular. TNW and Cyber News Chronicle report Kairos leaned hardest on material marked "prosecutors office," warning that a leak would help criminals evade charges.

Why It Matters

Two things in this case should worry defenders more than the dollar figure.

The first is the naming problem. Ransom-ISAC found no encryptor, no locker binary, and no decryption-key demand, and stated plainly that "No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos." Yet the county's own public notification, per SecurityWeek, described a ransomware attack. That gap is not a semantic quibble. It affects incident classification, insurance treatment, regulatory characterisation, and every statistic built on victim self-reporting. Ransom-ISAC's own framing is blunt: a U.S. government body paid a seven-figure ransom to an actor whose ransomware-group status remains unverified.

The second is that the county bought a promise. Ransom-ISAC assessed the proof of deletion as selective rather than comprehensive, noted it could have been generated by erasing a copy of the data, and found no mechanism to independently verify deletion. The Register puts the consequence directly: the files may still surface for sale on a criminal forum, and the same crew or another could return with a second demand. A $1 million payment bought a delay in publication, not an assurance of destruction.

Cybersecurity analyst Elena Voss, quoted by Cyber News Chronicle as having reviewed the findings, framed the shift as deliberate: groups skipping encryption because theft plus threatened publication is simpler, harder to detect, and effective. Treat that as one analyst's read rather than an established consensus, but it is consistent with what the transcript shows.

The Attack Technique

Kairos told the county it gained initial access by brute-forcing its way into the network, a claim repeated across all eight sources and sourced to the attackers themselves rather than to independent forensic confirmation. Overcentral characterises it as password guessing and draws the obvious control gap: no effective multi-factor authentication on the exposed authentication surface.

After access, the tradecraft was unremarkable and effective. Mass exfiltration from file servers, listing on a leak site within two days of the intrusion, controlled release of proof-of-access artifacts, hard deadlines, and targeted pressure on the most legally sensitive folder in the haul. Note the timeline: listed publicly on 21 May, two days after the 19 May intrusion date. There was no dwell period spent staging an encryption event, because none was coming.

What Organizations Should Do

Sources: County Paid $1M Ransom to Kairos Cyber Extortion Group | County Government Reportedly Paid $1 Million to Cyber Extortion Gro... | U.S. Government Agency Paid $1M to Data Extortion Group Kairos | An unnamed US county – perhaps in Ohio – paid $1M extortion demand... | US government body paid $1M in data-theft extortion | Researcher traces $1 million data-theft payment to Ohio county, not... | U.S. Government Paid $1 Million to Kairos in Data Extortion Case | US County Pays $1M to Cyber Extortionists Amid Data Leak Threat OS...