A U.S. government entity has paid $1 million to a cybercriminal group known as Kairos to prevent the public release of stolen files, according to a case study published by researcher Rakesh Krishnan. The victim, Union County, Ohio, is a small local government with limited security resources. Notably, Kairos did not encrypt any systems. Instead, the group stole highly sensitive resident and employee data and used the threat of publication as leverage, culminating in a seven-figure extortion payment.
What Happened
Kairos gained access to Union County's environment and exfiltrated sensitive files without deploying encryption or demanding a decryption key. Rather than locking the county out of its own systems, the attackers held the stolen data hostage and threatened to publish it unless a ransom was paid.
According to Krishnan's investigation, the negotiation unfolded as a series of escalating demands. The county, operating with the constrained budget and staffing typical of a small government body, ultimately agreed to a final payment of $1 million to keep the data from being leaked. The case reflects a broader shift in criminal tactics, where the theft of data itself, not the disruption of operations, is the primary source of pressure.
What Was Taken
The stolen files were deeply sensitive and directly tied to the identities of residents and staff. Reported categories include:
- Social Security details
- Financial records
- Fingerprints (biometric data)
- Passport numbers
This combination of identity, financial, and biometric data creates a severe and lasting risk. Unlike a password, biometric identifiers such as fingerprints cannot be reset or reissued, meaning affected individuals face potential exposure to fraud and identity theft long after the incident. For a small county, the exposure spans a significant share of the local population and workforce.
Why It Matters
This case underscores a documented pivot in the extortion economy away from encryption and toward pure data theft. As Sophos has reported, only about half of ransomware attacks now involve encryption at all. Kairos exemplifies groups that skip the encryption step entirely, betting that the sensitivity of the stolen data is enough to compel payment.
For defenders, the implications are significant. Backups and rapid restoration, long considered a primary defense against ransomware, offer no protection when the leverage is publication rather than encryption. Small government entities are especially attractive targets because they hold large volumes of high-value personal data while typically lacking mature security programs, dedicated staff, and incident-response budgets. The $1 million payment also signals to other actors that municipal victims can be pressured into large payouts.
The Attack Technique
The published details focus on the extortion model rather than the precise initial-access vector, which has not been definitively confirmed. What is clear is that the attackers were able to move through the environment and exfiltrate large volumes of sensitive records without triggering an effective response, and that they did so without deploying encryption.
The behavioral signature of this style of attack is data staging and bulk exfiltration: accessing sensitive record stores and transferring them out of the network. The guidance drawn from the case emphasizes watching for exactly these signals, including repeated failed logins that may indicate access attempts and large or unusual outbound data transfers that suggest exfiltration in progress. Organizations should also treat any attacker promise to delete stolen data with skepticism, as there is no way to verify deletion once a payment is made.
What Organizations Should Do
- Enforce multi-factor authentication across all accounts, especially remote access and administrative logins, to blunt credential-based entry.
- Monitor for repeated failed logins and alert on anomalous authentication patterns that may signal access attempts.
- Watch for large or unusual outbound data transfers, which are the clearest early indicator of exfiltration in a non-encrypting extortion attack.
- Isolate sensitive records such as Social Security numbers, biometrics, and passport data from the main network, and restrict access to them.
- Prepare an incident-response and public-communications plan in advance, so leadership can manage disclosure and public statements under pressure.
- Treat any attacker promise to delete stolen data as unreliable, and plan for breach notification and identity-protection support regardless of whether a payment is made.
Sources: U.S. Government Pays $1 Million in Data Extortion: Unraveling the Kairos Case (2026)