A government entity in the United States has paid a $1 million ransom to the Kairos cyber extortion group to prevent the public release of data stolen during a May 2025 intrusion, according to a detailed case study published by Ransom-ISAC. The incident underscores the growing threat of data-theft extortion, where attackers bypass file encryption entirely and rely solely on the threat of exposing sensitive information.
Kairos Demanded $3 Million, Settled for $1 Million in Bitcoin
Leaked negotiation transcripts reveal that Kairos initially demanded $3 million in cryptocurrency from the victim organization. Over a three-week negotiation period, the affected entity increased its offer from $100,000 to $430,000, but ultimately capitulated to a hard deadline and paid the $1 million ransom in Bitcoin on June 13. The attackers applied consistent pressure by threatening public exposure while maintaining tight control over deadlines and proof-of-access artifacts.
The affected government body appears to be Union County, Ohio. In September, the county notified 45,487 individuals that their personal information had been compromised in a May 2025 ransomware attack. The notification confirms the timeline and aligns with the profile of the victim described in the transcripts as “a small county with very limited resources.”
Brute-Force Attack Stole Over 2 Terabytes of Data
Kairos claimed to have exfiltrated more than 2 terabytes of data—approximately 1.6 million files—after breaching the victim’s environment through a brute-force attack. The stolen data included a broad spectrum of personally identifiable information: names, dates of birth, driver’s license and state ID numbers, passport numbers, Social Security numbers, financial account details, fingerprint data, medical records, and payment card information.
Extortion Without Encryption: A Growing Threat Model
Ransom-ISAC notes that this incident was purely an extortion attack and did not involve file-encrypting ransomware. This distinction is critical: victims face data exposure rather than operational disruption, which can alter both the negotiation dynamics and the recovery strategy. The attackers provided proof-of-deletion after payment, but the anti-ransomware organization cautions that the evidence appears selective rather than comprehensive. No mechanism was provided to independently verify that the data had been permanently erased.
“The listings they provided are consistent with a real file-server scrape,” Ransom-ISAC noted, adding that the proof-of-deletion could have been generated by simply erasing a copy of the data while retaining the original.
What Affected Residents Should Do Now
Individuals whose data was compromised in this breach face an elevated risk of identity theft, financial fraud, and targeted phishing attacks. Anyone notified by Union County or who believes their information may have been exposed should take the following steps immediately:
- Enroll in credit monitoring and identity theft protection if offered by the county or through a reputable provider. Free credit freezes with all three major bureaus (Equifax, Experian, TransUnion) are a critical first step.
- Change passwords on all financial, medical, and government-related accounts using a zero-knowledge password manager to generate and store strong, unique credentials. Enable multi-factor authentication on every account that supports it.
- Monitor bank statements, credit card activity, and credit reports for unauthorized transactions or new accounts opened in your name. Federal law entitles you to one free credit report per year from each bureau at AnnualCreditReport.com.
- Remain vigilant against phishing attempts that may reference the breach or stolen data. Attackers often use compromised information to craft convincing social engineering campaigns. Avoid clicking links or opening attachments in unsolicited messages, and verify requests for sensitive information through an independent communication channel.
While the county’s decision to pay the ransom may have prevented the immediate public release of files, the data remains in the hands of an extortion group with no guarantee of permanent deletion. Affected individuals should assume their information is compromised and act accordingly to minimize the risk of long-term harm.