U.S. Public Entity Reportedly Paid $1M to Kairos in Data-Theft Extortion
A recent case study by Rakesh Krishnan for Ransom-ISAC, reconstructed from a leaked negotiation chat and the blockchain record of the transfer, shows a U.S. government organization appears to have paid roughly $1 million to keep stolen documents from being released. The episode is notable because the group that collected the cash-calling itself Kairos-may not have performed any traditional ransomware encryption.
Krishnan’s review turned up no evidence that Kairos ever deployed an encryptor, a lock screen, or demanded a decryption key. Instead, the threat was straightforward: exfiltrate sensitive files and then demand payment in exchange for not publishing them. While the report does not name the victim, the leaked chat and the sample files point strongly at Union County, Ohio. The proof-of-theft artifacts include file names such as Union.xlsx, 1 union co psi template.doc, and a final archive labeled union.rar.
The victim in the negotiation described itself as a small county with limited resources, and the attackers repeatedly highlighted a folder labeled “prosecutors office,” claiming that releasing its contents would enable criminals to evade charges. Those details sync with a public incident: in May 2025 Union County, Ohio, reported detecting ransomware on its systems and later disclosed that 45,487 residents and staff had their information taken-affecting most of a county of about 70,000 people. The stolen dataset reportedly included Social Security numbers, financial records, fingerprints, and passport numbers. Neither Union County nor Kairos has publicly confirmed a direct link, but if the connection holds, the county made an undisclosed payment of about $1 million. The Hacker News has reached out to the Union County Commissioners’ Office for comment; this article will be updated if they respond.
The bargaining unfolded over roughly a month. Kairos began with a $3 million demand, asserting it had more than 2 terabytes of data-around 1.6 million files. County negotiators opened at $100,000, rising to $255,000 and then $430,000. Kairos lowered its ask to $2 million before imposing a hard deadline and a final price: $1 million, payable by Friday or the files would be released. The on-chain record shows about 9.44 BTC arriving in a wallet linked to Kairos.
After the transfer on June 13, 2025, the funds were split and routed through a series of wallets and then on toward deposit addresses connected to the exchanges Bybit and OKX, and a Russian platform called BELQI. Blockchain tracing provides investigative leads rather than direct identities, but it does show the movement of funds. In return for the ransom, Kairos produced a “proof of deletion” file; however, a list of filenames only demonstrates the attackers once possessed the data, not that the original copies were actually purged. Paying to have stolen information removed is ultimately a leap of faith-the receipt is issued by the thief.
Union County described the incident as ransomware, the common label for such events, yet in the Kairos case there was no encryption involved. This distinction underscores a shifting tactic: many operations that are still called ransomware now rely on exfiltration and extortion rather than encrypting systems. In 2025 Sophos reported that only about half of ransomware incidents included encryption-the lowest proportion in six years-and some groups have abandoned encryption entirely. For example, Silent Ransom Group, an offshoot of Conti, has long focused on pure data-theft extortion against U.S. legal and financial organizations without using an encryptor at all.
The negotiation pattern in the Kairos chat echoes other known extortion deals. When internal messages from Black Basta leaked in February 2025, the transcripts revealed a bargaining arc that ran from an initial $1.5 million demand down to a $100,000 counteroffer and ultimately a $1 million payment-an almost identical trajectory. Researchers have relied on leaks such as the Black Basta and 2022 Conti disclosures to map how these exchanges actually get negotiated.
Since the case became public, Kairos’ leak site has disappeared and the group has been quiet-its last publicly known victim appeared in June 2026-but blockchain activity tied to an associated wallet continued as recently as May 2026. That activity serves as a reminder that a dormant leak site does not necessarily mean the actors have stopped operating.
The episode comes with predictable takeaways for administrators of small government networks: enable multi-factor authentication (Kairos said it gained access by guessing a password); monitor for repeated failed sign-in attempts and unusually large outbound data transfers; watch for temporary file-sharing URLs like the temp.sh links Kairos used to move stolen material; isolate legal, HR, and citizen records from general network access; prepare a public communications plan in advance; and assume any promise from extortionists to delete stolen data is worthless.