← BACK TO FEED
ransomwareextortiondata theftlocal governmentcrypto tracing

A U.S. County Paid $1 Million to a Group That Never Even Locked a Single File

A U.S. government entity, likely Union County, Ohio, paid approximately $1 million in bitcoin to a group called Kairos after hackers stole over 1.6 million files and threatened to publish sensitive records, including data from the prosecutors' office. Unlike typical ransomware attacks, Kairos never encrypted any systems — it relied solely on the threat of leaking stolen data as leverage, reflecting a growing trend where extortion groups skip encryption entirely. After a month-long negotiation, the county paid ten times its opening offer, receiving only an unverifiable "proof of deletion" in return, with blockchain tracing linking the funds to exchanges including Bybit, OKX, and a Russian service.

A U.S. government entity quietly paid around $1 million to stop stolen files being published online. We know this because a researcher named Rakesh Krishnan, writing for Ransom-ISAC, got hold of a leaked negotiation chat and followed the money on-chain. The picture that emerged is instructive, and not in a good way.

The group behind it calls itself Kairos. And here's the thing: there's no evidence it ever encrypted anything. No locker, no encryptor, no ransom note demanding a decryption key. The entire operation was just theft followed by a very expensive threat to stay quiet about it.

Krishnan doesn't name the victim directly, but the negotiation chat practically does it for him. Proof-of-theft files carry names like Union.xlsx and 1 union co psi template.doc. A final archive is called union.rar. The victim describes itself as a small county with limited resources. The attacker repeatedly emphasises one specific folder labelled "prosecutors office," warning that releasing it would hand criminals a way to beat charges.

The dots connect to Union County, Ohio, which announced in May 2025 that it had detected a network intrusion. The county later notified roughly 45,000 residents and staff that their data had been taken, covering everything from Social Security numbers and financial records to fingerprints and passport information. The county has a population of around 70,000.

Neither Kairos nor the county has confirmed any link. But if the connection holds, a county government handed over a seven-figure sum it never publicly mentioned. The Hacker News reached out to the Union County Commissioners' Office. No response yet.

The negotiation itself took about a month. Kairos opened at $3 million, claiming to hold more than 2 terabytes of data across some 1.6 million files. The county came in at $100,000. Over several rounds it crept up to $255,000, then $430,000. Kairos came down to $2 million, then drew a hard line: $1 million by Friday, or the files go public. The county paid on June 13, 2025. That's ten times its opening offer.

The payment was approximately 9.44 bitcoin. Krishnan tracked it from the Kairos-linked wallet and watched it split in two within hours, then move through a chain of addresses toward deposit accounts tied to Bybit, OKX, and a Russian service called BELQI. That gives investigators threads to pull. It doesn't give them names.

As for what the payment actually bought: not much of anything verifiable. Kairos sent over a so-called proof of deletion, which is a list of file names. That proves the attacker had the files at some point. It proves absolutely nothing about whether those files still exist. Paying a thief to destroy stolen data and then trusting them to have done it is a peculiar kind of optimism.

Union County referred to the incident as ransomware, which is what everyone defaults to. But in the Kairos case, no ransomware was involved by any conventional definition. This is the real pattern shift: encryption is increasingly optional. Sophos reported in 2025 that only around half of attacks now involve any encryption at all, the lowest proportion in six years. Some operations have dropped it entirely. Silent Ransom Group, a Conti offshoot, has been running pure data-theft extortion against U.S. law and finance firms for years without ever deploying an encryptor.

The negotiation arc is also familiar to anyone who's read the leaked Black Basta chats from February 2025. One deal in those logs ran from a $1.5 million opening demand to a $100,000 counter and eventually settled at $1 million, nearly identical. The Conti leaks back in 2022 gave researchers the same kind of window. These documents are now how analysts understand what these negotiations actually look like from the inside.

Kairos itself appears to have gone quiet. The leak site is offline, and its last known victim appeared in June 2026. A wallet connected to the operation was still moving money as recently as May 2026, which is a useful reminder that a dead website is not the same thing as a dead operation.

The defensive lessons are, frankly, boring. Kairos claimed it got in by guessing a password, so multi-factor authentication would have been a reasonable start. Watching for repeated failed logins, large outbound data transfers, and throwaway file-sharing links like the temp.sh addresses Kairos used is basic hygiene. Keeping legal, HR, and citizen records segmented from the rest of the network helps. Having a communications plan drafted before you need one helps more.

And if someone sends you a proof-of-deletion document after you've paid them a million dollars, don't take it seriously. They wrote it.

READ NEXT
Small US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.Ransomware Knocks Fairlife's US Dairy Plants OfflineRoundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware Hell