← BACK TO FEED
ransomwaredata breachcyber extortionlocal governmentKairos

Small US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.

A US county government, reportedly Union County, Ohio, paid a $1 million Bitcoin ransom to the Kairos cyber extortion group following a May 2025 brute-force attack in which over 2 terabytes of data were stolen. Negotiations began at $100,000 and ended at $1 million after the attackers imposed a hard deadline, with the group originally demanding $3 million. The breach ultimately affected over 45,000 individuals whose sensitive personal, financial, and medical information was compromised, though no file-encrypting ransomware was involved and there is no independent verification that the stolen data was actually deleted.

A US county government paid a $1 million Bitcoin ransom to a cyber extortion group called Kairos in June, after the group claimed to have walked off with over two terabytes of sensitive data. The payment didn't come cheap in negotiating terms either: Kairos originally wanted $3 million.

The details come from Ransom-ISAC, which published analysis of a leaked negotiation transcript. The transcript paints a fairly familiar picture. The victim started low, offering $100,000, slowly climbed to $430,000, then eventually caved to a hard deadline and paid the full $1 million on June 13 in Bitcoin.

Kairos got in through a brute-force attack, which is about as unglamorous as intrusions get. No zero-days, no sophisticated supply chain compromise. Just hammering away at credentials until something gave. From there they claim to have scraped around 1.6 million files before anyone noticed.

The three-week back-and-forth was textbook extortion theatre. Deadlines, proof-of-access screenshots, threats of public exposure. Ransom-ISAC's read on the victim's side is that the slow negotiation wasn't just stalling for better terms. The organisation was almost certainly waiting for lawyers, executives, finance teams, and communications staff to align on what to do. Classic institutional paralysis under pressure.

One important distinction: this was a pure extortion case, not ransomware. No files were encrypted, no systems locked. Kairos just took the data and threatened to publish it.

Then there's the awkward question of whether paying actually accomplished anything. Kairos provided what looked like proof of deletion, but Ransom-ISAC is sceptical. The proof appears selective rather than thorough, and there's no independent verification mechanism. The analysts note the proof-of-deletion could simply be footage of erasing a copy while the originals remain intact elsewhere. Paying a ransom to an extortion group and trusting them to delete your data is, to put it generously, optimistic.

Ransom-ISAC kept the victim's name out of its report, but the transcript describes the target as a small county with very limited resources, and separate reporting points to Union County, Ohio. The county did send breach notifications to over 45,000 individuals in September, acknowledging a May 2025 incident that exposed a fairly alarming breadth of personal information: Social Security numbers, financial account details, passport numbers, medical records, fingerprint data, and payment card information.

SecurityWeek reportedly reached out to Union County for comment. Given that the county already paid a million dollars to keep things quiet, a chatty press response seems unlikely.

READ NEXT
Nichirei Cyberattack Leaves Japan's Frozen Food Chain on IceShinyHunters Breach Exposes Data of 3.8 Million Medtronic PatientsMedtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach