A US government entity paid a $1 million ransom. Not to encryptors — to prevent stolen data from being dumped online.
Ransom-ISAC broke down the whole negotiation. The extortion group, called Kairos, demanded $3 million in cryptocurrency after breaching the victim’s network in May 2025. They claimed to have stolen over 2 terabytes of data — roughly 1.6 million files — through a brute-force attack.
Negotiations stretched three weeks. The victim started at $100,000, raised to $430,000, and eventually settled at $1 million. Paid in Bitcoin on June 13.
The victim appears to be Union County, Ohio. In September, the county notified 45,487 people that their personal information was stolen. Names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account details, medical info, fingerprint data, payment card numbers. The whole nightmare package.
The attackers pressured hard. Public exposure threats, tight deadlines, constant proof-of-access artifacts. Ransom-ISAC described the victim’s responses as “consistent with an organization buying time while legal, leadership, financial, and communications decisions were coordinated.”
One detail worth noting: this was extortion only. No file-encrypting ransomware. The attackers provided proof-of-deletion after payment, but Ransom-ISAC says it could have been generated by erasing a copy. No way to independently verify.
Small counties don’t have dedicated cybersecurity teams. They don’t have incident response retainers. They have limited resources and a difficult choice when someone steals 1.6 million files and demands millions. The County reportedly paid.
