A U.S. government entity paid roughly $1 million to keep stolen files from leaking. But here’s the weird part — the group that collected the money may not have encrypted anything at all.
Ransom-ISAC researcher Rakesh Krishnan published a case study based on leaked negotiation chats and blockchain records. The group calls itself Kairos. Krishnan found no evidence it ever locked a single machine. No encryptor. No locker. No demand for a decryption key. The play was simpler: steal the files, then charge the victim not to publish them.
The victim isn’t named in the study, but details point to Union County, Ohio — population roughly 70,000. In May 2025, the county reported detecting ransomware on its network and later notified 45,487 residents that their data got taken. Social Security numbers, financial details, fingerprints, passport numbers.
The negotiation ran about a month. Kairos opened at $3 million, claiming over 2 terabytes of data. The county started at $100,000, crept up to $255,000, then $430,000. Kairos dropped to $2 million, then set a hard deadline: $1 million, pay by Friday, or the files go public.
The county paid on June 13, 2025 — about 9.44 BTC. Within hours, the money split and moved through wallets toward Bybit, OKX, and a Russian service called BELQI.
Kairos sent a “proof of deletion” file. All it proved was that they once had the files. Paying to make stolen data disappear is an act of faith, and the receipt is written by the thief.
Sophos reported in 2025 that only about half of ransomware attacks still involve encryption — the lowest rate in six years. Some crews have dropped it entirely. Silent Ransom Group, a Conti offshoot, has run pure data-theft extortion against U.S. law and finance firms for years with no encryptor at all.
The lessons are dull and familiar. Turn on MFA — Kairos claimed it got in by guessing a password. Watch for failed logins, large outbound transfers, and burner file-sharing links. Keep citizen records walled off. Treat any promise to delete stolen data as worth exactly nothing.
Kairos’s leak site is down. Its last known victim showed up in June 2026. But a wallet tied to the operation was still moving money as recently as May 2026. A dark leak site going quiet is not the same as a dead crew.
