A United States government entity, identified through a meticulous investigative case study, reportedly succumbed to a data extortion demand, paying approximately $1 million in Bitcoin to prevent the public release of stolen sensitive files. This incident, brought to light by Rakesh Krishnan for Ransom-ISAC, built upon a leaked negotiation chat and the immutable blockchain trail of the payment, underscores a significant shift in the cybercriminal landscape, where data exfiltration alone, without encryption, is increasingly leveraged as the primary pressure point.
The cybercriminal group responsible for this incident calls itself Kairos. Intriguingly, Krishnan’s analysis found no evidence that Kairos deployed traditional ransomware—meaning, there was no encryptor used to lock machines, no demand for decryption keys, and no indication of system unavailability. Instead, Kairos employed a simpler, yet highly effective, threat: steal the files, then demand payment from the victim to prevent their publication on the dark web or other public platforms. This tactic, often termed "double extortion" when combined with encryption, stands alone here as pure data extortion, highlighting a streamlined and potent method for threat actors.
Unmasking the Victim: Union County, Ohio
While the Ransom-ISAC case study refrained from explicitly naming the victim, the leaked negotiation chat contained compelling clues pointing directly to Union County, Ohio. Proof-of-theft files referenced in the chat bore names such as "Union.xlsx" and "1 union co psi template.doc," culminating in a final archive labeled "union.rar." Furthermore, the victim, in its pleas to the attackers, described itself as a "small county with limited resources," a description consistent with Union County’s demographic and governmental structure. The attackers specifically highlighted a folder marked "prosecutors office," ominously warning that its public disclosure could inadvertently assist criminals in evading charges, a tactic designed to amplify the perceived risk and pressure on the victim.

These investigative threads align with a real-world cyber incident publicly disclosed by Union County, Ohio. In May 2025, the county announced the detection of "ransomware" on its network. Subsequently, in September 2025, it notified 45,487 residents and staff—a substantial portion of the county’s approximately 70,000 inhabitants—that their personal and sensitive data had been compromised and exfiltrated. The breadth of the stolen records was alarming, encompassing highly personal and financially sensitive information, from Social Security and financial details to fingerprints and passport numbers. Such a comprehensive data breach carries severe implications for identity theft, fraud, and long-term privacy concerns for the affected population.
To date, neither Union County nor the Kairos group has officially confirmed the connection between the publicly disclosed breach and the private negotiation. However, if the evidence holds, it implies a county government made a substantial payment of approximately $1 million—an amount that was never publicly disclosed—to a cybercriminal entity. The Hacker News has reached out to the Union County Commissioners’ Office for comment, and this report will be updated pending any official response. The lack of public transparency regarding such a significant payment raises questions about accountability, public trust, and the broader policy implications for governmental entities facing similar threats.
The Month-Long Ordeal: A Glimpse into Cyber Extortion Negotiations
The negotiation process, spanning roughly a month, offers a stark illustration of the psychological and financial pressures exerted by data extortionists. Kairos initiated its demand at an exorbitant $3 million, claiming to possess over 2 terabytes of data, comprising approximately 1.6 million files. The county, attempting to mitigate the financial impact, began its counter-offers at a mere $100,000, gradually escalating to $255,000, and then $430,000.
Kairos, employing classic negotiation tactics, eventually lowered its demand to $2 million, before setting a non-negotiable final offer: $1 million, payable by a strict Friday deadline, or the entirety of the stolen files would be made public. The attackers leveraged a common playbook, incorporating countdown timers, imposing tight deadlines, and threatening to release the most damaging and sensitive folders first—such as the aforementioned "prosecutors office" data—to maximize leverage. Facing the imminent threat of catastrophic public data exposure and its cascading consequences, Union County capitulated, making the payment on June 13, 2025, ten times its initial offer. This demonstrates the immense pressure and the difficult choices faced by organizations under duress from sophisticated cybercriminals.

Following the Bitcoin Trail: A Fleeting Glimpse of the Perpetrators
The payment itself amounted to approximately 9.44 Bitcoin, valued at about $1 million at the time of the transaction. Rakesh Krishnan meticulously traced the cryptocurrency’s movement, providing crucial insights into the immediate post-payment activities of the Kairos group. Within hours of receipt, the Bitcoin was split into two distinct portions and systematically funneled through a complex chain of intermediary wallets. These funds ultimately converged towards deposit addresses linked to several prominent cryptocurrency exchanges, including Bybit, OKX, and BELQI, a Russian-based service.
While such on-chain analysis provides investigators with valuable leads and patterns of financial activity, it rarely yields immediate names or definitive identities of the individuals behind the operation. The inherent pseudonymity of cryptocurrency, combined with the use of mixers, tumblers, and multiple exchange accounts, allows threat actors to obscure their tracks. Moreover, the payment, despite its substantial sum, bought nothing concrete in terms of data security. Kairos provided a "proof of deletion" file, which, upon closer inspection, was merely a list of filenames. This list confirmed only that the attacker once possessed the files, offering no verifiable assurance that the original stolen data had been permanently wiped from their servers or would not be duplicated, sold, or leaked in the future. Paying to make stolen data disappear, in this context, remains fundamentally an act of faith, with the "receipt" issued by the very thief who perpetrated the crime. This highlights a core dilemma for victims: even after paying, the ultimate security of the data remains largely unverified and at the mercy of the attackers.
The Evolving Threat: Data Exfiltration as the New Ransomware
The Union County incident serves as a potent case study for a broader, concerning trend in cybercrime. While Union County officials initially termed the event "ransomware," the Kairos attack notably deviated from the traditional definition by omitting the encryption phase. This signifies a real and measurable shift in modus operandi among cybercriminal gangs: a significant portion of what is still colloquially referred to as ransomware now entirely bypasses encryption, opting instead to use the stolen data itself as the sole pressure point for extortion.

Supporting this observation, a 2025 report by Sophos revealed that only about half of all reported "ransomware" attacks actually involved any data encryption, marking the lowest rate observed in six years. This decline suggests that many cybercriminal crews have either partially or entirely abandoned encryption, recognizing the direct and often more damaging leverage afforded by pure data theft. For instance, groups like the Silent Ransom Group, a known offshoot of the notorious Conti syndicate, have spent years executing purely data-theft extortion schemes, targeting high-value entities such as U.S. law and finance firms without deploying a single encryptor. The rationale behind this shift is multi-faceted: victims are increasingly adept at restoring systems from backups, diminishing the impact of encryption. However, the reputational damage, regulatory fines, and legal liabilities associated with a data breach remain formidable, making data exfiltration a potent and often simpler extortion tool.
Insights from the Underground: Decoding Attacker Tactics
The Kairos negotiation chat, much like previously leaked internal communications from other prominent cybercrime groups, offers invaluable insights into the operational methodologies and psychological manipulation employed by these threat actors. The Black Basta ransomware group’s internal chats, leaked in February 2025, revealed a negotiation trajectory strikingly similar to Kairos’s: an initial demand of $1.5 million, met with a $100,000 counter-offer, eventually settling at a $1 million payment. Similarly, the extensive Conti leaks in 2022 provided an unprecedented look into the inner workings of a major ransomware syndicate, detailing their hierarchical structures, affiliate programs, and negotiation strategies. These leaked communications have become critical resources for cybersecurity researchers, law enforcement agencies, and incident response teams, allowing them to reconstruct the intricate dynamics of these high-stakes digital bargains and better anticipate future threats. They expose the cold, calculating nature of these operations, where human suffering and organizational integrity are merely variables in a profit-driven equation.
The Persistent Threat: Kairos and the Shadow Economy
Despite the successful payment, the ultimate fate of the stolen data remains ambiguous. Kairos itself has largely gone quiet; its leak site is reportedly down, and its last known victim appeared in June 2026. However, such operational silence should not be mistaken for complete cessation. A wallet definitively tied to Kairos’s operations was observed moving money as recently as May 2026, serving as a stark reminder that a dormant leak site does not equate to a defunct cybercriminal organization. These groups often operate in cycles, rebranding, restructuring, or simply taking a hiatus before re-emerging with new tactics or under new names. The funds acquired through extortion are frequently laundered and reinvested into new infrastructure, tools, and talent, perpetuating the cycle of cybercrime.

Lessons Learned for Small Government Networks and Beyond
The Union County incident, while specific in its details, offers universal and often "dull and familiar" lessons that are nonetheless critical for any organization, especially small governmental entities with constrained resources.
- Mandatory Multi-Factor Authentication (MFA): Kairos reportedly gained initial access by simply guessing a password. MFA, even basic forms, can dramatically increase the difficulty for attackers to gain unauthorized access, even if a password is compromised.
- Vigilant Monitoring for Anomalies: Organizations must implement robust monitoring systems to detect repeated failed login attempts, unusually large outbound data transfers (a clear indicator of exfiltration), and the use of burner file-sharing links, such as the
temp.shaddresses Kairos reportedly utilized to move the stolen files. Early detection is paramount for containment. - Network Segmentation and Data Isolation: Critical and sensitive data, particularly legal, HR, and citizen records, must be rigorously segmented and walled off from the rest of the network. This "least privilege" and "zero trust" approach minimizes the lateral movement of attackers within the network, limiting the scope of potential data exfiltration even if an initial breach occurs.
- Proactive Incident Response Planning: Develop and regularly update a comprehensive incident response plan. This plan should include not only technical steps for containment and recovery but also a predefined public statement strategy. Having a clear communication plan ready before an incident occurs is vital for managing public perception, maintaining trust, and adhering to regulatory notification requirements.
- Skepticism Towards "Proof of Deletion": Organizations should treat any promise from threat actors to delete stolen data with extreme skepticism. As demonstrated by the Kairos case, "proof of deletion" is often just a list of files, offering no verifiable guarantee. The inherent nature of digital data means that copies can be made effortlessly, and there is no practical way to confirm complete deletion by a malicious actor.
- Investment in Cybersecurity Resources: Small counties and municipalities often struggle with limited IT budgets and staff. This incident highlights the critical need for increased investment in cybersecurity talent, tools, and training. Collaboration with state and federal cybersecurity agencies, as well as participation in information sharing and analysis centers (ISACs), can provide much-needed support and intelligence.
- Employee Cybersecurity Awareness Training: The human element remains the weakest link in many security architectures. Regular, engaging training for all employees on phishing, social engineering, password hygiene, and data handling protocols is essential.
The Union County, Ohio, data extortion case serves as a stark reminder of the rapidly evolving threat landscape. Cybercriminals are innovative and adaptable, continuously refining their tactics to maximize profit. For governments, businesses, and individuals alike, the imperative to prioritize cybersecurity, invest in preventative measures, and prepare for inevitable incidents has never been more critical. The long-term implications of such breaches—ranging from financial costs to erosion of public trust—underscore the profound impact of these digital threats on the fabric of society.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
