IC Technology & Cyber — 2026-07-06

Ransom-ISAC Reveals US Government Entity Paid One Million Dollars to Data Extortion Group Kairos

BLUFKairos's million-dollar payday without deploying any encryptor validates pure data-extortion as a viable model and will draw lower-skilled actors toward under-resourced local governments.

Ransom-ISAC published a case study by researcher Rakesh Krishnan, corroborated by The Hacker News and TheNextWeb, reporting that a U.S. government entity paid roughly $1 million in Bitcoin on June 13, 2025 to a group calling itself Kairos after a 28-day negotiation that opened at $3 million 123. Kairos claimed initial access on May 19, 2025 through a brute-force credential attack, listed the victim on its leak site two days later citing over 1.6 million stolen files across 2TB, and has never been linked to a ransomware sample or encryptor 1. Security Affairs' research ties the case to a breach Union County, Ohio disclosed in May 2025, notifying 45,487 residents and employees that Social Security numbers, financial details, fingerprints, and passport data were taken after network access between May 6 and 18, though neither the county nor Kairos has confirmed the link 1. Blockchain tracing found the roughly 9.44 BTC payment split within hours toward exchanges including ByBit, OKX, and a Russian exchange called BELQI 1.

Analysis
Kairos's success without any confirmed ransomware capability demonstrates to other data-theft actors that leak-site pressure and staged deadlines can extract seven-figure payments from resource-constrained local governments, a model that lowers the capability threshold for targeting small public-sector entities through the rest of 2026. The unverifiable "proof of deletion" means Union County's exposure risk persists regardless of payment, since exchange-linked funds moving through OKX, ByBit, and a Russian exchange give investigators leads but no enforcement mechanism to compel actual data destruction. Confidence in the significance of this precedent is moderate, resting on a single detailed case reconstruction rather than a broader sample of confirmed copycat incidents.
4 sources
  1. U.S. Government Agency Paid $1M to Data Extortion Group Kairos - Security Affairs
  2. U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case - The Hacker News
  3. US government body paid $1M in data-theft extortion - TheNextWeb
  4. Kairos Ransomware: Data-Extortion Case Study Involving a U.S. Government Entity - Ransom-ISAC

View in full brief →

UNCLASSIFIED // OPEN SOURCE