Thenextweb US Government Agency Paid $1M to Data Extortion Group Kairos
Article Content
- •A U.S. government agency paid $1 million to Kairos to prevent data leaks.
- •The extortion involved no encryption, focusing instead on keeping stolen files private.
- •The incident may be linked to Union County, Ohio, which experienced a data breach affecting over 45,000 individuals.
A U.S. government entity reportedly paid $1 million to the Kairos extortion group to prevent the public release of sensitive data. The payment was revealed in a Ransom-ISAC case study, which utilized a leaked negotiation chat and blockchain analysis. The incident appears to involve Union County, Ohio, although neither the county nor Kairos has confirmed this link. The extortion group did not employ traditional ransomware tactics, as there was no encryption or demand for a decryption key. Instead, they threatened to publish stolen files, including sensitive personal information from approximately 45,487 individuals. The negotiation lasted a month, with the initial demand set at $3 million, which was eventually settled at $1 million. The payment was made in bitcoin and subsequently laundered through various wallets. This case illustrates the evolving nature of ransomware, which increasingly involves extortion without encryption.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Black Basta and Union County, Ohio in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Emerging EDR Killer Tool Targeting Ransomware Groups A new malicious tool, referred to as the EDR killer, is being actively used by at least eight ransomware groups, including Blacksuit and Medusa, to disable endpoint detection and response (EDR) solutions. This tool is believed to be an evolution of the EDRKillShifter developed by RansomHub, which allows ransomware…
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…