← All news

ransomware

Ohio County Reportedly Paid $1M to Kairos Extortion Crew

2026-07-08

A rural county government in Ohio appears to have paid $1 million in Bitcoin to a cyber extortion crew calling itself Kairos, according to a leaked negotiation transcript published by Ransom-ISAC. The victim is reportedly Union County, which disclosed in September that a May 2025 intrusion had exposed the personal information of 45,487 people.

Not your standard data grab

The stolen material was well beyond the usual name-and-email haul. It included Social Security numbers, driver's licence and passport details, financial account information, payment card data, medical records, and fingerprint data. Kairos claimed to have taken more than two terabytes, roughly 1.6 million files, after brute-forcing its way into the county's environment.

For a county of this size, that is essentially a full civic dossier on tens of thousands of residents. Fingerprints in particular are not something you rotate the way you rotate a password.

Three weeks of stalling

The negotiation ran for about three weeks. Kairos opened at $3 million. The county opened at $100,000, drifted up to $430,000, then folded at a hard deadline and paid the full $1 million on 13 June. Ransom-ISAC reads the back-and-forth as an organisation buying time while lawyers, leadership and communications staff worked out what they were actually willing to do.

That is not unusual. Ransom negotiations are rarely about the price. They are about whoever is on the receiving end trying to work out how much reputational and legal damage they can absorb, and how quickly.

No encryption, just the threat

The interesting wrinkle here is that no files were encrypted. This was pure extortion, built entirely on the threat of publishing what had been taken. There was no operational recovery to worry about, no systems to restore. The only thing on the table was silence.

Paying for silence is a bet, and it is a bet with terrible odds. The "proof of deletion" Kairos handed over was, in Ransom-ISAC's phrasing, selective rather than comprehensive. There is no way to confirm the data was actually destroyed. Only that a copy, somewhere, may have been.

The awkward maths of paying

Once a criminal group has a full copy of your residents' medical records and fingerprint data, the payment does not undo that fact. It buys a promise from people whose entire business model is breaking promises. Regulators know this, insurers know this, and the FBI has been saying it out loud for years.

There is also the small matter of what happens next. A crew that just received a million dollars from a small Ohio county now knows that small Ohio counties will pay. Other small counties, and everyone downstream who does business with them, should probably assume that maths is being done somewhere right now.

What actually would have helped

The intrusion reportedly started with brute-forcing. That is not a sophisticated technique. It is the digital equivalent of trying every key on a ring until one turns. Multi-factor authentication, sensible lockout policies, and staff who recognise a suspicious login prompt when they see one would have made the opening move considerably harder.

None of that is glamorous. It is also, roughly, the difference between a million-dollar problem and a Tuesday.

Ohio County Reportedly Paid $1M to Kairos Extortion Crew | RiskSense