← All news

ransomware

Union County paid $1M to a crew that never encrypted a thing

2026-07-04

A US government entity handed over roughly $1 million to keep stolen files off the internet. The details come from a case study by Rakesh Krishnan for Ransom-ISAC, pieced together from a leaked negotiation chat and the blockchain trail the payment left behind. File names in the chat, including union.rar and a folder marked prosecutors office, point to Union County, Ohio, which disclosed a ransomware incident in May 2025 affecting 45,487 residents and staff.

The crew never actually encrypted anything

The group behind it calls itself Kairos, and by all appearances it does not deploy an encryptor. No locker, no decryption key, no ransom note about restoring files. Just stolen data and a threat to publish it. Krishnan found no evidence Kairos has ever used ransomware in the traditional sense against any victim.

Which raises an awkward question about the word itself. Sophos reckons only about half of ransomware attacks in 2025 still involve encryption, the lowest share in six years. Crews like Silent Ransom Group ditched the encryptor years ago. The label now covers everything from locked servers to plain theft with a threat attached.

A month of haggling

Kairos opened at $3 million, claiming to hold 2 terabytes and 1.6 million files. The county started at $100,000, drifted up through $255,000 and $430,000, and eventually settled at $1 million after Kairos set a hard Friday deadline.

Payment landed on 13 June 2025 as roughly 9.44 bitcoin. Within hours it was split and funnelled through wallets tied to Bybit, OKX, and a Russian exchange called BELQI. A wallet in the chain was still moving funds as recently as May 2026.

In return, the county received a proof of deletion file. It is not proof of anything. It is a list of names showing the attacker once had the data. Whether Kairos actually deleted it, nobody outside Kairos can say.

The uncomfortable detail

Buried in the negotiation chat is the line that lands harder than any technical write-up. Kairos told the negotiator how it got in: it guessed a password.

Not a zero-day. Not a supply-chain compromise. Not some baroque exploit chain. Someone picked a weak password, and a US county ended up nearly a million dollars lighter and 45,487 people ended up in a breach notification.

The leak site is down and Kairos has gone quiet, at least for now. For the small councils, school boards and county offices watching this from a distance, the difficult bit is not the sophistication of the attacker. There isn't much. It is the way in.

Password hygiene is one of those topics that sounds boring right up until the moment a bitcoin wallet in Russia is a million dollars richer. A guessed password shouldn't get anyone into a system that holds records on 45,000 people. If it does, the fix is not more software. It is the humans and the habits behind them.

Union County paid $1M to a crew that never encrypted a thing | RiskSense