A small Ohio county paid the Kairos cyber extortion gang $1 million to prevent the public release of over 2 TB of stolen personal data. The case highlights the vulnerability of local governments to data‑extortion attacks.

According to a Ransom‑ISAC briefing, a U.S. government entity paid a $1 million Bitcoin ransom to the Kairos cyber extortion group after a May 2025 intrusion threatened to expose massive amounts of sensitive information. Kairos originally demanded $3 million in cryptocurrency, but after three weeks of negotiation the settlement was reduced.

Incident Overview

The leaked negotiation transcript shows the county initially offered $100,000, later raised it to $430,000, and finally accepted a hard deadline with a $1 million payment on June 13. The attackers leveraged the prospect of public exposure while providing selective proof‑of‑deletion that could not be independently verified.

Who Is Kairos?

Kairos is a specialized extortion outfit that avoids traditional ransomware encryption. Instead, it steals data and threatens to publish it, forcing victims to buy time while legal, leadership, financial, and communications teams align their response, as noted by Ransom‑ISAC.

Scope of the Theft

The group claimed to have exfiltrated more than 2 terabytes of data—approximately 1.6 million files—through a brute‑force attack on the county’s network. Stolen records included names, dates of birth, driver’s license and passport numbers, Social Security numbers, financial account details, fingerprints, medical information, and payment‑card data. In September, the county notified 45,487 residents of the breach.

Financial and Legal Implications

Paying an extortion demand is often a calculated move to mitigate immediate legal and reputational damage, yet it can embolden attackers and set a precedent for future crimes. Small jurisdictions with limited cyber‑incident response resources are especially prone to such payments.

Future Security Challenges

Experts argue that local governments must prioritize data encryption, multi‑factor authentication, and continuous network monitoring. Strengthening information‑sharing partnerships with entities like Ransom‑ISAC is also critical to detect and disrupt extortion campaigns before they reach a tipping point.

While Union County, Ohio has not yet issued a formal comment, the episode underscores the growing threat of cyber‑extortion and the preparedness gap among municipal bodies.