State and local governments across the United States have become prime targets for cybercriminals due to the sensitive nature of the data they hold and their often limited cybersecurity budgets. According to a new report from Ransom-ISAC, one such government body paid a seven-figure ransom to a cyber extortion group after a data breach in May 2025. The incident, which involved the Kairos cyber extortion group, highlights the growing trend of pure extortion attacks in which adversaries steal data and threaten to publish it rather than encrypting files.
Ransom Payment Details
Ransom-ISAC, an organization that tracks ransomware and extortion activity, said the affected government entity paid approximately $1 million in Bitcoin to Kairos on June 13. The payment followed a three-week negotiation that started with the extortionists demanding $3 million in cryptocurrency. According to a leaked negotiation transcript, the victim initially offered $100,000. Over the course of the discussions, the victim raised its offer to $430,000 before finally agreeing to the $1 million demand.
Kairos applied significant pressure throughout the negotiation process, threatening to publicly expose the stolen data if the victim did not meet its demands. The attackers also controlled key elements of the engagement, including deadlines and proof-of-access artifacts, maintaining the upper hand from the first contact to the final Bitcoin transaction.
Stolen Data and Attack Method
The extortion group claimed to have accessed the victim's IT environment through a brute-force attack, a method that involves repeatedly attempting credentials until the correct ones are discovered. Once inside, Kairos said it copied more than 2 terabytes of data, roughly 1.6 million files. The exfiltrated information included names, dates of birth, driver’s license and state identification numbers, passport numbers, Social Security numbers, financial account details, fingerprint information, medical information, and payment card details.
These categories of data are particularly damaging in the hands of criminals. Identity theft, financial fraud, and medical identity abuse are all potential consequences for the individuals whose records were exposed. Government agencies collect such information for essential public services, making them attractive targets despite the relatively small size of the organizations involved.
Evidence of Deletion Questioned
One notable aspect of the incident is that Kairos presented the victim with proof that the stolen data had been deleted after the ransom was paid. However, Ransom-ISAC expressed skepticism about the adequacy of that proof. The organization noted that the proof-of-deletion appears selective rather than comprehensive. The listings provided by the attackers are consistent with a real file-server scrape, but the evidence could also have been generated by simply erasing a copy of the data held by the extortionists. Crucially, no mechanism was provided that would allow an independent third party to verify the deletion.
This is a common problem in extortion incidents. Even when a ransom is paid, victims have no guarantee that the criminals have actually destroyed the stolen information. In many cases, data is sold on cybercriminal forums, used in secondary attacks, or retained for future extortion attempts. The lack of independent verification leaves victims in a position of uncertainty long after the payment has been made.
No File-Encrypting Ransomware Involved
Ransom-ISAC also clarified that the incident did not involve file-encrypting ransomware. Instead, it was purely an extortion operation. The attackers stole the data and threatened to publish it if the ransom was not paid. This distinction is important for understanding the operational model of groups like Kairos. By skipping encryption, attackers can reduce technical noise and potentially evade detection for longer periods. They also avoid the operational burden of developing or deploying a reliable encryptor, focusing instead on data theft and psychological pressure.
Pure extortion attacks have been rising in recent years as many victim organizations have improved their ability to restore encrypted systems from backups. When encryption no longer guarantees a payout, attackers often turn to data theft and public disclosure as a more reliable form of leverage. This shifts the calculus for victims because the data itself may have compliance and privacy implications that cannot be resolved through technical restoration alone.
Victim Likely Union County, Ohio
Ransom-ISAC did not name the affected government body in its report. However, the negotiation transcript describes the victim as "a small county with very limited resources." Based on public records and the timeline of events, the affected organization appears to be Union County, Ohio. In September, the county issued a notification to 45,487 individuals informing them that their personal information had been stolen during a security incident in May 2025. The notification, which was posted as a PDF on the county's website, describes the event as a ransomware attack and lists the types of data that were potentially compromised.
Union County is a predominantly rural county in central Ohio. Like many small jurisdictions, it relies on a limited IT staff and budgets that are stretched across multiple public services. Cybersecurity, while increasingly important, often competes with road maintenance, public safety, and other immediate needs. The reported $1 million ransom payment, if confirmed, would represent an enormous financial blow to a county government with such limited resources.
Data Breach Notification and Public Impact
The county's breach notification revealed that the stolen information included a broad range of personal identifiers and sensitive records. Social Security numbers, passport numbers, financial account details, fingerprint data, and medical information were all among the exposed categories. The breadth of the data suggests that the attackers had access to multiple systems within the county's network, possibly including departments responsible for public health, vehicle registration, and law enforcement support functions.
For affected individuals, the exposure of such information carries long-term risks. Unlike a credit card number that can be canceled and reissued, a Social Security number or fingerprint cannot be changed. Victims may face fraudulent tax filings, loan applications made in their names, and other forms of identity theft for years. Medical records, too, can be used to submit false insurance claims or obtain prescription drugs, causing further financial and legal complications.
The Broader Cyber Extortion Landscape
The Kairos incident is part of a broader wave of cyber extortion activity aimed at public-sector entities. State and local governments are often perceived as soft targets because they maintain extensive legacy systems, struggle to recruit cybersecurity talent, and cannot easily absorb the costs of a prolonged network outage or data exposure. In recent years, numerous counties, school districts, and municipal governments have been forced to pay ransoms or deal with the consequences of public data dumps.
Ransom-ISAC's role in documenting this incident reflects a growing effort among private-sector organizations to track and analyze extortion trends. By collecting leaked transcripts, monitoring dark web leak sites, and coordinating with affected entities, these organizations provide valuable intelligence that can help other potential victims understand the tactics, negotiation patterns, and technical signatures used by cybercriminal groups.
Tactics Used by the Attackers
The leaked negotiation transcript offers a rare glimpse into how cyber extortionists operate. Kairos used a combination of time pressure, public exposure threats, and controlled evidence disclosures to keep the victim off balance. The group was careful not to provide all the stolen data to the victim during negotiations, only sharing enough to prove that they had access and intended to follow through on their threats.
The attackers also maintained strict deadlines, applying a sense of urgency that is designed to prevent victims from conducting a more measured response. Ransom-ISAC observed that the affected entity's responses were consistent with an organization trying to buy time while legal, leadership, financial, and communications decisions were coordinated. That behavior is typical in incidents involving public agencies, where multiple stakeholders must be consulted before any major expenditure is approved.
Role of Legal and Leadership Teams
When a government entity discovers a breach and receives an extortion demand, the response is rarely straightforward. Legal counsel must assess regulatory notification obligations, law enforcement agencies may need to be informed, and financial officers have to determine whether a ransom payment is even legal under applicable sanctions and insurance policies. In the Union County case, the negotiation transcript suggests that these considerations were actively in play, which helps explain why the victim's offers increased only gradually over several weeks.
The decision to pay a ransom is controversial among cybersecurity professionals. Law enforcement agencies, including the FBI, generally discourage ransom payments because they fund further criminal activity and do not guarantee the safe return of data. However, in cases where the exposure of sensitive personal information could cause immediate and severe harm to thousands of residents, some officials choose to pay as a last resort. Whether that decision was ultimately the right one for Union County is a question that only local leaders and their constituents can answer.
Lessons for Other Small Governments
This incident serves as a reminder that cybersecurity is not just a technology issue but a risk management issue that affects every level of government. Small counties often assume they are too insignificant to attract the attention of sophisticated cybercriminals. The Kairos attack demonstrates that any organization holding valuable personal data can become a target. Attackers are opportunistic and are drawn to weak security controls rather than the prominence of the victim.
Basic protective measures, such as enforcing strong passwords, implementing multi-factor authentication, and patching vulnerabilities, can go a long way toward preventing brute-force attacks. However, many small government agencies lack the resources to implement these measures comprehensively. The presence of legacy systems and the difficulty of finding experienced security staff compound the problem. State and federal assistance programs have begun to address this gap, but progress remains slow and uneven.
Verification Challenges After Ransom Payment
Even after the ransom was paid, the victim was left without reliable proof that the data had been destroyed. This is a recurring theme in extortion incidents. Cybercriminals have little incentive to honor their promises, and the absence of a trusted third party capable of verifying deletion makes it almost impossible for victims to know the true state of their stolen data. Some organizations attempt to monitor dark web marketplaces for signs of their data, but the vast availability of stolen information makes such monitoring difficult and inconclusive.
Ransom-ISAC's analysis suggests that the proof-of-deletion provided by Kairos was carefully curated. Rather than offering a live demonstration of deletion or engaging an independent auditor, the attackers showed listings that could have come from any copy of the data. The absence of a comprehensive verification process leaves open the possibility that the stolen information is still circulating in criminal channels. This uncertainty deepens the long-term impact of the breach, as affected residents cannot assume that their personal data is no longer at risk.
Response From the County
In the aftermath of the reported ransom payment, Union County has not publicly confirmed or denied the specifics of the Ransom-ISAC report. Journalists have sought comment from county officials, but no response has been provided. The county's September breach notification remains the primary source of public information about the May 2025 incident. The notification described the event as a ransomware attack, a characterization that appears to be at odds with Ransom-ISAC's assessment that no file-encrypting malware was used. That discrepancy may simply reflect the way the county chose to classify the incident for public communication, or it may indicate a difference in how the initial intrusion was perceived by the victims.
The lack of a detailed public statement from the county is not unusual in the wake of a cyber incident. Government officials often withhold information while investigations are ongoing and while they work with law enforcement and cybersecurity consultants. However, the public is likely to continue pressing for answers, especially given that 45,487 residents were affected and that the reported ransom payment represents a substantial financial cost to a small community.
The case also raises important questions about the effectiveness of cyber insurance, negotiating strategies, and whether it is ever advisable to engage with extortionists. There is a significant divide between those who advocate zero negotiation with cybercriminals and those who see ransom payments as a practical, if painful, way to reduce harm. As extortion groups become more specialized and sophisticated, these questions will only become more urgent for organizations of all sizes.
For now, Ransom-ISAC's report offers a detailed account of what happened, even if some details remain unresolved. The identity of the victim has not been officially confirmed by the reporting organization, and the full scope of the data exposure is still unknown. What is certain is that a government entity in the United States found itself facing a difficult financial and operational decision after a network intrusion, and it ultimately chose to pay a seven-figure ransom in the hope of preventing the release of sensitive constituent data.
Source: SecurityWeek News