County Government Reportedly Paid $1 Million to Cyber Extortion Group

A US County Government Paid a $1 Million Ransom to Cyber Extortionists, and It Matters

The small Union County government in Ohio has made headlines for all the wrong reasons. According to reports, the county paid a staggering $1 million ransom to the Kairos cyber extortion group after they threatened to publicly release sensitive information stolen during a 2025 intrusion. This is not just a story about a large payout; it’s a stark reminder of how vulnerable government institutions can be to cyber threats and the high stakes involved in dealing with extortionists.

The breach occurred when Kairos gained access to the county’s environment through a brute-force attack, stealing over 2 terabytes of data – approximately 1.6 million files. The attackers demanded $3 million from the victim organization but eventually settled for $1 million after a three-week negotiation. The ransom was paid in Bitcoin on June 13. What’s striking is that the affected entity initially offered only $100,000 and later increased it to $430,000 before agreeing to pay the higher amount.

The anti-ransomware organization Ransom-ISAC notes that this incident was an extortion attack rather than a file-encrypting ransomware attack. The attackers provided proof of deletion, but Ransom-ISAC suspects this could have been generated by erasing a copy of the data and not independently verified. This highlights the challenges in verifying such claims.

What’s particularly concerning is that this affected organization appears to be one of the many entities struggling with limited resources. Despite its best efforts, it was pressured into making a significant payment to prevent public exposure of sensitive information. The county had previously notified over 45,000 individuals whose personal data was stolen during the initial attack in May 2025.

The fact that this incident has come to light is partly due to leaked negotiation transcripts and Ransom-ISAC’s involvement. While it’s understandable that governments may choose to pay ransoms in extreme cases, the financial burden and potential legal implications should not be underestimated. The case highlights the need for better cybersecurity measures and preparedness, especially among government institutions with limited resources.

For readers who manage or oversee sensitive data, this incident serves as a stark reminder of the importance of robust cybersecurity measures and having clear incident response plans in place. It’s also crucial to understand that paying ransoms does not guarantee protection against public exposure, and attackers may still choose to release stolen data regardless of payment. Prioritizing prevention, preparedness, and effective communication are key to mitigating the impact of such incidents.


Source: SecurityWeek — 2026-07-07