A Small County Government Pays $1 Million Ransom to Cyber Extortion Group, Leaving Questions About Data Protection
In a concerning development, a small county government in the US has reportedly paid a $1 million ransom to the Kairos cyber extortion group after they stole over 2 terabytes of sensitive data. The incident highlights the growing threat of cyber extortion and raises questions about the effectiveness of data protection measures.
The attackers accessed the victim’s environment through a brute-force attack in May 2025, stealing approximately 1.6 million files. In negotiations with the victim, Kairos initially demanded $3 million in cryptocurrency but eventually settled for $1 million after the victim increased its offer from $100,000 to $430,000. The ransom was paid on June 13, and the attackers claimed they had deleted the stolen data.
However, security experts have raised concerns about the attackers’ proof of deletion, which appears to be selective rather than comprehensive. Ransom-ISAC notes that the provided proof could have been generated by erasing a copy of the data, without any mechanism to independently verify the deletion. This raises questions about the integrity of the data and the effectiveness of the extortion group’s claims.
The affected government body is reportedly Union County, Ohio, which notified 45,487 individuals in September that their personal information was stolen in a ransomware attack in May 2025. The stolen data included sensitive information such as Social Security numbers, financial account details, and medical records.
This incident highlights the growing threat of cyber extortion, where attackers demand payment in exchange for not releasing stolen data. While paying the ransom may have prevented public exposure of the stolen data, it does not address the underlying security issues that allowed the attack to occur in the first place. It also raises questions about the effectiveness of data protection measures and the ability of organizations to protect sensitive information.
The incident serves as a reminder for organizations to prioritize robust cybersecurity measures, including regular backups, secure data storage, and employee education on cyber hygiene practices. While paying ransoms may provide temporary relief, it is essential to address the root causes of these attacks and invest in long-term security solutions that can prevent such incidents from occurring in the first place.
In light of this incident, organizations should review their cybersecurity posture and ensure they have adequate measures in place to protect sensitive data. This includes conducting regular security audits, implementing robust access controls, and investing in employee education on cyber hygiene practices. By taking proactive steps to secure their networks and systems, organizations can reduce the risk of falling victim to similar attacks and protect the sensitive information they hold.
Source: SecurityWeek — 2026-07-07