HackMyIP
← Back to News
2026-07-04 The Hacker News

Union County Ohio Paid $1M in Bitcoin to Kairos Extortion Group

RansomwareData BreachThreat Intel

A U.S. government entity—almost certainly Union County, Ohio—paid roughly $1 million in bitcoin to a group calling itself Kairos to suppress the leak of stolen files, according to a new case study by researcher Rakesh Krishnan for Ransom-ISAC. The findings, built on a leaked negotiation chat and on-chain blockchain analysis, suggest Kairos is not a ransomware operation in the traditional sense. Krishnan found no evidence of an encryptor, locker, or decryption demand; the threat was pure data extortion. Files referenced in the chats—including "Union.xlsx," "1 union co psi template.doc," and a final archive called "union.rar"—line up with a May 2025 incident in which Union County disclosed a network intrusion that exposed 45,447 residents and staff, with stolen records spanning Social Security numbers, financial details, fingerprints, and passport numbers.

The negotiation stretched roughly a month, opening at $3 million from Kairos, which claimed possession of more than 2 terabytes of data containing 1.6 million files. The county countered at $100,000, climbing to $255,000 and then $430,000, before Kairos imposed a hard deadline: $1 million by Friday or the files would be published. The county paid on June 13, 2025, transmitting approximately 9.44 BTC—worth about $1 million at the time. Krishnan traced the funds through a chain of wallets toward deposit addresses tied to Bybit, OKX, and the Russian crypto service BELQI. Defenders investigating similar exposures can start with an email breach checker to determine whether stolen credentials are already circulating, or a WHOIS lookup to map infrastructure tied to known extortion operators.

Kairos leaned on familiar psychological levers—countdown timers, tight deadlines, and tiered threats to release the most damaging folders first, including one labeled "prosecutors office" that the attacker warned would help defendants evade charges. After receiving payment, Kairos delivered a "proof of deletion" file, but the artifact contained only a list of file names, not evidence that the originals had actually been wiped. Krishnan's case study highlights a troubling reality: in modern extortion, paying for deletion is an act of faith, and the receipt is written by the thief. The semantic distinction matters—what governments and incident responders still reflexively call "ransomware" is increasingly just data theft with a price tag and no encryption involved.

For organizations looking to reduce their leverage in a future negotiation, the case underscores the value of proactive hygiene. Running a DNS leak test to validate network egress, an SSL/TLS checker to audit exposed services, or a privacy checkup to surface leaked data are small steps that, in aggregate, shrink an attacker's footing. Union County has not publicly confirmed the $1 million payment, and The Hacker News has reached out to the Union County Commissioners' Office for comment.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →