Biphoo.eu - Guest Posting Services

collapse
Home / Daily News Analysis / County Government Reportedly Paid $1 Million to Cyber Extortion Group

County Government Reportedly Paid $1 Million to Cyber Extortion Group

Aug 03, 2026  Twila Rosenbaum  14 views
County Government Reportedly Paid $1 Million to Cyber Extortion Group

A government entity in the United States reportedly paid a $1 million ransom to the Kairos cyber extortion group to prevent the public release of data stolen during a May 2025 intrusion, according to a report from Ransom-ISAC, an anti-ransomware organization that monitors extortion activity.

The revelation came through a leaked negotiation transcript that details a three-week back-and-forth between the attackers and the unnamed victim organization. The extortion group initially demanded $3 million in cryptocurrency, but ultimately accepted a payment of $1 million. That payment was made in Bitcoin on June 13, according to the report.

Kairos claimed to have accessed the victim's environment via a brute-force attack and exfiltrated more than 2 terabytes of data, or roughly 1.6 million files. The victim, described in the transcript as "a small county with very limited resources," reportedly attempted to negotiate the ransom down, raising its offer from $100,000 to $430,000 before eventually accepting the attackers' hard deadline and the $1 million figure.

Attack Details and Negotiations

The leaked transcript paints a tense picture of a small government body trying to navigate an unprecedented crisis. The attackers pressured the victim with the threat of public exposure, while maintaining strict control over deadlines and proof-of-access artifacts. According to Ransom-ISAC, the affected entity's responses were consistent with an organization "buying time while legal, leadership, financial, and communications decisions were coordinated."

This is a common pattern in high-stakes extortion negotiations. Victims often attempt to stall, verify the legitimacy of the attacker's claims, and consult with legal counsel and cybersecurity experts before making any payment decisions. In this case, the county's initial counteroffer of $100,000 was far below the $3 million demand, and the attackers apparently rejected it. The victim then moved to $430,000, but the extortionists held firm, setting a hard deadline that ultimately led the county to agree to the $1 million payment.

The fact that the payment was made in Bitcoin is typical of cyber extortion operations, as cryptocurrency provides a degree of pseudonymity for the recipients. Law enforcement agencies have increasingly worked with cryptocurrency exchanges and blockchain analysis firms to trace such payments, but recovering funds after a ransom is paid remains exceedingly difficult.

A Growing Shift to Pure Extortion

The incident also underscores a notable shift in the cybercriminal landscape: the rise of what researchers call "pure extortion" attacks. Unlike traditional ransomware, which encrypts files and demands payment for the decryption keys, pure extortion involves stealing sensitive data and threatening to publish it unless a ransom is paid. In some cases, attackers do both, but in this incident, no file-encrypting ransomware was deployed.

Ransom-ISAC noted that the attackers' proof-of-deletion appeared selective rather than comprehensive, and that the listings they provided were consistent with a real file-server scrape. However, the organization cautioned that the proof could have been generated by erasing a copy of the data, and that no mechanism was provided to independently verify deletion. This raises the uncomfortable possibility that the county's data may still be in the hands of the extortionists, even after the payment.

The use of brute-force attacks to gain initial access is another concerning trend. Brute-force attacks involve systematically guessing usernames and passwords until one combination works. This highlights the importance of strong, unique credentials and the implementation of multi-factor authentication on all remote access points. Governments, in particular, often struggle with legacy systems and limited IT budgets, making them attractive targets for such attacks.

Union County Connection

Ransom-ISAC did not name the affected organization, but the negotiation transcript identifies it as "a small county with very limited resources." All available evidence points to Union County, Ohio. In September, the county notified 45,487 individuals that their personal information had been stolen in a ransomware attack in May 2025. The timing of the intrusion and the description of the entity align closely with the Ransom-ISAC report.

Union County is a mostly rural county in central Ohio, with a population of roughly 60,000 residents. Local government IT departments in such areas often operate with small teams and constrained budgets, making them particularly vulnerable to sophisticated cybercriminals. The notification sent to affected individuals listed a wide range of sensitive data that was compromised, including names, dates of birth, driver's license or state ID numbers, passport numbers, Social Security numbers, financial account details, fingerprint information, medical information, and payment card details.

The breadth of the stolen data is alarming. With this information, cybercriminals can commit identity theft, open fraudulent accounts, file fake tax returns, and even obtain medical services in the victim's name. The long-term consequences for the affected individuals could be severe, and the county's decision to pay the ransom, while controversial, may have been driven in part by a desire to prevent the public release of such intimate data.

What Was Stolen

The detailed list of stolen information reveals the sheer volume and sensitivity of the data maintained by local governments. Names and dates of birth are common identifiers, but passport numbers and Social Security numbers are much more dangerous if exposed. Financial account details can be used for direct financial fraud, while fingerprint information is particularly concerning because, unlike passwords, biometric data cannot simply be changed. Medical information is also valuable on the black market, as it can be used for insurance fraud and other schemes.

This breach is a stark reminder that local governments are not just custodians of public records; they are also guardians of highly personal data. From property records to court documents to health department files, county governments store a wealth of information that cybercriminals can monetize. Yet many counties lack the resources to implement robust cybersecurity measures, and they often rely on outdated software and minimal staff training.

Lessons for Local Governments

Experts say the incident illustrates several critical lessons for government agencies at all levels. First, the threat of data extortion is real and growing, and no organization, regardless of size, is immune. Second, proactive measures such as regular data backups, network segmentation, employee training, and incident response planning are essential. Third, engaging with law enforcement and cybersecurity experts before making any ransom payment is critical, as paying ransoms can fund further criminal activity and does not guarantee the destruction of stolen data.

The case also highlights the importance of transparency with affected individuals. While Union County has not publicly confirmed the ransom payment, the breach notification it issued allows residents to take steps to protect themselves, such as monitoring their credit and changing passwords. Quick and clear communication is vital after a breach, even if the full details of the incident are not immediately disclosed.

The Ransom-ISAC report serves as a cautionary tale for the public sector. As cybercriminals continue to refine their tactics, government agencies must adapt their defenses and their response strategies. The decision to pay a ransom is never easy, and in this case, it is unclear whether the county will ever see any tangible benefit from the $1 million payment beyond the attackers' unverified assurance that the data has been deleted. What is clear, however, is that the threat of cyber extortion is not going away, and local governments will likely remain prime targets for years to come.


Source: SecurityWeek News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy