A US County Paid $1 Million to Hackers Who Never Even Locked a Single File
A newly published case study is pulling back the curtain on how a modern-day extortion deal actually plays out — and it's not the ransomware story most people picture. A hacking group calling itself Kairos hit a small US county government, stole roughly 2 terabytes of data, and got paid about $1 million to not leak it. No encryption. No locked computers. No decryption key ever changed hands, because there was never anything to decrypt.
Researcher Rakesh Krishnan pieced the case together using a leaked negotiation chat log and the bitcoin trail the ransom payment left behind. He doesn't name the victim outright, but the evidence lines up closely with Union County, Ohio, which disclosed a "ransomware" incident back in May 2025 and later told over 45,000 residents and staff their data — Social Security numbers, financial details, even fingerprints and passport numbers — had been stolen.
The negotiation itself reads almost like a haggling session. Kairos opened with a $3 million demand. The county countered with $100,000, crept up to $255,000, then $430,000. Kairos came down to $2 million before drawing a hard line: pay $1 million by Friday, or the files get published — with a folder marked "prosecutors office" singled out as the one that would help criminals dodge charges if it leaked. The county paid on June 13, 2025, ten times its opening offer.
From there, the trail gets more interesting. The roughly 9.44 bitcoin payment was split and funneled through a chain of wallets toward major exchanges, including Bybit, OKX, and a Russian platform called BELQI — the kind of blockchain breadcrumb trail that gives investigators leads, though rarely names. Kairos did send over a so-called "proof of deletion" file afterward, but researchers note it only proves the group once had the files — not that any original copies were actually destroyed. Paying to make stolen data disappear is essentially a leap of faith, and the receipt is written entirely by the person who stole it.
What makes this case worth paying attention to isn't just the county's bad month — it's what it says about where ransomware is heading. Security firm Sophos reported that only about half of ransomware attacks in 2025 still bothered with encryption at all, the lowest share in six years. Groups like Silent Ransom Group have already dropped encryption entirely, running pure data-theft-and-threaten operations instead. Encrypting a network takes time, tools, and effort. Simply stealing files and threatening to publish them is faster, cheaper, and just as effective at getting a payout — which may be exactly why more attackers are skipping the "ransomware" part of ransomware altogether.
For what it's worth, Kairos claims it got in by simply guessing a password — a detail that undercuts a lot of what gets marketed as sophisticated hacking. Security researchers point to the same short list of basics that keeps coming up in these cases: turn on multi-factor authentication, watch for repeated failed logins and large outbound data transfers, keep sensitive records segmented from the rest of the network, and treat any hacker's promise to "delete" stolen data as worth precisely nothing.