A small Ohio county government reportedly paid $1 million to a cyber extortion group to stop stolen records from being published. Ransom-ISAC says Kairos stole more than 2 terabytes of data, about 1.6 million files, in a May 2025 intrusion that began with a brute-force attack, then negotiated down from a $3 million demand; the incident reportedly involved data theft and extortion rather than file encryption. The victim appears to be Union County, Ohio, which previously disclosed that 45,487 people were affected and that exposed data included Social Security numbers, passport and driver's license details, financial and payment-card data, fingerprint data, and medical information.
Why it matters: This matters because a local government reportedly lost highly sensitive resident data and paid a large ransom despite no way to verify deletion. Government organizations should review exposed remote access points for brute-force weaknesses, harden authentication, and prepare for theft-and-extortion incidents even when ransomware encryption is not used.
2026.07.09
97% relevant
This article is the core reporting behind that event, adding leaked negotiation details, the gang’s claimed theft of more than 2 TB and 1.6 million files, the reduction from a $3 million demand to a $1 million payment, and the possible link to Union County, Ohio.
Ionut Arghire
2026.07.07
100% relevant
This article appears to be the first tracked item establishing the underlying event: the suspected Union County, Ohio, 2025 intrusion and subsequent $1 million payment to the Kairos extortion group.
← Back to all stories