CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

July 4, 2026

A U.S. government entity paid approximately $1 million to prevent the leak of stolen files, according to a case study by Rakesh Krishnan for Ransom-ISAC. The group behind the extortion, Kairos, did not deploy ransomware or encrypt any systems; instead, it relied solely on data theft and threats of public exposure. The negotiation lasted about a month, with Kairos initially demanding $3 million and eventually settling for $1 million, paid in 9.44 BTC on June 13, 2025. The funds were traced through wallets to exchanges Bybit, OKX, and the Russian service BELQI. The victim is believed to be Union County, Ohio, which reported a ransomware incident in May 2025 affecting 45,487 residents. The case highlights the growing trend of pure data-theft extortion, where encryption is skipped entirely. Sophos reported in 2025 that only about half of ransomware attacks still involve encryption, the lowest rate in six years. Groups like Silent Ransom Group, a Conti offshoot, have operated without encryptors for years. The article advises organizations to implement multi-factor authentication, monitor for unusual data transfers, segment sensitive data, and prepare public statements in advance.

CVEs: CVE-2026-55200, CVE-2026-46817

Attack groups: Kairos, Silent Ransom Group, Conti, Black Basta

Companies: Bybit, OKX, Sophos

Service providers: BELQI