In May 2025, Union County, Ohio, fell victim to a cyber extortion attack led by a group named Kairos. The hackers accessed the county's system through a brute-force attack, thereby obtaining over 2 terabytes of sensitive data.
Rather than employing traditional ransomware methods, Kairos utilized a pure data extortion scheme, demanding payment to prevent them from releasing the stolen data publicly.
Initially demanding $3 million, the group negotiated down to a $1 million payout. The negotiation spanned several weeks, during which the county's offers ranged from $100,000 to $430,000 before agreeing to the final payment in Bitcoin on June 13.
Union County's responses during negotiations appeared to focus on buying time to coordinate legal and organizational strategies.
The breach affected more than 45,000 residents and staff, placing significant pressure on the county due to confidentiality concerns linked to the compromised data.
The incident has highlighted potential vulnerabilities within government systems and signifies a shift in attack methods, leveraging data theft without direct file encryption to extract ransom payments.
This case demonstrates a growing threat from cybercriminal groups adopting new strategies of extortion that bypass the need to hijack system operations, focusing instead on the threat of data exposure.
The breach of such a significant amount of data underscores the urgent need for robust data security measures within government entities to protect against exploitation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Union County, Ohio, reportedly paid $1 million to Kairos to prevent the public release of stolen data following a May 2025 cyber intrusion. The settlement came after a prolonged negotiation, where Kairos initially demanded $3 million for over 2 terabytes of sensitive information.
A U.S. government entity paid approximately $1 million to avoid the public release of stolen data, highlighting an extortion model where no ransomware was involved. This case underscores the increasing vulnerability of government systems to data theft and extortion threats.