A US county reportedly paid $1 million to Kairos, an extortion gang that claimed to have stolen more than 2 TB of data, but the county never received independently verifiable proof that the stolen files had been deleted - just the criminals' promise.This means the county’s stolen files may turn up for sale on a dark web forum, and the same (or another) crime crew could again demand an extortion payment to not leak the data.It’s also a reminder that, despite the feds urging victims not to pay cybercriminals, sometimes coughing up the ransom demand seems to be the lesser of evils.

The alleged incident played out in May and June 2025, according to a case study by threat-intel researcher Rakesh Krishnan on Ransom-ISAC, a global knowledge-sharing platform for defenders and incident responders.

Krishnan based his report on a leaked transcript of the negotiations between the county and Kairos, along with attacker-provided artifacts and screenshots, and payment-tracing evidence on the blockchain.It doesn’t name the ransomware negotiator, citing privacy concerns, nor does it identify the victim, describing it as a US government entity.Communications between the attackers and the public agency, however, suggest it’s a US county, including this one following the attackers’ initial $3 million demand: “We have reviewed the situation with our leadership and financial teams. As a small county with very limited resources, we simply do not have the ability to meet the amount you have proposed. That said, we understand the seriousness of the matter and want to work toward a resolution. The most we have been able to identify at this time is $100,000. We respectfully ask that you consider this offer.”