The Register Home Page

back to article An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals

A US county reportedly paid $1 million to Kairos, an extortion gang that claimed to have stolen more than 2 TB of data, but the county never received independently verifiable proof that the stolen files had been deleted - just the criminals' promise. This means the county’s stolen files may turn up for sale on a dark web forum, …

  1. This post has been deleted by its author

    1. RM Myers
      FAIL

      Re: Lovely...

      Did you read the article? The evidence for Union County seems fairly compelling. Besides, $3 million would be less than 1/2 % of Franklin County's annual budget, so I doubt they could successfully claim poverty. And the budget is public information readily available on the internet.

  2. lglethal Silver badge
    Facepalm

    Pay the Geld and you'll never get rid of the Dane...

    Old saying, still relevant today...

    Yes, I'm suuuure they got in through brute forcing, and not through some other vulnerability that still remains vulnerable.

    And once in I guarantee they didnt install any backdoors or trojans, that will let them get in again at a later date.

    Under another name of course. I mean Kairos has promised not to attack them again. However, Lairos, Mairos, and Nairos have made no such promises...

    1. DS999 Silver badge

      Re: Pay the Geld and you'll never get rid of the Dane...

      Even if Kairos was honest in making those commitments and really did delete the data, didn't leave a backdoor etc. these are generally organizations with multiple people involved and it only takes one of those people to have squirreled away a copy of the data or installed a backdoor on his own. I doubt Kairos makes members sign an NDA and may not necessarily even know the true identities of those members, so even if the org itself is "on the up and up" (at least as far as that's possible for ransomware scum) there is no way they can guarantee their commitments are upheld.

  3. Lee D Silver badge

    Had this discussion many times, with managers, cybersecurity consultants, digital forensics people, etc.

    Paying the ransom is indistinguishable from money-laundering / embezzlement. (How do we know you're not just paying yourself that untraceable money? Or a friend?)

    And they've already committed a crime, so why would you ever trust them not to commit another just because they say so.

    This is literally in the realm of "Granny gets done by scammer, then gives scammer MORE money because they promised they'd fix it if she did."

    This shouldn't ever be the official position of ANY govermental organisation or even company.

    1. Anonymous Coward
      Anonymous Coward

      "How do we know you're not just paying yourself that untraceable money?"

      You don't.

      But 99% of the time it becomes obvious when the perp turns up to work in a new Jag and starts going on fancy holidays.

      In the event you suspect someone internally being involved, it might actually be better to pay the ransom, because eventually they will slip and get caught. The kind of person that would do this sort of thing from the inside is usually the sort of person that can't resist spending the money on dumb shit eventually.

      There is one universal constant that you can always rely on in cybersecurity...people are dumb.

      I wouldn't at all be surprised if some law enforcement suggested paying the ransom or at least part of it, because it gives them something to follow to track down the perp. Outside of "following the money" there probably isn't a lot to go on for LEA.

      They may not catch them straight away, but eventually the perp will feel "safe" and the law will catch up.

      https://www.bbc.co.uk/news/articles/cvg4w1g9ezko

      You have to remember, these cybercrims that pull various shit off rely on the fact that the organisations they target care more about their data, optics and bottom line than actually bringing a crim to justice...it's this fact that allows this shit to keep happening.

      Cybersecurity should not be an internalised singular mission of an organisation. It should be something that works more broadly than that. Your cyber guys should be working with other cyber guys out there as a collective army sharing knowledge and intelligence openly...otherwise it's just feudal Game of Thrones style bullshit with an even crappier ending.

      1. DS999 Silver badge

        What if it is a scam on the insurance company?

        People have done that since insurance became a thing - "oh no my money losing factory burned down, oh woe is me, good thing I have insurance!"

        Whether the owner of a company or an employee with enough access to IT systems I could pretty easily "attack" myself and send a ransomware notice to my company. The company goes to its insurance provider "help help if this isn't paid the company will be ruined!" and they pay the $1 million ransom. Unbeknownst to them, it goes to a bitcoin wallet I set up, which I later empty into mixers to turn the proceeds untraceable (maybe not untraceable to the FBI or Interpol, but untraceable to my insurance company) and now I'm $1 million richer - tax free.

        Now I can use that to buy myself some property overseas a couple years later, through a couple shell companies so that as far as anyone knows when I visit that property, I'm renting. I could even pay my shell company for the rental to keep up the illusion, and thus funnel money in to pay for upkeep or save up to eventually upgrade to a larger property. As far as the assets I have in the country nothing has changed so no one would be able to detect this by watching my lifestyle. But I have a $1 million property (hopefully growing in value) overseas as a nice place to retire to someday. And all gains are tax free since without a really deep dive audit my government would never know about those offshore holdings.

        Seems like this would be a far more difficult insurance fraud to prove than arson. And it is available to anyone in the company, not just the owner. An employee can't burn down the place he works for personal gain, because he doesn't get the money. Here he does.

    2. Anonymous Coward
      Anonymous Coward

      It's not about trusting them, it's about giving them something that can be tracked so they can eventually be caught...because they will eventually surface, suddenly flush and will try and buy a Porsche with the proceeds. The blockchain is an open ledger, at the point the crypto moves to an exchange to be "cashed in" it can be followed in the real world...and the person that bought that Porsche will likely have done it in his or her own name...like an absolute muppet.

      Insular thinking is precisely why cybersecurity will always fail...because is priority number 1 is protecting your own data, bottom line and nothing else, the crims will continue to circulate.

      Cybersecurity shouldn't just be about protecting your own stuff, it should also be about knowledge sharing, intelligence gathering and actually catching the crims. You can't do that if all your company cares about is the optics, their bottom line and their own asses.

      1. Lee D Silver badge

        Blockchain mixers exist and basically are money-laundering facilities.

        10 Bitcoin go in, via ten thousand individual transactions.

        10 Bitcoin come out, via tens of thousands individual transactions to a dozen addresses, while being mixed in with COUNTLESS MILLIONS of other such transactions, with no correlation between the in-wallet and the out-wallet.

        Now the person with the out-wallets is free to spend them on what they want, when they want, how they want, and they can't be traced back to the original funds. That pizza I bought officer? Well, clearly that was done with the proceeds of my Bitcoin gambling from the 0.01BTC that I put online five years ago. Can I prove it, you ask? No. And neither can you prove it wasn't.

        At best you can trace it back to... a bitcoiner mixer account. Whatever the last one they used was. Which might be one of dozens or hundreds such mixing transactions.

        Sorry, but it's just not that simple to trace this stuff, even if avoiding detection isn't just as simple as pressing a button.

        1. AVR Silver badge

          Keeping in- and out-wallets entirely separate while controlling both is a problem which has caught would-be money launderers before. The actual mixer likely works as advertised (not certainly), but if an X amount of bitcoin leaves your wallet and the same enters your girlfriends' while your two devices at the same physical location access the mixer then you haven't done enough to not be tracked later, judging by media reports.

          It does help if you're in Russia and don't need to worry about American law enforcement getting hold of those devices.

      2. DS999 Silver badge

        Who says you have to buy something with it?

        Why couldn't you just keep the money in a hardware wallet for a few decades? Or if you are worried bitcoin might go to zero during that time then (after appropriate mixing) use it to buy gold bars or a Picasso you keep stored in a Swiss bank or some offshore property? Sure if you suddenly buy a fancy new house and are driving a Ferrari around town people are going to know something's up, but you read about people doing that because only the dumb criminals who do that sort of thing get caught.

        If you look at it as an early retirement plan that you won't touch for years and keep living your normal life in the meantime even if they suspect you and are watching you they will give up eventually when you don't do anything suspicious that would indicate you had a sudden windfall.

  4. Anonymous Coward
    Anonymous Coward

    Don’t pay Ethel!

    Too late, she paid…

    1. David 132 Silver badge
      Thumb Up

      Re: Don’t pay Ethel!

      Ah, a rare and unexpected Ray Stevens reference. I approve!

  5. Taliesinawen Bronze badge

    Union County, Ohio Pays $1 Million Bitcoin Ransom to Kairos

    Union County, Ohio Government Pays $1 Million Bitcoin Ransom to Kairos Cyber Extortion Group After Data-Only Attack

    “A small Ohio county government, widely believed to be Union County, Ohio, reportedly paid a $1 million ransom in Bitcoin to the cyber extortion group Kairos in June 2026. The attackers gained access to the county’s network via a brute-force credential attack, exfiltrated over 2 terabytes of sensitive data” ..

  6. Brave Coward Bronze badge

    allegedly stolen document?

    I don't get it. That 'allegedly stolen document' is freely accessible here

  7. sindrelspec

    Payment ban is separate from digital security

    "“A payment ban will backfire because it doesn't address the root cause of our national problem: widespread digital insecurity.”"

    What a stupid thing to say. That's like saying we should not help the victims of car crashes because it does not address the cause of car crashes.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon