A U.S. Government Agency Quietly Paid $1 Million to a Group That May Not Even Be Ransomware

A leaked negotiation chat and blockchain trail suggest Kairos runs pure data-theft extortion: no file-locking, just threats to leak.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dimly lit government office corridor at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A U.S. Government entity paid roughly $1 million to an extortion group calling itself Kairos to stop stolen files from being published.
  • The payment was traced on the public blockchain, the shared ledger that records every cryptocurrency transaction.
  • Researcher Rakesh Krishnan, writing for Ransom-ISAC, found no evidence Kairos ever locked victims' files with ransomware.
  • The case was pieced together from a leaked negotiation chat between the victim and the criminals.
  • Kairos appears to run a data-theft-only extortion model, threatening to leak stolen data rather than encrypt systems.

An unnamed U.S. Government entity handed roughly $1 million to a criminal group known as Kairos to keep stolen files off the internet. The payment, and the negotiation behind it, were reconstructed by researcher Rakesh Krishnan in a case study for Ransom-ISAC, an information-sharing group that tracks ransom incidents. The Hacker News first surfaced the story.

What makes this case strange is what Kairos apparently didn't do.

So what actually happened to the victim?

The criminals broke into the agency's systems and stole files but did not, as far as Krishnan can tell, deploy ransomware: the malicious software that scrambles files and demands payment for a decryption key. Kairos simply took copies of sensitive data and threatened to publish them unless the agency paid.

That distinction matters. A traditional ransomware attack leaves an organisation unable to work: computers frozen, patient records inaccessible, payroll stuck. This attack left the lights on. Pressure came entirely from the threat of a leak, and the victim paid anyway.

How was the payment tracked?

Krishnan followed the money on the blockchain, the public ledger where every cryptocurrency transaction is permanently recorded. Anyone with the right tools can trace where coins move, even without knowing who holds a wallet. The trail confirmed roughly $1 million flowing to wallets tied to Kairos. A leaked chat log filled in the rest: the demands, the haggling, the eventual agreement.

Is Kairos actually a ransomware gang?

Probably not, in the strict sense. Krishnan's analysis found no confirmed case of Kairos encrypting a victim's files. The group behaves more like a pure extortion crew: steal data, threaten to leak, collect payment.

This model is spreading. We reported in June on UNC3753 running a data-theft extortion campaign against U.S. Professional services firms without locking a single file. Several established gangs have quietly dropped the file-locking step because it's technically fiddly, draws more attention from law enforcement, and often isn't needed. If the stolen data is embarrassing or regulated enough, the threat of publication does the work on its own.

Why did a government entity pay?

The case study does not name the agency, and U.S. Federal guidance generally discourages ransom payments. Paying is not illegal in most cases, though, and agencies facing exposure of sensitive citizen data, think benefits records, investigation files, personnel information, sometimes decide a leak is worse than a wire transfer. That calculation is exactly what groups like Kairos are betting on.

Should you worry about your own data?

If you've ever handed personal information to a U.S. Government office, this case is a reminder that the risk of it reaching criminal hands is not hypothetical. Freeze your credit with the major bureaus if you haven't already, turn on multi-factor authentication (the second login step that sends a code by text or app) for any account tied to government services, and treat unexpected agency emails with suspicion. Real agencies don't ask for passwords or payment by email.

The Kairos wallets remain visible on-chain. Whether the group reuses them, or law enforcement moves first, is the next chapter worth watching.

© 2026 Threat Vectr