Last updated 2 weeks ago
A U.S. government entity paid approximately $1 million to the threat actor group Kairos to prevent the leak of stolen files. The incident was detailed in a case study by Rakesh Krishnan for Ransom-ISAC, which analyzed leaked negotiation chat logs and blockchain payment records. No ransomware deployment was observed, and the group may not be a traditional ransomware gang.
The attack vector involved unauthorized access leading to data theft, with no encryption or system locking reported. The threat actor Kairos exfiltrated files and demanded payment to avoid public disclosure. The payment was traced via blockchain, confirming the ransom was paid.
The U.S. government entity paid the ransom to prevent data leakage. The case study provides evidence of the negotiation and payment, but no further details on the specific agency or data types were disclosed. No regulatory or legal actions were mentioned in the article.
Data theft extortion via stolen files; no ransomware deployment
The U.S. government entity's payment to Kairos highlights the failure of preventive controls to detect and block unauthorized data exfiltration. The lack of ransomware deployment suggests the need for robust data loss prevention (DLP) and monitoring of outbound data transfers, as well as incident response plans that address extortion without payment.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor