logo

Kairos Ransomware: Data-Extortion Case Study Involving a U.S. Government Entity

ID: 7cd6ebac-c3de-5814-85ae-454f6c61a56a

STIX ID: report--7cd6ebac-c3de-5814-85ae-454f6c61a56a

Feed Name: Ransomware ISAC Blog

Threat Score
70/100

Date Published: 2026-07-03

Date Updated: 2026-07-29

Author: [email protected] (Rakesh Krishnan)

...
...

This report analyzes a May–June 2025 data-extortion incident in which the Kairos actor claimed ~2 TB (1.6M files) of stolen data from a U.S. government body, negotiated from an initial $3M demand to a $1M ransom payment, and provided negotiation transcripts and claimed deletion artefacts; blockchain tracing shows rapid post-payment splitting and touchpoints with exchanges (ByBit, OKX, BELQI). The assessment emphasizes Kairos appears to operate as a data-extortion brand (no confirmed encryptor or locker was obtained), outlines negotiation tradecraft, lists high-confidence wallet addresses and investigative leads, and presents lessons for public-sector response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.