Kairos Ransomware: Data-Extortion Case Study Involving a U.S. Government Entity
ID: 7cd6ebac-c3de-5814-85ae-454f6c61a56a
STIX ID: report--7cd6ebac-c3de-5814-85ae-454f6c61a56a
Feed Name: Ransomware ISAC Blog
This report analyzes a May–June 2025 data-extortion incident in which the Kairos actor claimed ~2 TB (1.6M files) of stolen data from a U.S. government body, negotiated from an initial $3M demand to a $1M ransom payment, and provided negotiation transcripts and claimed deletion artefacts; blockchain tracing shows rapid post-payment splitting and touchpoints with exchanges (ByBit, OKX, BELQI). The assessment emphasizes Kairos appears to operate as a data-extortion brand (no confirmed encryptor or locker was obtained), outlines negotiation tradecraft, lists high-confidence wallet addresses and investigative leads, and presents lessons for public-sector response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
