U.S. agency paid $1M to delete stolen data — but there was no encryption

I’d like to highlight a notable cybersecurity case.
A U.S. government entity reportedly paid about $1 million to the Kairos group to prevent stolen files from being published.
The key point: there were no signs of encryption. According to the investigation, this was a pure data-extortion scheme — the attackers stole data and pressured the victim with the threat of disclosure.
Negotiations lasted about a month, from $3 million down to the final $1 million. The payment was made in cryptocurrency, but “proof of deletion” does not guarantee anything.
Why it matters: attackers are increasingly relying not on encryption, but on theft and extortion. That makes MFA, segmentation, and data-loss controls critical.
How do you assess the risk of such attacks for public-sector organizations and businesses?

