[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTIdLq1NfKsoQdGFFIdWtGSkwfrmAZWGwv5v67uCy_zs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"4a6080f5-fe75-4347-a2a1-ae05db2cc3fe","county-pays-1m-ransom-after-brute-force-attack-exposes-2tb-of-data","9ea103d4-913a-4694-a26e-0f2e9b82482a","County Pays $1M Ransom After Brute-Force Attack Exposes 2TB of Data","The Kairos extortion group gained access to Union County, Ohio's environment through a brute-force attack, suggesting weak or absent account lockout policies and poor password hygiene on internet-facing systems. The theft of over 2 terabytes of sensitive data before detection points to insufficient monitoring and data access controls. Paying the $1 million ransom — even negotiated down from $3 million — does not guarantee data deletion and emboldens future attacks against public sector targets. This incident underscores that government entities holding citizens' sensitive data have both an ethical and regulatory obligation to enforce strong authentication and maintain tested incident response plans.","**Immediate actions:**\n- Enforce account lockout policies and multi-factor authentication (MFA) on all internet-facing systems and administrative accounts immediately.\n- Audit and rotate all privileged credentials, especially those exposed to external access points.\n- Engage a third-party forensics firm to determine the full scope of data exfiltration and notify affected individuals per breach notification laws.\n\n**Long-term improvements:**\n- Implement a Zero Trust architecture with least-privilege access to limit lateral movement after any initial compromise.\n- Classify and encrypt sensitive data at rest and in transit, ensuring 2TB+ datasets cannot be exfiltrated without triggering alerts.\n- Develop and regularly test a ransomware-specific incident response playbook that includes pre-negotiation legal and law enforcement engagement guidance.\n\n**Detection measures:**\n- Deploy SIEM\u002FUEBA tooling to detect brute-force login attempts and abnormal bulk data access or transfer patterns in real time.\n- Establish baseline network traffic monitoring with automated alerting for large outbound data transfers.\n- Conduct quarterly penetration testing and red team exercises targeting authentication mechanisms on all public-facing systems.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4 – Controlled Use of Administrative Privileges","CIS Control 6 – Access Control Management","CIS Control 13 – Data Protection","CIS Control 17 – Incident Response Management","NIST SP 800-53 AC-7 – Unsuccessful Logon Attempts","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 IR-4 – Incident Handling","NIST SP 800-53 SI-4 – Information System Monitoring","NIST CSF RS.RP-1 – Response Planning","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","ITIL 4 – Major Incident Management Practice","published","2026-07-07T18:20:20.71395+00:00","2026-07-07T18:20:20.616+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fcounty-government-reportedly-paid-1-million-to-cyber-extortion-group\u002F","county-government-reportedly-paid-1-million-to-cyber-extortion-group-82e377","County Government Reportedly Paid $1 Million to Cyber Extortion Group",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]