The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals

A US county reportedly paid $1 million to Kairos, an extortion gang that claimed to have stolen more than 2 TB of data, but the county never received independently verifiable proof that the stolen files had been deleted - just the criminals' promise. This means the county’s stolen files may turn up for sale on a dark web forum, and the same (or another) crime crew could again demand an extortion payment to not leak the data. It’s also a reminder that, despite the feds urging victims not to pay cybercriminals, sometimes coughing up the ransom demand seems to be the lesser of evils. The alleged incident played out in May and June 2025, according to a case study by threat-intel researcher Rakesh Krishnan on Ransom-ISAC, a global knowledge-sharing platform for defenders and incident responders. Krishnan based his report on a leaked transcript of the negotiations between the county and Kairos, along with attacker-provided artifacts and screenshots, and payment-tracing evidence on the blockchain. It doesn’t name the ransomware negotiator, citing privacy concerns, nor does it identify the victim, describing it as a US government entity. Communications between the attackers and the public agency, however, suggest it’s a US county, including this one following the attackers’ initial $3 million demand: “We have reviewed the situation with our leadership and financial teams. As a small county with very limited resources, we simply do not have the ability to meet the amount you have proposed. That said, we understand the seriousness of the matter and want to work toward a resolution. The most we have been able to identify at this time is $100,000. We respectfully ask that you consider this offer.” Additionally, one of the allegedly stolen documents, "Media Release - Motorcycle Crash Claims the Life of Dublin Resident 9-10-2020.pdf," indicates that there’s a city of Dublin inside the county’s boundaries. It’s worth noting that the city of Dublin, Ohio, spans four counties in that state: Union, Franklin, Delaware, and Madison. And last fall, Union County, Ohio disclosed a May 2025 “ransomware attack that involved unauthorized access to and acquisition of protected personal information held by the County.” According to the cyber-incident notice, the intruders accessed Union County networks from May 6, 2025 through May 18, 2025 and stole data including people’s names, Social Security numbers, driver’s license/state identification card numbers, financial account information, dates of birth, fingerprint information, medical information, payment card information, and passport numbers. The disclosure doesn’t say anything about paying a $1 million ransom, nor does it name the attacker. The Register reached out to county officials and law enforcement and asked if Union County is the government entity described in the Ransom-ISAC report. We will update this story if we receive any response. The FBI declined to comment. We should also note that there’s no indication this was a ransomware attack, as the attackers didn’t claim to encrypt any data or provide a decryptor in exchange for payment. Plus, as Krishnan says, security researchers have not obtained, or linked to Kairos, any ransomware sample, encryptor, or locker binary. What we do know, based on the transcript and Kairos’ data-leak site, is that the miscreants claimed to steal more than 2TB of data, totaling about 1.6 million files. 'You are wasting our time with such offers' After listing the victim county on their name-and-shame blog, Kairos demanded $3 million. “We will give you the full list of files we have and give you some time to study it,” the crims told the victim. “You can choose up to 10 files from this list and we will send them to you. In order to prevent the publication of data you need to pay 3000000$.” According to the transcript, county officials reviewed the files during the last week of May 2025, and made the first counteroffer of $100,000 on June 4, 2025. Kairos responded: “You are wasting our time with such offers.We cant accept it.Your files will be a great advertisement on our site and we understand what terrible consequences will await you. You cant hide the data leak.You have two more days to make us a favorable offer.” Two days later, the county increased its offer to $255,000. Kairos reduced its demand to $2 million, and on June 9, 2025, the county proposed paying $430,000. “As a small county and limited resources, we are doing our best to navigate this within what is financially feasible for us,” the leaked negotiations say. “That said, we are committed to finding a resolution and have taken steps internally to increase our offer to $430,000. This reflects a sincere attempt to make progress despite our constraints. We ask that you consider this proposal as part of a continued effort to resolve the matter in a constructive and timely manner.” That same day, both parties settled on $1 million, Kairos provided a Bitcoin payment wallet and the county requested a few deliverables in exchange for the payment: “Please confirm for $1,000,000 you will provide us with: proof of deletion, a complete list of all files taken, and tell us how you got in.” Kairos claimed to have gained initial access by bruteforcing their way into the network, shared an RAR file that they claimed provided “proof of deletion of all downloaded files,” and a promise: “We also guarantee that we will not share the downloaded data with third parties, and we also guarantee that we will not attack you again.” However, as Krishnan notes, “the transcript does not show a technical mechanism by which deletion could be independently verified, which remains a fundamental limitation in ransom-payment scenarios.” To pay, or not to pay? It’s also one of the reasons why both the FBI and US Cybersecurity and Infrastructure Agency urge victims not to pay criminals. “Paying a ransom doesn’t guarantee you or your organization will get any data back,” according to the FBI. “It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity.” While there is no outright ransom-payment ban at the US federal government level, two states - North Carolina and Florida - explicitly prohibit public agencies from paying extortion demands, and others have proposed similar legislation. The Register has discussed the topic of a ransomware-payment ban with many experts over the years, and while they mostly agree that the only way to eliminate attacks is to cut off the financial incentive for the criminals, they also typically say a total payment ban won’t work. “Complex problems are rarely solved with binary solutions, and ransomware is no different,” Sezaneh Seymour, VP and head of regulatory risk and policy at Coalition, told us in an earlier interview. “A payment ban will backfire because it doesn't address the root cause of our national problem: widespread digital insecurity.” ®

AI slop writing has taken over the internet, particularly LinkedIn and X

No surprise here. A study from AI detection platform Pangram suggests that social media posts are teeming with AI-generated slop, particularly if the posts are long and especially if they live on LinkedIn or X. If you’re sick of reading non-human prose, we’d recommend getting off the platforms altogether. Along with offering your typical AI-content detection services, Pangram released a Chrome extension at the end of April that, with a $20/month subscription, will automatically scan a user’s LinkedIn, Medium, Substack, X, and Reddit feeds to check for AI-generated or assisted content. With more than one million posts analyzed from users who opted in to share data through the extension since its launch, Pangram has concluded that, while AI slop is flooding social media, it’s hitting longform content particularly hard. With longform content defined in its study as any post over 250 words, Pangram found that a full 25 percent of such posts across all the platforms it studies were fully AI-generated. Fully, mind you, meaning that doesn’t include posts in which users got the assistance of an LLM to gussy up their bland prose. That average across platforms was hardly evenly distributed, though. Leading the way was LinkedIn, where 41 percent of longform content was fingered by Pangram as being AI-generated. That’s likely unsurprising to anyone who's ever bothered to read a lengthy professional diatribe from the Microsoft-owned slop shop, or for El Reg readers - a prior story we reported on in late 2024 from AI detection outfit Originality.ai found that 54 percent of LinkedIn longforms were AI-generated. Originality’s definition of Longform was a bit looser, however, with anything over 100 words counting in its analysis. Per Pangram, shortform content on LinkedIn isn’t much more likely to be human authored - they found 30 percent of posts between 50 and 250 words were fully written by AI. For LinkedIn thought slop leaders, it’s generally all or nothing when it comes to using AI to write posts, with a mere 4.3 percent of longform content written with AI assistance. On the other hand, only 55.2 percent of longform posts on the platform, Pangram concluded, are actually written by humans. While LinkedIn may take the cake in terms of the volume of full-slop longform posts, Elon’s X has it beat when adding partially-written AI garbage into the mix, but not by much, honestly. A quarter of posts on X are fully AI authored, and an additional 23.2 percent are believed to be written with AI help. That leaves 52.7 percent of Twitter posts attributed to humans. In effect, you’re roughly batting .500 on either site. Pangram found that Medium isn’t that much better, with roughly one in three posts likely to have been written by, or with the aid of, an AI. Substack was far and away the least likely place to find AI slop in disguise, but even then, nearly a quarter (21.9 percent) of posts analyzed by the Chrome extension were written by or with AI. Reddit is a slightly more complicated situation, with comments on posts making up a large portion of Reddit content. According to Pangram, 11.6 percent of Reddit posts are AI authored or assisted; 98.1 percent of comments were found to be human authored, and the sheer quantity of comments vs. top-level posts meant that Reddit appears to be the place to go if you want to avoid an intrusion of AI thinking. All said, Pangram concluded from its data that AI writing is flooding social media, just like it’s flooding websites and basically everywhere else online. “An internet that is completely flooded with undisclosed AI content is bleak, but we don't believe it's inevitable,” Pangram CEO Max Spero said of his company’s findings in the report. Pangram believes letting internet users know what’s been AI-generated so they can ignore it is a solution to the problem, but you’ll have to pay $20/month if you want the Chrome extension to provide that service. It’s still usable without paying, but content has to be manually input, and the daily limit is just 4,000 words. In other words, unless you want to pony up and see who’s bullshitting you on social media, you’ll have to just assume everyone is. Like we suggested up top, maybe it’s time to disconnect from those feeds entirely. ®

xiffy

Public posts from @xiffy@mastodon.nl

en pleurt op met je vuurwerk, je hebt verloren!
Poes weer schijtbenauwd.

Claxoneren!

Dominant Frankrijk laat Marokko kansloos: 2-0

Frankrijk is na een 2-0 overwinning op Marokko de eerste halvefinalist van dit WK voetbal. De goals in het Gillette Stadium van Boston werden gemaakt door Kylian Mbappé en…

Inspectie: wanbeheer bij Cornelius Haga Lyceum, ministerie moet beslissen over vervolgstappen

Volgens de Onderwijsinspectie schiet het islamitische Cornelius Haga Lyceum in Amsterdam ernstig tekort in de kwaliteit van het onderwijs. Inmiddels is de situatie op de school volgens de staatssecretaris zo slecht, dat het ministerie kan besluiten de financiering stop te zetten.

begging for food

BertvB posted a photo:

begging for food

An intimate wildlife portrait capturing a heartwarming interaction between an adult female Great Spotted Woodpecker (Dendrocopos major) and her fledgling.

Spiral Web

Greg Adams Photography posted a photo:

Spiral Web

It Doesn't Matter Who Loves Who

Thomas Hawk posted a photo:

It Doesn't Matter Who Loves Who

Carnaval San Francisco 2015

Thomas Hawk posted a photo:

Carnaval San Francisco 2015

Found Photo

Thomas Hawk posted a photo:

Found Photo

handwritten on negative envelope, "Jr. High Camp, Aug 17-23, 1958". handwritten on back of photograph, "Camp Ceder Crest, August 23, 1958, L to R. Kathleen Garrislimo, Linda Kelly, Sandra Orchard, Eileen MacArthur, Louise Quade (counselor) Sharson Telecke, Pat Sparks, Barbara Rogers, Sandra Horn"

Tell Me the Time of Day

Thomas Hawk posted a photo:

Tell Me the Time of Day

The Thunder Makes Her Conemplate

Thomas Hawk posted a photo:

The Thunder Makes Her Conemplate

Slashdot

News for nerds, stuff that matters

Google Hands Open Health Stack To the Linux Foundation

BrianFagioli writes: The Linux Foundation intends to launch the Open Health Stack Software Foundation, a new vendor-neutral home for the Google Open Health Stack project. Google is contributing the project code and assets while Google.org is providing a $3 million grant. The initiative is also backed by Microsoft, Anthropic, and the World Health Organization, with the goal of building open source, AI-ready digital health infrastructure. Will moving the project under Linux Foundation governance accelerate adoption, or is this simply another foundation that most developers will never interact with? The new project will focus on core HL7 FHIR technologies for healthcare interoperability, the Open Health Stack Player deployment toolkit, and AI Commons -- a model-agnostic healthcare AI initiative being co-developed with the World Health Organization.

A notable part of the announcement is its planned Implementer Program, which aims to give startups, small businesses, and local developers in low- and middle-income countries a formal role in governance. In other words, the effort is not just about building healthcare software standards, but about making sure the people implementing them in underserved markets help shape the project too.

Read more of this story at Slashdot.

San Francisco Moves To Build Private Luxury Airport Terminal

An anonymous reader quotes a report from The Guardian: The [San Francisco international airport] is hoping to build a brand-new terminal exclusively for passengers who pay a premium, gaining access to a luxurious airport experience complete with private security lines and valet service from terminal to tarmac. It will service commercial flights, not business or corporate jets, and the terminal will have its own Transportation Security Administration (TSA) lines as well as Customs and Border Protection (CBP) lines for international travel.

SFO is seeking bidders to take on the development, construction and operation of the private terminal, which is planned for a 75,000-sq-ft site located across the runway from all current public terminals. The airport will accept proposals between late September and early October, and is looking to award a contract by early December with hopes of opening the terminal in late 2028. [...]

If SFO is successful, it would become the next major American airport to open a luxury terminal. Los Angeles, Dallas Fort Worth, Miami and Hartsfield-Jackson Atlanta international airports all offer a private terminal through PS (formerly known as the Private Suite), a company owned by security firm Gavin de Becker and Associates. Multiple representatives from PS and Gavin de Becker and Associates attended a June conference hosted by SFO about the private terminal, and PS has said it hopes to open a private terminal at every major US airport by 2030. The report notes that access to existing PS private terminals "can cost passengers $1,295 for a one-time experience, or up to $4,850 for a yearly membership."

Read more of this story at Slashdot.

Behance Featured Projects

The latest projects featured on the Behance

The Geometry of Silence


kottke.org

Jason Kottke's weblog, home of fine hypertext products

How — and Why — to Cull Your Book Collection . “6....

How — and Why — to Cull Your Book Collection. “6. I have to give up on some of my little projects.” (I am mid-cull right now, making some tough calls. But also: many books I haven’t so much as touched in 10 years.)

Colossal

The best of art, craft, and visual culture since 2010.

Ana Elisa Egreja Takes a Magical Realist Approach to Migration in Her Rich Still Lifes

Ana Elisa Egreja Takes a Magical Realist Approach to Migration in Her Rich Still Lifes

“Improbable but not impossible” is how Brazilian artist Ana Elisa Egreja describes the unexpected companions in her vibrant still lifes. Combining the architectural motifs, animals, and fare common in her native São Paulo with elements from abroad, Egreja positions domestic spaces as sites of change, where migration and cross-cultural pollination come to bear.

In a new suite of 15 oil paintings, the artist draws on the long tradition of Dutch Golden Age still lifes alongside the contrived qualities of collage. Tablescapes filled with fresh flowers and shiny produce also contain cellophane-wrapped snacks and canned goods. Egreja acknowledges flight as a rich symbol of freedom and migration, and birds swirl overhead and perch atop the uncanny objects. There’s also a pair of window pieces, blanketed in 24-karat gold leaf and decorative wrought grilles, which serve as an interstitial spot for the winged creatures to pause as they move between interior and exterior.

a painting of five black cats lounging on a red patterened couch in front of a wooden blind covering a sunset
“Interior with Five Cats at Sunset [Interior com Cinco Gatos ao Pôr do Sol]” (2026), oil on canvas with beaded curtain, 63 x 74 3/4 inches

Egreja’s focus on bridging these divides emerges in her renditions of sunsets, too, with their bold gradients rippling from crimson to amber across living spaces. This glowing feature backdrops both “Interior with a Jaguar and Sun Conure,” in which a forlorn feline lounges on an Art Deco sofa, and “Interior with Five Cats at Sunset.” The latter also contains a sculptural element as the vibrant light streams through a beaded curtain mounted to the painting’s edge.

Taking a magical realist approach to migration, Egreja questions the hard boundaries we perceive between private and public space, wildness and domesticity, as well as international borders. She also renders these lines illegible to our non-human counterparts, nodding to an ongoing organic exchange between seemingly disparate entities.

The works shown here are part of the artist’s first solo exhibition in the U.S., titled The Flight of Color, which runs from July 16 to September 5 at Jessica Silverman in San Francisco. Explore more of the artist’s practice on Instagram.

a jaguar lounges sadly on an ornate corner bench with birds flying around
“Interior with a Jaguar and Sun Conure [Interior com Onça-Pintada e Jandaias-Sol]” (2026), oil on canvas, 63 x 74 3/4 inches
a painting of a metal wrought window with red birds
“Window with Scarlet Tanagers and a Golden Sky [Janela com Tiês-Sangue e Céu de Ouro]” (2026), oil and 24 karat gold leaf on canvas, 31 1/2 x 31 1/2 inches
a still life painting filled with watermelons and fruits and parrots perched all over. there's a bold floral background
“Red Table with Chinoiserie, Macaws, and Parrots [Mesa Vermelha com Chinoiserie, Araras, e Papagaios]” (2026), oil and 24 karat gold leaf on canvas, 47 1/4 x 86 5/8 inches
a primarily orange still life with birds and elaborate fabric on the table and background
“Still Life with Embroidered Fabric [Natureza Morta com Tecido Laranja]” (2026), oil and fabric on canvas, 11 3/4 x 15 3/4 inches
a painting of a metal wrought window with parrots
“Window with Parrots and a Golden Sky [Janela com Papagaios e Céu de Ouro]” (2026), oil and 24-karat gold leaf on canvas, 31 1/2 x 47 1/4 inches
a still life with purple and pink produce on a table with a purple bird and a gold background
“Magenta Still Life (Sunset) [Natureza Morta Magenta]” (2026), oil and 24-karat gold leaf on canvas, 14 1/8 x 23 5/8 inches

Do stories and artists like this matter to you? Become a Colossal Member today and support independent arts publishing for as little as $7 per month. The article Ana Elisa Egreja Takes a Magical Realist Approach to Migration in Her Rich Still Lifes appeared first on Colossal.

MetaFilter

The past 24 hours of MetaFilter

"Is it working?"

Every John Oliver Scene on General Hospital Meet Zee (or Zed? or Zeke on the captions?). He's got black hair, he shot a guy, and he got slapped.

John Oliver Bags Two Roles After 'Publicly' Urging to 'Appear on a Soap' His "Days Of Our Lives" stint will be in August.

Loop-de-loop

The Loop: A picture puzzle game from the Britannica Arrange the pictures so that each one is connected to the previous and the next (semi) logically.