Back to news

U.S. Agency Pays $1M Extortion; FBI Seizes NetNut Proxy Network

Two cases this week expose how data-theft extortion and compromised residential proxies are reshaping the threat landscape for public and private sector organizations alike.

U.S. Agency Pays $1M Extortion; FBI Seizes NetNut Proxy Network

What happened

A U.S. government entity paid roughly $1 million to a group calling itself Kairos to prevent stolen files from being publicly released, according to a Ransom-ISAC case study built on leaked negotiation transcripts and blockchain transaction records. Notably, Kairos appears to operate purely as a data-theft extortion outfit — researchers found no evidence it has ever deployed file-encrypting ransomware, challenging the assumption that extortion demands always follow a network lockdown. Separately, the FBI announced the seizure of hundreds of domains tied to NetNut, a residential proxy platform operated by Nasdaq-listed Israeli firm Alarum Technologies. The action followed reporting that connected NetNut to the Popa botnet, a network of compromised devices whose bandwidth was being routed through the commercial proxy service without device owners' knowledge.

Why it matters for your business

The Kairos case signals that ransomware defenses centered on backup and recovery are insufficient on their own — adversaries can now generate seven-figure payouts simply by exfiltrating sensitive data and threatening disclosure, skipping encryption entirely. Organizations holding regulated or politically sensitive data face extortion risk even when their systems stay fully operational. The NetNut seizure is a reminder that legitimate-looking commercial proxy services can serve as infrastructure for malicious actors, making traffic from residential IP ranges harder to flag with conventional security tools. Security teams should audit which third-party network services have access to their environments and verify that proxy or VPN vendors do not aggregate bandwidth from enrolled devices in ways that could obscure attacker traffic.

What to watch next

Regulatory and law-enforcement scrutiny of Alarum Technologies is likely to intensify following the NetNut seizure, and the company's Nasdaq listing means financial markets will be watching for further disclosures. On the extortion front, the Kairos case may encourage other threat actors to adopt data-theft-only models, which carry lower operational complexity than deploying ransomware. Both developments suggest a broader industry reckoning with how cybercriminal business models are diversifying beyond traditional malware-centric attacks.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp