2026-09-17NOTABLEVille de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
Kairos
actor · actor:kairos-extortion single-source
Kairos, data-theft-only extortion actor; no ransomware encryptor or locker binary has been obtained or confidently linked to it. Leverage rests on the threat to publish exfiltrated data rather than on file encryption; documented retrospectively by Ransom-ISAC (2026-07-03) in a case study of a ~$1M payout by a small US county government.
Coverage
5
4 about it · 1 mention · first 2026-05-19 → last 2026-09-17
Latest activity
2026-09-17
Ville de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
Peak priority
high
1 high · 3 notable
Targets
public-sector
sectors: public-sector, healthcare · regions: europe, us, dach
Sources cited
15
13 hosts
2026-05-195 appearances2026-09-17
Action items (3)
Do-now tasks recorded on the entries about Kairos, newest first. Check the date before acting on an older one.
- Hunt for repeated authentication failures against shared / service accounts followed by a single success (T1110.001 / T1110.003) on externally reachable RDP, VPN, webmail and AD FS endpoints; enforce MFA on any exposed account that still lacks it.2026-07-05Ransom-ISAC case study: a US county paid ~$1M to…
- Tune extortion detection to large abnormal outbound transfers and unusual access to sensitive file shares, encryption-centric ransomware telemetry (mass file rename, entropy spikes) will not fire on data-theft-only extortion.2026-07-05Ransom-ISAC case study: a US county paid ~$1M to…
- Record in incident-response and legal negotiation playbooks that a threat actor's 'proof of deletion' is not technically verifiable; paid extortion must never be treated as guaranteed data destruction.2026-07-05Ransom-ISAC case study: a US county paid ~$1M to…
Defender insights
What each entry about Kairos tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
related to
- Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)Kairos claimed the intrusion on its own leak site and the municipality separately confirmed a security incident, but no source attributes the incident to the actor, only the actor's own claim connects them, so the edge is the generic fallback rather than attributed-to.
- Ville de Libercourt ransomware/data-theft incident (2026-08)Kairos claimed the intrusion on its own leak site and the municipality separately confirmed a ransomware attack with data exfiltration, but no source attributes the incident to the actor, only the actor's own claim connects them, so the edge is the generic fallback rather than attributed-to.
Story timeline
Every entry that names Kairos, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-17A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
- 2026-08-22Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
- 2026-07-05Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered
- 2026-05-24Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
- 2026-05-19ARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
Hunting pivots
ATT&CK techniques (5 across 7 tactics)
5 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts
- PersistenceValid Accounts
- Privilege EscalationValid Accounts
- StealthValid Accounts
- Credential AccessBrute Force
- ExfiltrationExfiltration Over Web Service
- ImpactData Encrypted for Impact · Financial Theft
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Credential Access TA0006
T1110Brute Force×1
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-09-17/kairos-libercourt-commune-ransomware-confirmed · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality · ATT&CK page ↗
Entries about Kairos (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)×2
- ARWINI data exfiltration×1
- Ville de Libercourt ransomware/data-theft incident (2026-08)×1
Where this entity is cited
Source distribution
- escudodigital.com2 (13%)
- heise.de2 (13%)
- aerzteblatt.de1 (7%)
- ayto-velilla.es1 (7%)
- borncity.com1 (7%)
- frenchbreaches.com1 (7%)
- ransom-isac.org1 (7%)
- ransomware.live1 (7%)
- other5 (33%)
All cited sources (15)
- aerzteblatt.deDeutsches Ärzteblatthttps://www.aerzteblatt.de/news/hackerangriff-auf-rezeptprufer-c259a70c-595b-4770-9d84-87f6c8338c0c
- ayto-velilla.esAyuntamiento de Velilla de San Antoniohttps://ayto-velilla.es/posible-exposicion-de-informacion-en-los-sistemas-del-ayuntamiento-de-velilla-de-san-antonio/
- borncity.comBorns IT Bloghttps://borncity.com/blog/2026/05/16/cyberangriff-auf-die-arwini-rezeptpruefung-in-niedersachsen-mit-datenabfluss/
- escudodigital.comEscudoDigitalhttps://www.escudodigital.com/ciberseguridad/ayuntamiento-valdemoro-ciberataque-ransomware.html
- escudodigital.comEscudoDigitalhttps://www.escudodigital.com/ciberseguridad/kairos-asegura-haber-robado-776-gb-de-datos-del-ayuntamiento-de-velilla-de-san-antonio.html
- frenchbreaches.comFrenchBreacheshttps://frenchbreaches.com/alertes/ville-de-libercourt-mu3s726lzo8j6uv1ta
- heise.deheise online, 2026-05-22https://www.heise.de/en/news/Patient-data-affected-Cyberattack-on-billing-service-provider-for-clinics-11305015.html
- heise.deHeise Securityhttps://www.heise.de/news/Niedersachsen-Datenabfluss-bei-Wirtschaftsprueferverein-im-Gesundheitswesen-11297772.html
- ransom-isac.orgRansom-ISAChttps://ransom-isac.org/blog/kairos-ransomware-data-extortion-case-study/
- ransomware.liveRansomware.livehttps://www.ransomware.live/id/VmlsbGUgZGUgTGliZXJjb3VydEBrYWlyb3M=
- securityaffairs.comSecurity Affairshttps://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html
- therecord.mediaThe Record, 2026-05-22https://therecord.media/hackers-steal-patient-billing-data-german-hospitals
- uk-koeln.deUniklinik Köln, 2026-05-21https://www.uk-koeln.de/uniklinik-koeln/aktuelles/detailansicht/cyberkriminelle-entwenden-patientendaten-bei-externem-abrechnungs-dienstleister/
- uniklinik-freiburg.deUniklinik Freiburg, 2026-05-21https://www.uniklinik-freiburg.de/presse/pressemitteilungen/detailansicht/6807-cyberangriff-auf-externen-dienstleister-betrifft-auch-daten-von-patientinnen-des-universitaetsklinikums-freiburg.html