ctipilot.ch

Kairos

actor · actor:kairos-extortion single-source

Kairos — data-theft-only extortion actor; no ransomware encryptor or locker binary has been obtained or confidently linked to it. Leverage rests on the threat to publish exfiltrated data rather than on file encryption; documented retrospectively by Ransom-ISAC (2026-07-03) in a case study of a ~$1M payout by a small US county government.

Coverage timeline
6
first 2026-05-18 → last 2026-07-05
Peak priority
high
3 high · 3 notable
Sources cited
11
10 hosts
Sections touched
4
active-threats, research, weekly-incidents-recap
Co-occurring entities
1
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below
2026-05-186 appearances2026-07-05

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Story timeline

  1. 2026-07-05Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
    weekly-incidents-recapExtortion without encryption matures — a US county paid ~$1M to Kairos, no encryptor recovered
  2. 2026-07-05Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered
    researchRansom-ISAC case study: a US county paid ~$1M to data-theft extortion actor Kairos — no encryptor was ever deployed
  3. 2026-05-24Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
    active-threats
  4. 2026-05-19ARWINI (Lower Saxony statutory-prescription audit body) — investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
    active-threatsARWINI (Lower Saxony statutory-prescription audit body) — investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87
  5. 2026-05-18Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital
    weekly-sector-patterns
  6. 2026-05-18ARWINI (Lower Saxony prescription-audit body) — exfiltration confirmed; Kairos claims 2.87 TB including ~70,000 GDPR Art. 9 records
    weekly-incidents-recap

Where this entity is cited

  • weekly-incidents-recap2
  • active-threats2
  • weekly-sector-patterns1
  • research1

Source distribution

  • heise.de2 (18%)
  • aerzteblatt.de1 (9%)
  • borncity.com1 (9%)
  • ransom-isac.org1 (9%)
  • ransomware.live1 (9%)
  • securityaffairs.com1 (9%)
  • thehackernews.com1 (9%)
  • therecord.media1 (9%)
  • other2 (18%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (11)

Entries about Kairos (6)

2026-07-05 · view entry permalink →

NOTABLENATOB2

Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered

The week's incident cases reinforce a shift that has been building through 2026: extortion is decoupling from encryption. The concrete anchor is Kairos.

Ransom-ISAC published a case study of a US county government that paid roughly $1 million to the data-theft extortion actor Kairos after an intrusion in which no encryptor was recovered — Ransom-ISAC obtained no locker binary and notes the actor's "ransomware group" status remains unverified, so the leverage was the threat to publish exfiltrated county data rather than encryption (Ransom-ISAC, 2026-07-03). The intrusion itself is a 2025 case (demand mid-May, payment mid-June 2025) published as a retrospective this window, not a this-week breach. This is the pure form of a model that also showed up elsewhere in the week: MedusaLocker's leak-site listings (including the unconfirmed Canton of Zürich claim) trade on data-disclosure threat rather than demonstrated encryption, and the ShinyHunters cluster consolidated separately in this week's long-running status entry continues to extort on exfiltration alone, without a locker.

Why it is strategic, not just another incident: for a decade the standard ransomware-resilience answer has been tested, offline, immutable backups — a posture that bounds the availability impact of encryption. Encryption-less data-theft extortion routes around that entirely: if the leverage is disclosure of citizen or employee PII, restoring from backup does not reduce the harm or the notification obligation. The defender consequence for a public-sector SOC is a re-weighting: exfiltration detection (anomalous large outbound transfers, cloud/SFTP staging), data minimisation on sensitive stores, and clear pre-agreed non-payment / notification playbooks matter as much as recovery engineering. The Kairos county case is a single-source 2025 retrospective case study (§ references) — treat the dollar figure as illustrative and the "no encryptor" as evidentiary absence, not proven — but the encryption-less-extortion pattern across this week's cases is the durable signal.

Builds on: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · 2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek

incident05 Jul 23:32Zmulti-sourceOpen finding ↗

2026-07-05 · view entry permalink →

NOTABLE

Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered

Ransom-ISAC has published a post-incident case study reconstructing a data-theft extortion case against a small US county government body, in which the victim paid roughly $1M after a May 2025 intrusion (Ransom-ISAC, 2026-07-03; The Hacker News, 2026-07-04). The distinguishing feature of the actor, self-styled "Kairos", is that it is a pure data-theft-and-leak extortion operation — Ransom-ISAC states "No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos", so its leverage rested entirely on the threat to publish stolen data rather than on file encryption (Ransom-ISAC, 2026-07-03). Kairos itself claimed the intrusion was achieved through a brute-force credential attack — "We accessed your network using a bruteforce attack" — mapping to T1110 Brute Force and T1078 Valid Accounts; the report does not independently confirm the access method beyond the actor's own statement (Ransom-ISAC, 2026-07-03).

Kairos claimed access to more than 2 TB of data — approximately 1.6 million files — and exfiltrated it for leak-site leverage (T1567 Exfiltration Over Web Service); after roughly a month of negotiation the victim paid about $1M on 13 June 2025 (Ransom-ISAC, 2026-07-03; Security Affairs, 2026-07-04). Ransom-ISAC explicitly cautions that "The provided 'proof of deletion' was not technically verifiable and should not be treated as evidence that the stolen data was destroyed", noting there was nothing cryptographically binding the actor's deletion log to an actual deletion event (Ransom-ISAC, 2026-07-03).

We accessed your network using a bruteforce attack.

Kairos (quoted by Ransom-ISAC)

No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos

The provided 'proof of deletion' was not technically verifiable and should not be treated as evidence that the stolen data was destroyed

Ransom-ISAC 2026-07-03
research05 Jul 00:25Zmulti-sourceOpen finding ↗

2026-05-24 · view entry permalink →

HIGH

Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed

Unimed, a Saarland-based billing-service provider that handles private-insurance and self-payer invoicing for an estimated 95% of German university hospitals, was breached in mid-April 2026; attackers exfiltrated patient data and an attempted full encryption of Unimed's infrastructure was reportedly averted (heise online, 2026-05-22). On 2026-05-21 at least six state-funded Universitätsklinikum hospitals — Cologne, Freiburg, Heidelberg, Tübingen, Ulm and Mannheim — disclosed that their patients' data was among the stolen records (The Record, 2026-05-22). University Hospital Freiburg states master data for ~54,000 patients (names, addresses, dates of birth) was taken, with billing records for ~900 patients additionally exposing diagnoses and treatment methods, and bank-account data in a small number of those cases (Uniklinik Freiburg, 2026-05-21); Cologne reports ~30,000 affected (Uniklinik Köln, 2026-05-21). The exposed categories include GDPR Article 9 special-category health data (diagnoses, treatment codes) and financial data (IBANs). Attribution is open: heise states it is "not yet known who is responsible" for the Unimed attack, and The Record likewise reports no actor had publicly claimed responsibility at its publication. The intrusion does rhyme with the earlier ARWINI Lower-Saxony statutory-billing breach (covered 2026-05-19) — which the Hannover Police Directorate attributed to the Kairos ransomware group per heise — but that resemblance is an analyst pattern-overlap, not a sourced attribution of the Unimed breach.

incident24 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (3)