CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Kairos

actor · actor:kairos-extortion single-source

Kairos, data-theft-only extortion actor; no ransomware encryptor or locker binary has been obtained or confidently linked to it. Leverage rests on the threat to publish exfiltrated data rather than on file encryption; documented retrospectively by Ransom-ISAC (2026-07-03) in a case study of a ~$1M payout by a small US county government.

Coverage
5
4 about it · 1 mention · first 2026-05-19 → last 2026-09-17
Latest activity
2026-09-17
Ville de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
Peak priority
high
1 high · 3 notable
Targets
public-sector
sectors: public-sector, healthcare · regions: europe, us, dach
Sources cited
15
13 hosts
2026-05-195 appearances2026-09-17

Action items (3)

Do-now tasks recorded on the entries about Kairos, newest first. Check the date before acting on an older one.

Defender insights

What each entry about Kairos tells a defender to do, newest first.

2026-09-17NOTABLEVille de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier

2026-08-22NOTABLEAn encryption-free extortion brand is working through Spanish municipal administrations, where the first visible symptom is the claim itself

Triage

2026-07-05NOTABLERansom-ISAC case study: a US county paid ~$1M to data-theft extortion actor Kairos; no encryptor was ever deployed

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

Every entry that names Kairos, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-09-17A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
    active-threatsVille de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
  2. 2026-08-22Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
    active-threatsAn encryption-free extortion brand is working through Spanish municipal administrations, where the first visible symptom is the claim itself
  3. 2026-07-05Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered
    researchRansom-ISAC case study: a US county paid ~$1M to data-theft extortion actor Kairos; no encryptor was ever deployed
  4. 2026-05-24Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
    mentionactive-threats
  5. 2026-05-19ARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
    active-threatsARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87
ATT&CK techniques (5 across 7 tactics)

5 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts
  • PersistenceValid Accounts
  • Privilege EscalationValid Accounts
  • StealthValid Accounts
  • Credential AccessBrute Force
  • ExfiltrationExfiltration Over Web Service
  • ImpactData Encrypted for Impact · Financial Theft

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-17/kairos-libercourt-commune-ransomware-confirmed · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality · ATT&CK page ↗

Entries about Kairos (4)

2026-09-17 · view entry permalink →

NOTABLENATOB2

A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site

The Ville de Libercourt, a commune in France's Pas-de-Calais department, announced on 2026-09-15 that it suffered a ransomware attack in late August 2026 and confirmed that personal data was exfiltrated (FrenchBreaches, 2026-09-16). The commune states it detected the threat quickly and had its external IT provider run technical checks, and has since deployed unspecified corrective measures to strengthen server-access security; it says municipal services were not operationally disrupted. It does not confirm the intrusion method, the responsible ransomware group, the categories or volume of exfiltrated data, or whether a ransom was demanded, all stated as still under investigation. The commune has notified France's CNIL and ANSSI, filed a criminal complaint, and is warning residents to watch for phishing attempts using any exfiltrated data (FrenchBreaches, 2026-09-16).

An extortion actor tracked as Kairos listed the commune on its own leak site on 2026-09-02, thirteen days before the commune's confirmation (Ransomware.live, 2026-09-02); the listing states no data volume or access vector, and no party (not the commune, not any other source) attributes the confirmed intrusion to Kairos beyond that leak-site claim and its timing. That gap matters here specifically: Kairos's own tracked history is data-theft extortion with no ransomware encryptor ever linked to it, while the commune's statement names a genuine ransomware attack; a tension the sources do not resolve, and one more reason the Kairos link stays a claim, not an attribution. Kairos separately claimed the Madrid-region municipality of Velilla de San Antonio in August 2026; that municipality's own statement confirmed a security incident but was explicit that it could not yet confirm effective data access or extraction had occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21), a narrower confirmation than Libercourt's, which names exfiltration outright. Taken together, this is now a second small European municipality where a Kairos leak-site claim coincides with a victim's own confirmation of at least a security incident, a pattern consistent with (though not proven to be) this actor opportunistically targeting small local-government administrations that typically run with limited in-house IT security staffing and externally contracted IT support, a profile shared by Swiss cantonal and communal administrations.

It is confirmed that personal data was exfiltrated. (translated from French)

Ville de Libercourt (relayed by FrenchBreaches)

Ransomware.live discovered on 2026-09-02 that Ville de Libercourt has been claimed by Kairos ransomware group

Ransomware.live 2026-09-02

Builds on: An encryption-free extortion brand is working through Spanish municipal administrations, where…

incident17 Sep 04:37Zsingle-sourceOpen finding →

2026-08-22 · view entry permalink →

NOTABLENATOA2

Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken

The Ayuntamiento de Velilla de San Antonio, a municipality in the Community of Madrid, states it has detected a security incident that could have allowed the exposure of certain information held in its computer systems, and is explicit about the limits of what it knows: the investigation remains open and, for now, it cannot be confirmed that effective access to or extraction of data has occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Work is under way to determine the scope and nature of the potentially affected information, municipal services have not been affected and continue to operate normally, the matter has been notified to the National Cryptologic Centre and other competent authorities, and the Community of Madrid's cybersecurity agency has offered technical and coordination support under the regional incident-response model (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Against that carefully bounded statement sits the actor's claim: the extortion group Kairos says it accessed the municipal infrastructure and took 77.6 GB, and per the group's own published list the files would include administrative and personnel records, officially signed electronic documents, municipal motions, personal data and national identity documents (EscudoDigital, 2026-08-21). Nothing in that list is confirmed by anyone but the group claiming it.

Kairos is already in this store as a data-theft-only extortion brand, with no encryptor ever confidently linked to it, and the outlet's description of the model matches: the attacker enters the organisation, locates information of interest, copies it, and then threatens to publish it if the victim does not pay (EscudoDigital, 2026-08-21). The same outlet reported a Kairos claim against another Madrid-region municipality, Valdemoro, in May 2026, of 1.8 TB said to include police reports, citizens' identity documents and administrative files, following an incident that town hall acknowledged on its own website as having been detected on 5 May and having affected its servers (EscudoDigital, 2026-05-12). That earlier report is internally inconsistent in a way worth flagging rather than averaging: its headline frames the Valdemoro case as ransomware, while the background it carries on the same page describes Kairos as a group focused on data theft without encryption. Two Madrid-region town halls claimed by the same brand inside four months is a pattern worth naming, and the outlet is careful about how far it can be pushed: it says the coincidence of attacker and geography makes the Velilla case particularly relevant but does not on its own establish any relationship between the two incidents (EscudoDigital, 2026-08-21). No access vector has been disclosed for either case.

El Ayuntamiento de Velilla de San Antonio ha detectado una incidencia de seguridad que podría haber permitido la exposición de determinada información alojada en sus sistemas informáticos.

La investigación continúa abierta y, por el momento, no se puede confirmar que se haya producido un acceso o extracción efectiva de datos.

La incidencia no ha afectado a la prestación de los servicios municipales, que continúan funcionando con normalidad.

La Agencia de Ciberseguridad de la Comunidad de Madrid ha ofrecido su apoyo técnico y de coordinación al Ayuntamiento en el marco de sus competencias, de acuerdo con el modelo regional de respuesta ante incidentes.

Ayuntamiento de Velilla de San Antonio 2026-08-21

Según la información difundida por el grupo, entre los archivos supuestamente obtenidos figurarían registros administrativos y de personal, documentos oficiales firmados electrónicamente, mociones municipales, datos personales y documentos nacionales de identidad (DNI).

La coincidencia del grupo atacante y de la localización geográfica convierte el caso de Velilla en una reivindicación especialmente relevante, aunque no permite establecer por sí sola ninguna relación entre ambos incidentes.

EscudoDigital 2026-08-21
incident22 Aug 05:09Zmulti-sourceOpen finding →

2026-07-05 · view entry permalink →

NOTABLE

Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered

Ransom-ISAC has published a post-incident case study reconstructing a data-theft extortion case against a small US county government body, in which the victim paid roughly $1M after a May 2025 intrusion (Ransom-ISAC, 2026-07-03; The Hacker News, 2026-07-04). The distinguishing feature of the actor, self-styled "Kairos", is that it is a pure data-theft-and-leak extortion operation; Ransom-ISAC states "No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos", so its leverage rested entirely on the threat to publish stolen data rather than on file encryption (Ransom-ISAC, 2026-07-03). Kairos itself claimed the intrusion was achieved through a brute-force credential attack ("We accessed your network using a bruteforce attack") mapping to T1110 Brute Force and T1078 Valid Accounts; the report does not independently confirm the access method beyond the actor's own statement (Ransom-ISAC, 2026-07-03).

Kairos claimed access to more than 2 TB of data (approximately 1.6 million files) and exfiltrated it for leak-site leverage (T1567 Exfiltration Over Web Service); after roughly a month of negotiation the victim paid about $1M on 13 June 2025 (Ransom-ISAC, 2026-07-03; Security Affairs, 2026-07-04). Ransom-ISAC explicitly cautions that "The provided 'proof of deletion' was not technically verifiable and should not be treated as evidence that the stolen data was destroyed", noting there was nothing cryptographically binding the actor's deletion log to an actual deletion event (Ransom-ISAC, 2026-07-03).

We accessed your network using a bruteforce attack.

Kairos (quoted by Ransom-ISAC)

No ransomware sample, encryptor, or locker binary has been obtained or confidently linked to Kairos

The provided 'proof of deletion' was not technically verifiable and should not be treated as evidence that the stolen data was destroyed

Ransom-ISAC 2026-07-03
research05 Jul 00:25Zmulti-sourceOpen finding →

Earlier coverage (1)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats4
  • Research1

Source distribution

  • escudodigital.com2 (13%)
  • heise.de2 (13%)
  • aerzteblatt.de1 (7%)
  • ayto-velilla.es1 (7%)
  • borncity.com1 (7%)
  • frenchbreaches.com1 (7%)
  • ransom-isac.org1 (7%)
  • ransomware.live1 (7%)
  • other5 (33%)
All cited sources (15)