CTIPilot

Ville de Libercourt ransomware/data-theft incident (2026-08)

incident · incident:libercourt-kairos-ransomware-breach-2026-08 single-source

Ville de Libercourt (Pas-de-Calais, France) confirmed on 2026-09-15 a ransomware attack in late August 2026 with personal-data exfiltration, thirteen days after the extortion actor Kairos listed the commune on its own leak site (2026-09-02, no data volume stated). The commune does not confirm the responsible group, entry vector, or data scope; CNIL and ANSSI notified.

Coverage timeline
1
first 2026-09-17 → last 2026-09-17
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-17/kairos-libercourt-commune-ransomware-confirmed · ATT&CK page ↗

Story timeline

  1. 2026-09-17A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
    active-threatsVille de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • ayto-velilla.es1 (33%)
  • frenchbreaches.com1 (33%)
  • ransomware.live1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Ville de Libercourt ransomware/data-theft incident (2026-08) (1)

2026-09-17 · view entry permalink →

NOTABLENATOB2

A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site

The Ville de Libercourt, a commune in France's Pas-de-Calais department, announced on 2026-09-15 that it suffered a ransomware attack in late August 2026 and confirmed that personal data was exfiltrated (FrenchBreaches, 2026-09-16). The commune states it detected the threat quickly and had its external IT provider run technical checks, and has since deployed unspecified corrective measures to strengthen server-access security; it says municipal services were not operationally disrupted. It does not confirm the intrusion method, the responsible ransomware group, the categories or volume of exfiltrated data, or whether a ransom was demanded, all stated as still under investigation. The commune has notified France's CNIL and ANSSI, filed a criminal complaint, and is warning residents to watch for phishing attempts using any exfiltrated data (FrenchBreaches, 2026-09-16).

An extortion actor tracked as Kairos listed the commune on its own leak site on 2026-09-02, thirteen days before the commune's confirmation (Ransomware.live, 2026-09-02); the listing states no data volume or access vector, and no party (not the commune, not any other source) attributes the confirmed intrusion to Kairos beyond that leak-site claim and its timing. That gap matters here specifically: Kairos's own tracked history is data-theft extortion with no ransomware encryptor ever linked to it, while the commune's statement names a genuine ransomware attack; a tension the sources do not resolve, and one more reason the Kairos link stays a claim, not an attribution. Kairos separately claimed the Madrid-region municipality of Velilla de San Antonio in August 2026; that municipality's own statement confirmed a security incident but was explicit that it could not yet confirm effective data access or extraction had occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21), a narrower confirmation than Libercourt's, which names exfiltration outright. Taken together, this is now a second small European municipality where a Kairos leak-site claim coincides with a victim's own confirmation of at least a security incident, a pattern consistent with (though not proven to be) this actor opportunistically targeting small local-government administrations that typically run with limited in-house IT security staffing and externally contracted IT support, a profile shared by Swiss cantonal and communal administrations.

It is confirmed that personal data was exfiltrated. (translated from French)

Ville de Libercourt (relayed by FrenchBreaches)

Ransomware.live discovered on 2026-09-02 that Ville de Libercourt has been claimed by Kairos ransomware group

Ransomware.live 2026-09-02

Builds on: 2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality

incident17 Sep 04:37Zsingle-sourceOpen finding ↗