2026-08-22 · view entry permalink →
Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
The Ayuntamiento de Velilla de San Antonio, a municipality in the Community of Madrid, states it has detected a security incident that could have allowed the exposure of certain information held in its computer systems, and is explicit about the limits of what it knows: the investigation remains open and, for now, it cannot be confirmed that effective access to or extraction of data has occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Work is under way to determine the scope and nature of the potentially affected information, municipal services have not been affected and continue to operate normally, the matter has been notified to the National Cryptologic Centre and other competent authorities, and the Community of Madrid's cybersecurity agency has offered technical and coordination support under the regional incident-response model (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Against that carefully bounded statement sits the actor's claim: the extortion group Kairos says it accessed the municipal infrastructure and took 77.6 GB, and per the group's own published list the files would include administrative and personnel records, officially signed electronic documents, municipal motions, personal data and national identity documents (EscudoDigital, 2026-08-21). Nothing in that list is confirmed by anyone but the group claiming it.
Kairos is already in this store as a data-theft-only extortion brand, with no encryptor ever confidently linked to it, and the outlet's description of the model matches: the attacker enters the organisation, locates information of interest, copies it, and then threatens to publish it if the victim does not pay (EscudoDigital, 2026-08-21). The same outlet reported a Kairos claim against another Madrid-region municipality, Valdemoro, in May 2026, of 1.8 TB said to include police reports, citizens' identity documents and administrative files, following an incident that town hall acknowledged on its own website as having been detected on 5 May and having affected its servers (EscudoDigital, 2026-05-12). That earlier report is internally inconsistent in a way worth flagging rather than averaging: its headline frames the Valdemoro case as ransomware, while the background it carries on the same page describes Kairos as a group focused on data theft without encryption. Two Madrid-region town halls claimed by the same brand inside four months is a pattern worth naming, and the outlet is careful about how far it can be pushed: it says the coincidence of attacker and geography makes the Velilla case particularly relevant but does not on its own establish any relationship between the two incidents (EscudoDigital, 2026-08-21). No access vector has been disclosed for either case.
El Ayuntamiento de Velilla de San Antonio ha detectado una incidencia de seguridad que podría haber permitido la exposición de determinada información alojada en sus sistemas informáticos.
La investigación continúa abierta y, por el momento, no se puede confirmar que se haya producido un acceso o extracción efectiva de datos.
La incidencia no ha afectado a la prestación de los servicios municipales, que continúan funcionando con normalidad.
La Agencia de Ciberseguridad de la Comunidad de Madrid ha ofrecido su apoyo técnico y de coordinación al Ayuntamiento en el marco de sus competencias, de acuerdo con el modelo regional de respuesta ante incidentes.
Según la información difundida por el grupo, entre los archivos supuestamente obtenidos figurarían registros administrativos y de personal, documentos oficiales firmados electrónicamente, mociones municipales, datos personales y documentos nacionales de identidad (DNI).
La coincidencia del grupo atacante y de la localización geográfica convierte el caso de Velilla en una reivindicación especialmente relevante, aunque no permite establecer por sí sola ninguna relación entre ambos incidentes.