ctipilot.ch

Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)

incident · incident:velilla-san-antonio-kairos-breach-2026-08

The Madrid-region municipality of Velilla de San Antonio states it detected a security incident that could have allowed the exposure of information held in its systems, that the investigation remains open and that effective access to or extraction of data cannot yet be confirmed; municipal services were unaffected, the National Cryptologic Centre and other authorities were notified, and the Community of Madrid's cybersecurity agency offered technical and coordination support. The extortion actor Kairos claims 77.6 GB including administrative and personnel records, electronically signed official documents, municipal motions and national identity documents. No access vector has been stated (Ayuntamiento de Velilla de San Antonio and EscudoDigital, 2026-08-21).

Coverage timeline
1
first 2026-08-22 → last 2026-08-22
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality · ATT&CK page ↗

Story timeline

  1. 2026-08-22Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
    active-threatsAn encryption-free extortion brand is working through Spanish municipal administrations, where the first visible symptom is the claim itself

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • escudodigital.com2 (67%)
  • ayto-velilla.es1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08) (1)

2026-08-22 · view entry permalink →

NOTABLENATOA2

Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken

The Ayuntamiento de Velilla de San Antonio, a municipality in the Community of Madrid, states it has detected a security incident that could have allowed the exposure of certain information held in its computer systems, and is explicit about the limits of what it knows: the investigation remains open and, for now, it cannot be confirmed that effective access to or extraction of data has occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Work is under way to determine the scope and nature of the potentially affected information, municipal services have not been affected and continue to operate normally, the matter has been notified to the National Cryptologic Centre and other competent authorities, and the Community of Madrid's cybersecurity agency has offered technical and coordination support under the regional incident-response model (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Against that carefully bounded statement sits the actor's claim: the extortion group Kairos says it accessed the municipal infrastructure and took 77.6 GB, and per the group's own published list the files would include administrative and personnel records, officially signed electronic documents, municipal motions, personal data and national identity documents (EscudoDigital, 2026-08-21). Nothing in that list is confirmed by anyone but the group claiming it.

Kairos is already in this store as a data-theft-only extortion brand, with no encryptor ever confidently linked to it, and the outlet's description of the model matches: the attacker enters the organisation, locates information of interest, copies it, and then threatens to publish it if the victim does not pay (EscudoDigital, 2026-08-21). The same outlet reported a Kairos claim against another Madrid-region municipality, Valdemoro, in May 2026, of 1.8 TB said to include police reports, citizens' identity documents and administrative files, following an incident that town hall acknowledged on its own website as having been detected on 5 May and having affected its servers (EscudoDigital, 2026-05-12). That earlier report is internally inconsistent in a way worth flagging rather than averaging: its headline frames the Valdemoro case as ransomware, while the background it carries on the same page describes Kairos as a group focused on data theft without encryption. Two Madrid-region town halls claimed by the same brand inside four months is a pattern worth naming, and the outlet is careful about how far it can be pushed: it says the coincidence of attacker and geography makes the Velilla case particularly relevant but does not on its own establish any relationship between the two incidents (EscudoDigital, 2026-08-21). No access vector has been disclosed for either case.

El Ayuntamiento de Velilla de San Antonio ha detectado una incidencia de seguridad que podría haber permitido la exposición de determinada información alojada en sus sistemas informáticos.

La investigación continúa abierta y, por el momento, no se puede confirmar que se haya producido un acceso o extracción efectiva de datos.

La incidencia no ha afectado a la prestación de los servicios municipales, que continúan funcionando con normalidad.

La Agencia de Ciberseguridad de la Comunidad de Madrid ha ofrecido su apoyo técnico y de coordinación al Ayuntamiento en el marco de sus competencias, de acuerdo con el modelo regional de respuesta ante incidentes.

Ayuntamiento de Velilla de San Antonio 2026-08-21

Según la información difundida por el grupo, entre los archivos supuestamente obtenidos figurarían registros administrativos y de personal, documentos oficiales firmados electrónicamente, mociones municipales, datos personales y documentos nacionales de identidad (DNI).

La coincidencia del grupo atacante y de la localización geográfica convierte el caso de Velilla en una reivindicación especialmente relevante, aunque no permite establecer por sí sola ninguna relación entre ambos incidentes.

EscudoDigital 2026-08-21
incident22 Aug 05:09Zmulti-sourceOpen finding ↗