CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)

incident · incident:velilla-san-antonio-kairos-breach-2026-08 single-source

The Madrid-region municipality of Velilla de San Antonio states it detected a security incident that could have allowed the exposure of information held in its systems, that the investigation remains open and that effective access to or extraction of data cannot yet be confirmed; municipal services were unaffected, the National Cryptologic Centre and other authorities were notified, and the Community of Madrid's cybersecurity agency offered technical and coordination support. The extortion actor Kairos claims 77.6 GB including administrative and personnel records, electronically signed official documents, municipal motions and national identity documents. No access vector has been stated (Ayuntamiento de Velilla de San Antonio and EscudoDigital, 2026-08-21).

Coverage
2
first 2026-08-22 → last 2026-09-30
Latest activity
2026-09-17
Ville de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
Peak priority
notable
1 notable · 1 routine
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
5
4 hosts
2026-08-222 appearances2026-09-17

Defender insights

What each entry about Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08) tells a defender to do, newest first.

2026-08-22NOTABLEAn encryption-free extortion brand is working through Spanish municipal administrations, where the first visible symptom is the claim itself

Triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-09-17A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
    active-threatsVille de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier
  2. 2026-08-22Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
    active-threatsAn encryption-free extortion brand is working through Spanish municipal administrations, where the first visible symptom is the claim itself
ATT&CK techniques (2 across 1 tactic)

2 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactData Encrypted for Impact · Financial Theft

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-17/kairos-libercourt-commune-ransomware-confirmed · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality · ATT&CK page ↗

Entries about Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08) (2)

2026-09-17 · view entry permalink →

ROUTINEupdatedNATOC2

A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site

The Ville de Libercourt (Pas-de-Calais, France) announced on 2026-09-15 a ransomware attack in late August 2026 with confirmed exfiltration of personal data, naming no access vector, group or data scope; it notified CNIL and ANSSI and says its IT provider ran the technical checks (FrenchBreaches, 2026-09-16). The extortion actor Kairos had listed the commune on its leak site on 2026-09-02 (Ransomware.live, 2026-09-02), after claiming the Madrid-region municipalities of Valdemoro in May and Velilla de San Antonio in August (Escudo Digital, 2026-08-21), but no source attributes the Libercourt intrusion to Kairos beyond that listing.

It is confirmed that personal data was exfiltrated. (translated from French)

Ville de Libercourt (relayed by FrenchBreaches)

Ransomware.live discovered on 2026-09-02 that Ville de Libercourt has been claimed by Kairos ransomware group

Ransomware.live 2026-09-02
Correctionrun 2026-09-30T0639Z-auditprioritybodyclassificationsourcessourcing_notesummary

Neither municipal case identifies a gap in an IT provider's detection or notification: Libercourt says its provider ran the technical checks (FrenchBreaches, 2026-09-16), and Velilla de San Antonio said it had activated its security protocols and was still establishing what happened (Escudo Digital, 2026-08-21). The earlier takeaway's claim that both cases share such a gap, and its reference to limited in-house IT staffing, had no source and are withdrawn.

Builds on: An encryption-free extortion brand is working through Spanish municipal administrations, where…

incident17 Sep 04:37Zsingle-sourceOpen finding →

2026-08-22 · view entry permalink →

NOTABLENATOA2

Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken

The Ayuntamiento de Velilla de San Antonio, a municipality in the Community of Madrid, states it has detected a security incident that could have allowed the exposure of certain information held in its computer systems, and is explicit about the limits of what it knows: the investigation remains open and, for now, it cannot be confirmed that effective access to or extraction of data has occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Work is under way to determine the scope and nature of the potentially affected information, municipal services have not been affected and continue to operate normally, the matter has been notified to the National Cryptologic Centre and other competent authorities, and the Community of Madrid's cybersecurity agency has offered technical and coordination support under the regional incident-response model (Ayuntamiento de Velilla de San Antonio, 2026-08-21). Against that carefully bounded statement sits the actor's claim: the extortion group Kairos says it accessed the municipal infrastructure and took 77.6 GB, and per the group's own published list the files would include administrative and personnel records, officially signed electronic documents, municipal motions, personal data and national identity documents (EscudoDigital, 2026-08-21). Nothing in that list is confirmed by anyone but the group claiming it.

Kairos is already in this store as a data-theft-only extortion brand, with no encryptor ever confidently linked to it, and the outlet's description of the model matches: the attacker enters the organisation, locates information of interest, copies it, and then threatens to publish it if the victim does not pay (EscudoDigital, 2026-08-21). The same outlet reported a Kairos claim against another Madrid-region municipality, Valdemoro, in May 2026, of 1.8 TB said to include police reports, citizens' identity documents and administrative files, following an incident that town hall acknowledged on its own website as having been detected on 5 May and having affected its servers (EscudoDigital, 2026-05-12). That earlier report is internally inconsistent in a way worth flagging rather than averaging: its headline frames the Valdemoro case as ransomware, while the background it carries on the same page describes Kairos as a group focused on data theft without encryption. Two Madrid-region town halls claimed by the same brand inside four months is a pattern worth naming, and the outlet is careful about how far it can be pushed: it says the coincidence of attacker and geography makes the Velilla case particularly relevant but does not on its own establish any relationship between the two incidents (EscudoDigital, 2026-08-21). No access vector has been disclosed for either case.

El Ayuntamiento de Velilla de San Antonio ha detectado una incidencia de seguridad que podría haber permitido la exposición de determinada información alojada en sus sistemas informáticos.

La investigación continúa abierta y, por el momento, no se puede confirmar que se haya producido un acceso o extracción efectiva de datos.

La incidencia no ha afectado a la prestación de los servicios municipales, que continúan funcionando con normalidad.

La Agencia de Ciberseguridad de la Comunidad de Madrid ha ofrecido su apoyo técnico y de coordinación al Ayuntamiento en el marco de sus competencias, de acuerdo con el modelo regional de respuesta ante incidentes.

Ayuntamiento de Velilla de San Antonio 2026-08-21

Según la información difundida por el grupo, entre los archivos supuestamente obtenidos figurarían registros administrativos y de personal, documentos oficiales firmados electrónicamente, mociones municipales, datos personales y documentos nacionales de identidad (DNI).

La coincidencia del grupo atacante y de la localización geográfica convierte el caso de Velilla en una reivindicación especialmente relevante, aunque no permite establecer por sí sola ninguna relación entre ambos incidentes.

EscudoDigital 2026-08-21
incident22 Aug 05:09Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats2

Source distribution

  • escudodigital.com2 (40%)
  • ayto-velilla.es1 (20%)
  • frenchbreaches.com1 (20%)
  • ransomware.live1 (20%)