CTIPilot
← Back to Daily brief 2026-09-17
NOTABLENATOB2incident

A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site

Ville de Libercourt confirms data exfiltration; Kairos claimed the commune on its leak site two weeks earlier

Analysis

The Ville de Libercourt, a commune in France's Pas-de-Calais department, announced on 2026-09-15 that it suffered a ransomware attack in late August 2026 and confirmed that personal data was exfiltrated (FrenchBreaches, 2026-09-16). The commune states it detected the threat quickly and had its external IT provider run technical checks, and has since deployed unspecified corrective measures to strengthen server-access security; it says municipal services were not operationally disrupted. It does not confirm the intrusion method, the responsible ransomware group, the categories or volume of exfiltrated data, or whether a ransom was demanded, all stated as still under investigation. The commune has notified France's CNIL and ANSSI, filed a criminal complaint, and is warning residents to watch for phishing attempts using any exfiltrated data (FrenchBreaches, 2026-09-16).

An extortion actor tracked as Kairos listed the commune on its own leak site on 2026-09-02, thirteen days before the commune's confirmation (Ransomware.live, 2026-09-02); the listing states no data volume or access vector, and no party (not the commune, not any other source) attributes the confirmed intrusion to Kairos beyond that leak-site claim and its timing. That gap matters here specifically: Kairos's own tracked history is data-theft extortion with no ransomware encryptor ever linked to it, while the commune's statement names a genuine ransomware attack; a tension the sources do not resolve, and one more reason the Kairos link stays a claim, not an attribution. Kairos separately claimed the Madrid-region municipality of Velilla de San Antonio in August 2026; that municipality's own statement confirmed a security incident but was explicit that it could not yet confirm effective data access or extraction had occurred (Ayuntamiento de Velilla de San Antonio, 2026-08-21), a narrower confirmation than Libercourt's, which names exfiltration outright. Taken together, this is now a second small European municipality where a Kairos leak-site claim coincides with a victim's own confirmation of at least a security incident, a pattern consistent with (though not proven to be) this actor opportunistically targeting small local-government administrations that typically run with limited in-house IT security staffing and externally contracted IT support, a profile shared by Swiss cantonal and communal administrations.

Cited evidence

It is confirmed that personal data was exfiltrated. (translated from French)

Ville de Libercourt (relayed by FrenchBreaches)

Ransomware.live discovered on 2026-09-02 that Ville de Libercourt has been claimed by Kairos ransomware group

Ransomware.live 2026-09-02

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.