Skip to content

Kairos

1 claimLast activity:
Also known as:
  • Kairos V2 · Alias

Overview

Kairos is a financially motivated data-theft extortion operation tracked since late 2024. Researchers often include it in ransomware datasets, but a Ransom-ISAC case study found no encryptor or locker confidently linked to the group. Its demonstrated leverage is the threatened publication of purportedly stolen data. “Kairos V2” is a name TRM Labs associates with the operation; public evidence does not establish whether it denotes a formal rebrand or a distinct team.

Activity and targeting

FTI Cybersecurity described Kairos as emerging in late 2024 and making claims chiefly against U.S. organizations. TRM’s October 2025 research identified healthcare, manufacturing and business services among its reported targets. A 2026 Ransom-ISAC study reconstructed a data-extortion negotiation with a U.S. government body. These examples describe observed and claimed activity, not a limit on whom the operation may target. A Kairos monitoring page showed continued victim postings on Oct. 1, 2026.

Methods and operational characteristics

TRM reported that Kairos purchases access from initial access brokers and pressures victims with threats to publish files. In one Kairos-linked intrusion investigated by Triskele Labs, an attacker used valid credentials through an exposed Remote Desktop Gateway, attempted credential access and lateral movement, cleared Windows event logs, and transferred selected documents with Rclone over SFTP. Triskele observed no encryption in that case and documented email and telephone pressure against the victim. Ransom-ISAC’s separate negotiation study documented file-list sharing, publication deadlines and a payment, while treating the group’s access and deletion assertions as unverified.

What type of group is it?

Kairos’s observed demands and payment activity support a financially motivated cyberextortion assessment. Its payment flows analyzed by TRM overlap with cash-out infrastructure used by other groups, which may indicate shared affiliates or services; they do not establish that those groups have the same operators. Public research has not established a state sponsor or a Kairos encryptor. Individual victim listings, including the Oct. 1 Slate Valley claim, remain allegations until independently corroborated.

Incident claim

Slate Valley Unified Union School District cyberattack

Incident date: Source: ransomware.liveDiscovered:

Claim details

An Oct. 1, 2026, email sent to DysruptionHub from an address publicly listed as a Kairos contact claimed to have personal information for more than 1,500 Slate Valley employees, including Social Security numbers and home addresses, and threatened release. It included an image of apparent employee/benefits records and a ZIP link. Separately, an Oct. 1 Kairos victim listing identified Slate Valley Unified School District and alleged possession of 647 GB of SQL databases with personal and medical information about students and employees. The sender’s identity, the records’ authenticity and origin, the ZIP contents, claimed counts and volume, data theft, and Kairos’s responsibility for the district incident have not been independently established. The district has not identified an attacker or confirmed data theft.

Impacted organizations

Impacted locations

Sources