SUBJECT PROFILE
Kairos is a data-extortion actor first appearing in November 2024 that, per a Ransom-ISAC case study published July 4–5, 2026, extorted approximately $1 million from a U.S. government entity (likely Union County, Ohio) using only stolen-data exposure threats — no ransomware encryption was ever deployed. The group accessed the network via brute-force credential attack, exfiltrated 1.6 million files (2+ TB), and leveraged prosecutors' office records as maximum-pressure leverage. Kairos's leak site was seized by the Ukrainian Security Service (SBU); its last known victim was posted June 2026 and a linked wallet showed activity as recently as May 2026.
Financial — pure data-theft extortion (no encryption); targets under-resourced public sector entities holding sensitive citizen and law enforcement records
OPERATIONAL HISTORY
Brute-force credential access (T1110), data exfiltration (T1041), pure data-theft extortion (no encryptor), countdown timers and staged disclosure threats as negotiation pressure, temp.sh file-sharing for proof-of-theft delivery, Bitcoin ransom collection, rapid fund splitting to ByBit/OKX/BELQI for laundering
KNOWN INFRASTRUCTURE
Tor onion leak site (seized by Ukrainian SBU); clear-net backend at 62.182.81.38 (Virtual Systems LLC, Ukraine, AS30860); Bitcoin payment wallets linked to ByBit, OKX, and BELQI (Russian exchange); email contact at KairosSupp@[redacted] mirroring LockBit branding convention