Kairos
Kairos is a cyber extortion actor primarily associated with data-theft and leak-based coercion rather than confirmed file-encrypting ransomware operations.
Profile source: Mallory opens in a new tabKairos
Family profile
Kairos is a cyber extortion actor primarily associated with data-theft and leak-based coercion rather than confirmed file-encrypting ransomware operations. The group emerged in 2024 and operated a dedicated leak site used to name victims, apply negotiation pressure, and threaten staged public disclosure of stolen data. Reporting consistently characterizes Kairos as an extortion-focused actor for which no encryptor, locker binary, or verified ransomware payload has been confidently linked.
Kairos targets organizations across multiple sectors, including government, education, healthcare, and private industry, with observed victims in North America, Europe, and Australia. Public reporting indicates particular impact on public-sector entities, including a U.S. county government that reportedly paid approximately $1 million after Kairos claimed to have exfiltrated more than 2 TB of data. The group has also been associated with attacks against local government bodies, educational institutions, and healthcare-related organizations.
The actor’s tradecraft centers on data exfiltration, extortion negotiation, and reputational pressure. Kairos has been reported to claim initial access via brute-force attacks against credentials. Its extortion model relies on countdowns, fixed response windows, escalating deadlines, selective release threats, and references to especially sensitive data to increase pressure on victims. Kairos has advertised a victim workflow in which targets are given a limited period to respond before an initial leak post is published, followed by broader disclosure and full publication if negotiations fail. This places Kairos within the broader trend of encryption-less extortion operations that prioritize speed, lower operational overhead, and coercive disclosure threats over disruptive encryption.
Kairos has been observed on Russian-language cybercriminal forums and has been described as operating independently rather than as a clearly identified sub-group of another major cluster. At the same time, available reporting does not provide high-confidence attribution to a specific state sponsor or formal nation-state apparatus. Infrastructure associated with the group was later reportedly seized by Ukraine’s Security Service cyber authorities, but that does not by itself establish nationality or sponsorship.
Victim-volume reporting indicates Kairos became a moderately active extortion brand during 2025 and 2026, appearing in multiple ransomware and leak-site tracking datasets. Some reporting places the group’s first observed activity in late 2024, while other tracking suggests a dedicated leak-site presence beginning around mid-2024; the exact initial start date remains inconsistently reported. Known aliases in the available data are limited to Kairos itself.
Operational record
Recent claims
MITRE ATT&CK