# Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent

> Slate Valley Unified School District (Fair Haven, Vermont) suffered a cyber incident beginning 2026-09-03. The Kairos group lists the district on its leak site claiming 762 GB (647 GB of SQL databases); the school board voted on 2026-09-29 not to pay and a countdown timer indicates publication is imminent.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2898
- **ID:** TL-2026-2898
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Kairos
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Slate Valley Unified School District (SVUUSD), Fair Haven, Vermont, reported a ransomware/cyber incident that began on 2026-09-03. According to DataBreaches.net (2026-10-04), the Kairos group listed the district on its dark web leak site claiming 762 GB of exfiltrated data, of which 647 GB are SQL databases containing personal and medical information. The school board voted on 2026-09-29 not to pay the ransom; the ransom demand was announced to media on 2026-10-02 and a countdown on the listing points to a leak around 2026-10-05. The ransom amount is not stated in the source.

Data described as exposed in the leak-site listing/sample material includes: student names, dates of birth, parents' names, home addresses and phone numbers, special education status (IEPs) and placement notes (April-June 2026), Medicaid billing references for special education students and FERPA-protected placement dispute files; a 7/13/2026 spreadsheet covering 329 employees (names, DOBs, full Social Security numbers, marital status, salaries, job class, hire dates, addresses, phone numbers, emails); and 466 spouse/dependent records with names, DOBs and SSNs. Superintendent Brooke Olsen-Farrell told the Rutland Herald the district is 'not in a position to confirm that student (data) was not compromised'.

Attribution and TTP context (from independent reporting on Kairos, NOT from the Slate Valley source): Kairos first surfaced on 2024-11-13 with a Tor leak site and is repeatedly described as a data-theft-only extortion operation that has never been confirmed to deploy encryption. Cyjax reports a 7-day deadline with a 20% discount for payment within 5 days, Bitcoin payment, and a promise of deletion within 24 hours of payment. In the Union County, Ohio case (May-June 2025) the group reportedly gained access through brute-forcing a single guessed password, exfiltrated ~2 TB / 1.6M files and was paid ~$1M after a $3M opening demand. A likely backend server (62.182.81.38, Virtual Systems LLC, Ukraine, ASN 209605) was reported seized by Ukraine's SBU Cyber Department in January 2026 and the original leak site reported down, yet new victim listings (including this one in September 2026) indicate the operation continues or has been rebuilt; this discrepancy is unresolved in the sources.

Caveats: the Slate Valley incident rests on a single source (DataBreaches.net); no CVE, initial-access vector, malware, or IOC specific to this incident has been published, and encryption is not confirmed. Technique mappings below are drawn from the group's documented behavior and the claimed data theft, not from forensic findings at the district. BeaconBeagle returned no usable result (HTTP 404) for 62.182.81.38.

## MITRE ATT&CK

- T1110.001 Brute Force: Password Guessing
- T1078 Valid Accounts
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1657 Financial Theft

## Sources

- [Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data (DataBreaches.net)](https://databreaches.net/2026/10/04/slate-valley-unified-school-district-voted-not-to-pay-ransom-demand-kairos-likely-to-leak-data/)
- [An elephant in Kairos: data-leak site emerges for new extortion group (Cyjax)](https://www.cyjax.com/resources/blog/an-elephant-in-kairos-data-leak-site-emerges-for-new-extortion-group)
- [U.S. Government Agency Paid $1M to Data Extortion Group Kairos (Security Affairs)](https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html)
- [County government reportedly paid $1 million to cyber extortion group (SecurityWeek)](https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/)
- [Union County, Ohio Government Pays $1 Million Bitcoin Ransom to Kairos After Data-Only Attack (Rescana)](https://www.rescana.com/post/union-county-ohio-government-pays-1-million-bitcoin-ransom-to-kairos-cyber-extortion-group-after-data-only-attack)
- [NSW-based Strata Republic allegedly breached by Kairos ransomware group (Cyber Daily)](https://www.cyberdaily.au/security/13487-exclusive-nsw-based-strata-republic-allegedly-breached-by-kairos-ransomware-group)
- [Kairos Ransomware Strikes Trico School District (DeXpose)](https://www.dexpose.io/kairos-ransomware-strikes-trico-school-district/)
- [Kairos ransomware: why extortion defense must go beyond encryption (Hexnode)](https://www.hexnode.com/threat-watch/kairos-ransomware-why-extortion-defense-must-go-beyond-encryption/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2898
