Ransomware group
Kairos ransomware: victims and leak site activity
The Kairos ransomware group has listed 95 victims on its leak site since November 2024; its latest post is from 2 September 2026. Most affected countries: United States, Australia and United Kingdom. Most targeted sector: Professional Services.
Total posts
95
First seen
2024-11-13
Latest post
2026-09-02
Countries hit
15
About Kairos
Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.
Most targeted countries
- United States 54
- Australia 12
- United Kingdom 7
- Canada 4
- Germany 3
- France 3
- Denmark 2
- Spain 2
- Slovakia 2
- Cyprus 1
Most targeted sectors
- Professional Services 19
- Healthcare 13
- Education 12
- Government & Defense 11
- Manufacturing 8
- Retail & E-Commerce 8
- Financial Services 5
- Agriculture and Food Production 4
- Energy & Utilities 4
- Transportation 3