IronSights

Incident response · Kairos data extortion

Contacted by Kairos? Nothing is encrypted. The decision is about the data.

Kairos is not a ransomware strain in the usual sense. No encryptor has ever been recovered from a Kairos incident, and Australian cases confirm it. Systems keep running and files are untouched. The first sign is an email, or a leak-site listing, saying your data is theirs. Since December 2024 it has listed a wealth manager, a real estate agency, a golf club, a hospitality group, a pharmacy chain, a strata manager, a jeweller, a fabric house and an owners-corporation manager, all Australian.

Recognise it

How to confirm it is Kairos.

Keep the extortion emails with their headers, any proof-of-theft file lists, and your firewall and remote access logs exactly as they are. Nothing here is encrypted, so the evidence is in the trail they left.

File extension
None. Kairos does not encrypt. If your files have been renamed or locked, a different group did it and this page is the wrong one
How they make contact
An email from the operator, sometimes sent from a mailbox inside your own organisation that they have taken over, and in at least one Australian case by phone. Proof-of-theft file lists are shared through throwaway file-hosting links. Their Tor portal needs the token from that message
First seen
The leak site appeared in November 2024 with six victims already on it. The operator works Russian-language criminal forums and a second brand, Kairos V2, was tracked through 2025. Its infrastructure was reported disrupted in April 2026, and listings continued regardless
Typical entry
An exposed Remote Desktop Gateway, a generic account with no multi-factor authentication and a sprayed password, or access bought from a broker. Data leaves over Rclone or SFTP

Behaviour

What Kairos does to your systems.

Theft, without encryption

Kairos skips encryption entirely. It takes data and proves it with samples. That removes the recovery problem and leaves the harder one: what was taken and who it belongs to.

Contact by email and phone

The approach arrives as email, occasionally from your own compromised Outlook account so it lands in colleagues' inboxes, and has been followed up by phone. Replies come within minutes to hours during US night-time.

A rules page with a seven-day clock

Kairos publishes its terms: seven days to respond, a discount for paying inside five, and a promise to delete the data and hand over a security report. After seven days it says it will notify your partners, competitors and customers, then publish everything.

It does publish

Australian listings have run from 24 gigabytes to more than 570 gigabytes, and full datasets have been released when victims did not pay. Samples have included passports, tenancy agreements, prescriptions and card scans.

Demands sized to your accounts

The group says its price is based on your income, expenses and documents, which is why it goes looking for financial records first. The one publicly documented settlement opened at three million US dollars and closed at one.

Australia is a regular target

Nine Australian organisations listed between December 2024 and July 2026, out of roughly a hundred victims worldwide. Almost all were small and mid-sized businesses in professional services, retail, hospitality and property.

The honest answer

Is there anything to recover?

Not in the way this word usually applies. Nothing is locked, so there is no decryptor to find and no partial recovery to attempt. Systems keep working, which is exactly why Kairos incidents are dangerous: the temptation is to carry on as normal while a clock runs that you did not set.

The work starts with the claim itself. Check the sample files and the file list against your own systems rather than taking either side's word for it. Then work out what left and when, from the remote access gateway, firewall and transfer logs, before those logs roll over. Your obligations run on a timeline from that point: an assessment under the Notifiable Data Breaches scheme has 30 days, and if a payment is ever made, a business with more than three million dollars in turnover must report it within 72 hours under the Cyber Security Act.

Keep the extortion emails with their headers, the proof files and the portal token exactly as received, and export your gateway and firewall logs today. That evidence is what scopes the incident, and it is what the regulator will ask about.

Common questions

Kairos, in plain terms.

Mid-incident and need a straight answer? Call 1300 004 766. A person answers, 24 hours a day.

  1. Does Kairos encrypt files?

    No. Across every published analysis and every Australian case, Kairos has stolen data and extorted over it without deploying an encryptor. Some recovery-vendor pages describe a Kairos file extension or encryption scheme; those claims are not supported by any primary analysis. If your files are locked, another group is responsible and identifying it is the first job.

  2. How do we know the Kairos claim is real?

    Check the evidence. Kairos shares a file list and sample documents; compare them against your systems, look for the remote access session that would have been needed to take them, and check outbound transfer volumes from your gateway and firewall logs. Claims have occasionally named the wrong organisation. Establishing the truth usually takes hours, and it changes every decision after it.

  3. Should we reply to Kairos?

    Not before you have counsel, your insurer and an incident responder in the room. Opening a conversation starts their clock and shapes their price, and anything sent from a compromised mailbox may be read by them. Kairos replies fast and negotiates down, which tells you the opening figure is a starting point rather than a bill.

  4. What are our notification obligations?

    If personal information was taken and serious harm is likely, the Notifiable Data Breaches scheme requires you to assess within 30 days and notify the OAIC and affected people once you know. If your organisation ever makes an extortion payment and has annual turnover above three million dollars, the Cyber Security Act 2024 requires a report to the government within 72 hours. Contracts, insurers and industry regulators may add clocks of their own. Start the timeline on day one.

  5. Kairos listed us, but nothing seems to be missing. What now?

    That is the normal experience, because theft leaves no gap. The data was copied and the originals are still where they were. Work backwards from the samples they published to the system that held them, then to the account and connection that reached it. In Australian cases that trail has led to a Remote Desktop Gateway with a shared account and no multi-factor authentication. Close that door before anything else.

  6. What should we do in the first hour?

    Preserve the emails, headers and proof files, export the logs from your remote access and firewall before they age out, reset the credentials on the path they used and turn on multi-factor authentication there, and open a simple timeline. Do not reply, do not delete anything, and do not let the compromised mailbox keep running. Our First-Response Guide covers the first steps on one page, and 1300 004 766 is answered around the clock.

Right now

The first hours decide what can be saved.

Preserve the emails and logs, close the remote access they used, start the notification clock, and call before anyone replies to the attacker. Australian incident response, answered by a real person.