INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Slate Valley Unified School District rejects ransom demand from Kairos
| 2026-10-04 19:12 MEDIUM LOW RANSOMWARE & EXTORTION
Executive Summary
AI-generated
The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat actors contacted DataBreaches to alert them to the incident and their response to the district's claim that they believed student data had not been compromised. The board declined to authorize payment of any ransom or extortion demand arising from the District’s current cybersecurity incident and authorized the Superintendent, in consultation with the District’s legal counsel, cybersecurity professionals, insurance carrier, and appropriate law enforcement agencies, to continue all necessary response, recovery, investigation, notification, and remediation activities related to the incident. The district has reported that student data is likely compromised, as DataBreaches examined some of the 762 GB of information acquired by Kairos, which includes personal and medical information about students and employees. The leaked data appears to include current student records with sensitive information such as date of birth, parents' name(s), home address, and home phone number, including notes from April-June 2026 indicating that some students were referred to special education services.
Technical Mitigations AI-generated
• Block or hunt for unlabeled fields that appear to relate to special education in the leaked data.
• Use FERPA-compliant tools and techniques to detect and protect sensitive student records, such as those disputing educational placement or decision files.
• Implement a robust search function on SQL databases containing personal and medical information about students and employees to identify any unauthorized access or exfiltration of current student data.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
healthhealth
Incident Timeline
June 2026
Threat actors leaked employee and spouse information, including Social Security numbers for 329 employees and 466 spouses and dependents, likely to cause harm.
Click on any entity below to view its context and source!
organisation
Social Security
The spreadsheet did not include any Social Security numbers or parents’ financial information, but some entries referred to Medicaid as health insurance.
organisation
Medicaid
The spreadsheet did not include any Social Security numbers or parents’ financial information, but some entries referred to Medicaid as health insurance.
organisation
IEP
05/27/26 HA”
“Student is no longer elig for IEP 05/11/26 – HA”
DataBreaches validated that people with the parents’ names lived at those addresses.
organisation
FERPA
FERPA protects these files, and schools treat them as confidential.
financial
79 Stolen / Extorted Funds
As examples:
“4/29/26 current placement is >80% but next school year will change to 40-79%, so marked as such for Dec. Child Count to be accurate.”
“Student was referred to 504.
victims
329 employees
The employee information included information on 329 employees in a sheet dated 7/13/2026: first and last name, date of birth, full Social Security number, marital status, salary, job class, hire date, postal and email addresses, home phone number, and other details.
September 3
Threat actors demanded ransom from the Slate Valley Unified School District, which ultimately declined to pay.
Click on any entity below to view its context and source!
organisation
The Slate Valley Unified School District
The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3.
September 29
Threat actors, identified as Kairos, made a ransom demand to the Slate Valley Unified School District on September 29.
October 2
Kairos threat actors contacted DataBreaches on October 2 to alert them of the incident and their response to a claim by Slate Valley Unified School District that student data had not been compromised.
Click on any entity below to view its context and source!
target_region
United States
On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised.
organisation
DataBreaches
On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised.
April – June 2026
Threat actors leaked data from a spreadsheet containing notes about current students between April and June 2026.
2026/10/04
Threat actors, identified as Kairos, leaked unredacted data containing students' personal information to DataBreaches.
Click on any entity below to view its context and source!
organisation
Slate Valley Unified School District
Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data.
organisation
SQL
On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information about students and employees.”
data_breach
762 GB
On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information about students and employees.”
data_breach
647 GB
On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information about students and employees.”
organisation
Unredacted
Student data
Unredacted data Kairos provided to DataBreaches included some current student data.
organisation
Benson
The addresses were in Benson, Fair Haven, Hubbardton, Bomoseen, Castleton, and other towns.
Tactical Metrics
Metrics
data_breach
762
Gb
Click for context!
On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information about students and employees.”
Metrics
data_breach
647
Gb
On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information about students and employees.”
Metrics
financial
79
Stolen / Extorted Funds
As examples:
“4/29/26 current placement is >80% but next school year will change to 40-79%, so marked as such for Dec. Child Count to be accurate.”
“Student was referred to 504.
Metrics
victims
329
Employees
The employee information included information on 329 employees in a sheet dated 7/13/2026: first and last name, date of birth, full Social Security number, marital status, salary, job class, hire date, postal and email addresses, home phone number, and other details.
Intelligence Sources
Data Breaches
2026-10-04
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:10
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
DataBreaches
entity
5x
timeline
Temporal Reference
October 2
date
3x
industry
Targeted Sector
Legal
sector
2x
data breach
Gb
762
gb
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
United States
country
tactic
Cyber Operation Type
Extortion
tactic
general metric
Entries
243
entries
general metric
%
80
%
financial
Stolen / Extorted Funds
79
%
victims
Employees
329
employees
general metric
People
466
people
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.