The Kairos extortion group has claimed an early-September cyberattack on Slate Valley Unified Union School District in Fair Haven, Vermont. The district serves Benson, Castleton, Fair Haven, Hubbardton, Orwell and West Haven. Superintendent Brooke Olsen-Farrell has said the attackers took personal information belonging to current and former staff, along with district business documents. She said they are demanding "hundreds of thousands of dollars" (National Cyber Security), an amount she described to WCAX as "substantial." The school board voted on Sept. 28 not to pay. Kairos told the media it holds personal data on "more than 1,500 employees," including Social Security numbers and home addresses. Leak-site trackers report that the group's posted dataset is far larger than that claim suggests. All eight sources for this brief are local press or third-party trackers. We have no PRIMARY-tier document (such as a breach notification or regulator filing), so the district's own statements here come through press quotes.
What Happened
- Sept. 3, 2026: Staff arrived and could not log in to Windows devices or reach the internet (WPTZ, National Cyber Security). Teachers first thought the Wi-Fi was down. The district's internal IT team realized it was a cyberattack, not a network fault. According to the Rutland Herald, a ransom note was found on a server that same day. Olsen-Farrell alerted families that day. Email and internet were expected to be lost, but phones stayed up (WPTZ).
- Roughly one week of disruption: The district ran without internet or internal platforms, including the PowerSchool grading system, for about a week. Cybersecurity contractors helped restore service (National Cyber Security, Rutland Herald). School stayed open on manual workarounds. "The one thing we did not want to do is cancel school," Olsen-Farrell told WCAX.
- Sept. 28 (Monday): The board formalized its decision to decline any ransom or extortion payment, on the advice of legal counsel (Rutland Herald, WPTZ, WCAX).
- Sept. 29: A district press release said the district is working with cybersecurity professionals, legal counsel, its insurance carrier and law enforcement. The FBI is investigating (WPTZ, National Cyber Security).
- Oct. 1: Slate Valley appeared on the Kairos leak site, as indexed by Breach House and Cyber Threat Intelligence. Breach House lists the leak status as "pending."
The district says it is paying cybersecurity firms "hundreds of thousands of dollars" to work out which staff were affected (National Cyber Security). That means recovery costs alone are already in the same range as the ransom demand.
What Was Taken
Accounts of the scope differ a lot, and the gap matters.
- District position: Business documents and personal information of current and former staff were accessed (WPTZ, WCAX). Officials told WCAX they do not believe student data leaked. However, the Rutland Herald quotes the superintendent saying the district is "not in a position to confirm that student (data) was not compromised, although we believe it is unlikely." As late as Sept. 29, WPTZ reported the district had not yet said what data was affected.
- Kairos's claim to media: Personal information on "more than 1,500 employees," including SSNs and home addresses (National Cyber Security). That figure has not been independently verified.
- Leak-site trackers: Breach House records a dataset of 762 GB posted Oct. 1. Cyber Threat Intelligence cites ransomware.live, which says the data includes 647 GB of SQL databases containing personal and medical information about students and employees.
The tracker description directly contradicts the district's belief that student data was not affected. We cannot verify either side. Both trackers are OTHER-tier sources that repeat the group's own listing. The district's statement is itself hedged. Until the forensic review finishes and notifications go out, the student-data question remains open. The volume figures (647 GB to 762 GB) are large for a district this size. They suggest bulk database theft rather than a few HR files, but that is an inference, not something any source has confirmed.
Why It Matters
Kairos's operating model is described inconsistently. The Cyber Threat Intelligence profile calls Kairos a data-theft-only group "with no encryption," active since late 2024 and buying initial access from brokers. The same page also says the group "typically employs a double extortion model" that includes encrypting files. Slate Valley's experience matches the second description: locked-out Windows logins, a ransom note on a server, and a week-long outage. Defenders should not assume a "Kairos" incident is limited to data theft. The same page gives two victim counts for the group, 95 and 101.
Rural districts are being worked over. In August, VTDigger reported that a phishing campaign had hit several Vermont districts that summer, including Slate Valley. State officials warned that credential theft "is often just the first stage of a longer attack that can end in ransomware."
Refusing to pay does not end the costs. Slate Valley is spending heavily on forensics, staff face lasting identity-theft risk, and the stolen data is now listed on a leak site.
The Attack Technique
The initial access vector has not been disclosed. The district says it cannot share investigative details that could compromise the work (Rutland Herald, WPTZ).
There is one relevant prior event. In summer 2026, about a month before VTDigger's Aug. 19 report, Olsen-Farrell and other Slate Valley staff clicked a link labeled "excel secure portal" in a convincing phishing email. According to technology coordinator Walter Ripley, a script then ran in the background of their accounts. It read and deleted email and sent more phishing messages to their contacts. Ripley said no data was compromised at the time because the district acted quickly. Vermont Digital Services Secretary Denise Reilly-Hughes said credential harvesting was "only one part of the malware kill chain."
No source links that phishing incident to the September intrusion. The timing and the state's warning make it a reasonable line of inquiry, not a finding. Kairos's reported habit of buying access from brokers (Cyber Threat Intelligence) fits a scenario where harvested credentials were resold. That is also unconfirmed.
What Organizations Should Do
- Treat any successful phish as a full compromise. If a user clicks a credential-harvesting link, reset passwords, revoke sessions and OAuth tokens, audit mailbox rules and sign-in logs, and hunt for persistence. Do not stop at "no data lost."
- Use phishing-resistant MFA everywhere. Prioritize admin, finance, HR and remote-access accounts. Harvested credentials sold to access brokers are a common route into district networks.
- Segment and monitor HR, payroll and student-information databases. Alert on large outbound transfers. An exfiltration of hundreds of gigabytes should not go unnoticed.
- Keep offline, tested backups of identity infrastructure and core platforms such as Active Directory and SIS/gradebook systems. That way, losing Windows logins means days of disruption, not weeks.
- Pre-negotiate incident response. Have IR retainers, legal counsel and cyber insurance terms settled before an incident. Prepare staff and family notification templates so the response does not depend on emergency spending.
- Minimize stored PII. Purge or archive former-employee SSNs and records that are no longer legally required. Slate Valley's exposure includes former staff.
Sources: Hackers demand ransom from Slate Valley school district after compr... | A Rutland County school district recovers from cybersecurity attack... | Slate Valley School Board moves to deny ransom be paid in cyberatta... | Slate Valley Unified School District — KAIROS Ransomware Attack Br... | Slate Valley Unified School District Ransomware Attack by Kairos (2... | Vermont education officials face sophisticated phishing scheme this... | Slate Valley school district refuses ransom following cyberattack | Slate Valley will not pay ransom in cyberattack, board says - WPTZ