Skip to content

Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data

Databreaches •Dissent • October 4, 2026

The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3.

On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised. They were also angry that the board was refusing to pay their ransom demand.

The district has updated its incident notice as recently as September 29. By then, they had reported that the school board had taken formal action to decline payment, approving the following motion:

I move that the Slate Valley Unified Union School District Board decline to authorize payment of any ransom or extortion demand arising from the District’s current cybersecurity incident and authorize the Superintendent, in consultation with the District’s legal counsel, cybersecurity professionals, insurance carrier, and appropriate law enforcement agencies, to continue all necessary response, recovery, investigation, notification, and remediation activities related to the incident.

I move that the Slate Valley Unified Union School District Board decline to authorize payment of any ransom or extortion demand arising from the District’s current cybersecurity incident and authorize the Superintendent, in consultation with the District’s legal counsel, cybersecurity professionals, insurance carrier, and appropriate law enforcement agencies, to continue all necessary response, recovery, investigation, notification, and remediation activities related to the incident.

The September 29 update did not claim that student data had not been compromised. Rather, Superintendent Brooke Olsen-Farrell wrote that:

We recognize that the length and complexity of this incident have created challenges and questions for our staff, families, and community. Cybersecurity investigations take time, and there are limits on what we can responsibly while the investigation remains active. We remain committed to communicating accurate information when it becomes available, and when sharing it, we will not compromise the investigation, the security of our systems, or our recovery efforts.

We recognize that the length and complexity of this incident have created challenges and questions for our staff, families, and community. Cybersecurity investigations take time, and there are limits on what we can responsibly while the investigation remains active. We remain committed to communicating accurate information when it becomes available, and when sharing it, we will not compromise the investigation, the security of our systems, or our recovery efforts.

In a statement to the Rutland Herald , she stated :

Determining whether any information was accessed or exfiltrated is an important part of the ongoing investigation. At this time, we are not in a position to confirm that student (data) was not compromised, although we believe it is unlikely for current students.

Determining whether any information was accessed or exfiltrated is an important part of the ongoing investigation. At this time, we are not in a position to confirm that student (data) was not compromised, although we believe it is unlikely for current students.

On its leak site, Kairos claims that they acquired 762 GB of information, which “includes 647 GB of SQL databases containing personal and medical information students and employees.”

DataBreaches examined some of the data.

Unredacted data Kairos provided to DataBreaches included some current student data.

A spreadsheet with 243 entries appears to have students’ first and last names, their date of birth, parents’ name(s), address, and phone number. The addresses were in Benson, Fair Haven, Hubbardton, Bomoseen, Castleton, and other towns.

There are also unlabeled fields that appear to relate to special education.

With respect to “current students,” DataBreaches found notes in that spreadsheet from April – June 2026. As examples:

“4/29/26 current placement is >80% but school year will change to 40-79%, so marked as such for Dec. Child Count to be accurate.”

“Student was referred to 504. 05/27/26 HA”

“Student is no longer elig for IEP 05/11/26 – HA”

DataBreaches validated that people with the parents’ names lived at those addresses. Other records provided to this site suggest that students named in the spreadsheet were likely receiving special education services under IEPs or other plans.

The spreadsheet did not include any Social Security numbers or parents’ financial information, but some entries referred to Medicaid as health insurance. Districts can bill Medicaid for certain special education services.

In addition to the spreadsheet, Kairos also provided a portion of a file disputing an educational placement or decision. FERPA protects these files, and schools treat them as confidential.

In sum, DataBreaches found evidence that Kairos has at least some current student data. Whether they have any data from regular education students is unknown to DataBreaches at this point. How much more data they may have on special education students is also unknown to DataBreaches.

In addition to the student data they provided, Kairos also provided DataBreaches with an unredacted 2026 spreadsheet containing data on employees, their spouses, and their dependents.

The employee information included information on 329 employees in a sheet dated 7/13/2026: first and last name, date of birth, full Social Security number, marital status, salary, job class, hire date, postal and email addresses, phone number, and other details.

The spreadsheet also included spouse and dependent information for 466 people, including their names, dates of birth, and Social Security numbers for most spouses and dependents.

Another tab included detailed employee benefit information.

In addition to the spreadsheet, Kairos also provided an employment issue file as part of its proof of claims.

A countdown clock on the district’s listing on the dark web leak site suggests that the data will all be leaked tomorrow.