Slate Valley Unified School District suffered a ransomware attack discovered on September 3 that compromised a district server and teachers’ personal information. The incident disrupted internet access and internal platforms for approximately a week before cybersecurity contractors helped restore connectivity. Attackers identifying themselves as the Kairos ransomware group demanded hundreds of thousands of dollars and threatened to leak personal information they claimed belonged to more than 1,500 employees; that claimed scope has not been independently confirmed.
The FBI is investigating, and the school board said the district had made no ransom payments. District officials are notifying staff and working with outside specialists to identify affected individuals, while the Vermont Agency of Education has warned recipients not to engage with suspicious communications. Separately, TRM Labs has warned of impersonation scams in which malicious actors falsely claim affiliation with the company and offer fraudulent fund-recovery services, highlighting an additional fraud risk distinct from the school district incident.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
Slate Valley Unified School District discovered the attack on September 3 after teachers could not log in to Microsoft Windows. Attackers compromised a district server and obtained teachers’ records, disrupting internet access and internal platforms, including PowerSchool.
After the district alerted it to the incident, the Vermont Agency of Education reported that emails using the name “Kairos Support Group” had reached staff and community members. It urged recipients not to engage with suspicious messages and to preserve and forward them to the district.
Slate Valley notified staff about the breach and engaged outside specialists to identify affected current and former teachers and provide individual notifications. The superintendent said the district was paying cybersecurity firms hundreds of thousands of dollars to determine whose information had been compromised.
The school board denied making any ransom payments in response to the attack.
The FBI’s Albany office confirmed that it was investigating and assisting with the incident. The FBI advised the district against paying because ransom payments incentivize attackers and can encourage future attempts.
Individuals identifying themselves as the Kairos ransomware group emailed media outlets claiming possession of staff information and threatening to leak Social Security numbers, home addresses, and other confidential records. The claimed total of more than 1,500 affected employees was not confirmed by the district.
Attackers demanded hundreds of thousands of dollars in ransom from the district. Superintendent Brooke Olsen-Farrell declined to disclose the exact amount while the investigation remained ongoing.
Outside cybersecurity contractors helped restore Slate Valley’s connectivity after approximately one week without internet access and internal platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.