Quick Summary
AllegedExecutive Summary
Collège O’Sullivan de Québec, an educational institution located in Canada, was identified on July 20, 2026, as a victim on the dark web portal of the Kairos ransomware group through SOCRadar’s Dark Web Monitoring service. The organization operates within the post-secondary education sector, an area that consistently attracts ransomware threats due to the extensive student data it holds and the critical nature of its academic schedules. This listing places the college among a small but currently active set of victims attributed to Kairos. In the 60 days leading up to this listing, Kairos demonstrated relatively low operational volume, claiming a few other victims. The group’s recent activity shows a discernible focus on the education sector, with a geographical and linguistic footprint that includes Canada and French-speaking regions. While Collège O’Sullivan de Québec’s profile aligns with this pattern, the limited number of recent victims makes it difficult to definitively categorize Kairos as a specialized actor targeting educational institutions. The observed overlap includes organizations like Mortensenlawoffices and Commune De Camiers, though the current data sample is too small to establish a firm targeting thesis.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry, correlated with initial access indicators, revealed a significant exposure concerning the osullivan.edu domain. The most recent data captured approximately ten employee credentials linked to organization-owned systems, in addition to around fifteen records where corporate identities from osullivan.edu appeared on third-party services. This combination suggests a potential compromise of endpoints leading to credential leakage, rather than a singular theft event. Critical endpoints identified within the sample included the Microsoft 365/Entra ID sign-in portal and the Office 365 SMTP relay, which provide direct access to the tenant, as well as the college’s Brightspace learning management system and an internal service accessible through a dynamic-DNS host. The identified credential patterns were diverse, indicating both workstation compromises and potential intrusions into the corporate network. The data suggests a prolonged period of vulnerability, with log dates ranging from spring 2025 to mid-July 2026, implying that compromised credentials may not have been rotated for over a year. The recurrence of several corporate usernames across both identity infrastructure and consumer-facing websites further supports the assessment of workstation infections. For ransomware operations, the exposure of infostealer-harvested credentials is a known initial access vector. Threat actors or initial access brokers often source credentials from underground marketplaces, validate corporate access, and then utilize them to authenticate against services like Microsoft 365, VPNs, or remote access portals before deploying ransomware. While the observed stealer-log data does not definitively confirm that Kairos utilized these specific credentials for intrusion, the pattern—valid Microsoft 365 and SMTP credentials persisted and unrotated for over a year—is consistent with typical attack chains for such incidents. Consequently, CTI teams should consider these exposed accounts as potential access paths. Priorities should include organization-wide credential rotation, revocation of active sessions and tokens, enforcement of MFA on identity endpoints, and thorough endpoint forensics on users whose credentials have recurred across multiple compromised locations.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.