A New South Wales-based joinery business, Leisure Coast Kitchens, has been listed on the Kairos ransomware group’s leak site, adding another Australian organisation to the group’s growing list of alleged victims.
Leisure Coast Kitchens, a NSW-based company specialising in bespoke kitchens, joinery and related home projects, has reportedly been listed by the Kairos cyber-extortion group.
The company has been operating for around 30 years and provides kitchen and joinery services to residential customers.
At this stage, the listing should be treated as an unverified claim by the threat actor. A listing on a ransomware or extortion site does not, by itself, establish that an organisation was successfully compromised or that the data claimed by the actor is genuine.
Who are Kairos?
Kairos is a cyber-extortion group associated with ransomware-style operations. Recent reporting indicates continued activity during 2026, with the group targeting organisations across Australia, New Zealand, Europe and North America.

The group’s claimed victims have included organisations in the public sector, education, manufacturing, real estate, retail, pharmaceuticals, hospitality and professional services.
Kairos operations appear to place significant emphasis on data theft and threatened publication, rather than relying solely on traditional ransomware encryption.
Kairos Victim List
The following table shows organisations this year associated with Kairos listings, based on the victim information available to us.
| Company | Domain | Date Listed | Industry | Country |
|---|---|---|---|---|
| Leisure Coast Kitchens | leisurecoastkitchens.com.au | 17 Sep 2026 | Manufacturing | Australia |
| Warwick Fabrics | warwick.co.nz | 29 Jul 2026 | Textile, Manufacturing | New Zealand |
| LR Reed | lrreed.com.au | 22 Jul 2026 | Real Estate | Australia |
| Gregory Jewellers | gregoryjewellers.com.au | 22 Apr 2026 | Retail, Luxury Goods | Australia |
| Strata Republic | stratarepublic.com.au | 17 Apr 2026 | Real Estate, Asset Management | Australia |
| FriendlyCare Pharmacy | friendlycare.com.au | 15 Apr 2026 | Pharmaceuticals | Australia |
| Seagrass Boutique Hospitality Group | seagrassbhg.com | 12 Feb 2026 | Food and Beverage | Australia |
The victim data indicates that Kairos has not been focused on a single industry. The listed organisations span manufacturing, textiles, real estate, retail, pharmaceuticals and hospitality, while both Australia and New Zealand appear in the group’s claimed victim set.
The dates above represent the dates associated with the listings and should not necessarily be interpreted as the date an intrusion occurred.
Data theft rather than traditional ransomware
One of the more notable characteristics associated with Kairos is the apparent emphasis on data exfiltration and extortion.
In several reported cases, there has been no publicly confirmed evidence of Kairos deploying a conventional file-encrypting ransomware payload. Instead, the threat actor’s leverage can come from obtaining sensitive information and threatening to release it publicly.
This distinction is important for businesses.
An organisation does not necessarily need to experience widespread system outages or encrypted servers for a serious cyber incident to have occurred. If attackers gain access to sensitive business information and remove it, they can potentially use that information to pressure the victim into paying.
For a business such as Leisure Coast Kitchens, potentially sensitive information could include customer details, invoices, contracts, employee information, financial records, supplier information and other business documentation.
There is currently no public evidence confirming what, if anything, Kairos obtained from Leisure Coast Kitchens.
A reported $1 million payment
The potential financial consequences of Kairos-style data extortion were highlighted by reporting in 2026 concerning a US government entity.
According to reporting based on leaked negotiations and blockchain analysis, a US government organisation reportedly paid approximately US$1 million to prevent stolen information from being published. Kairos had reportedly demanded approximately US$3 million and claimed to have stolen more than two terabytes of data.
The identity of the organisation and the circumstances surrounding the reported payment have not been independently confirmed in all reporting, so the case should be treated accordingly.
The incident nevertheless illustrates the potential scale of financial demands that can accompany modern data-extortion operations.
Reported Kairos TTPs
The following MITRE ATT&CK techniques have been associated with Kairos activity:
| MITRE ATT&CK ID | Technique | Description |
|---|---|---|
| T1005 | Data from Local System | Collection of data stored on local systems |
| T1078 | Valid Accounts | Use of legitimate credentials to access systems |
| T1021 | Remote Services | Access to systems through remote services |
| T1133 | External Remote Services | Access through externally exposed remote services |
| T1486 | Data Encrypted for Impact | Encryption of data to disrupt availability |
| T1505 | Server Software Component | Abuse of server-side software components |
| T1110 | Brute Force | Attempts to obtain access through credential attacks |
| T1586 | Compromise Accounts | Obtaining or compromising accounts for subsequent operations |
The exact techniques used in an individual incident can vary. The presence of a technique in a threat-actor profile does not establish that it was used against Leisure Coast Kitchens.
What does the Leisure Coast Kitchens listing mean?
At this stage, the most important point is that the Kairos claim remains unverified.
The appearance of a company on an extortion site can indicate that an attacker believes it has compromised the organisation, but organisations and security researchers still need to validate the claim through technical investigation.
For now, the Leisure Coast Kitchens listing should be regarded as an alleged Kairos victim listing, rather than confirmation of a successful breach.
More information will be reported as further evidence becomes available.