Kairos has surged this month, claiming 11 victims in the last 30 days against just 13 all-time since first appearing on tracking systems in late May 2026, an acceleration concentrated heavily in manufacturing (three of the top four sector hits) alongside education, public sector, and professional services targets. Geographic spread is broad and opportunistic, with claims spanning the US, Canada, New Zealand, France, and Australia rather than a fixed regional focus. The group is described as a data-theft-only operation that skips encryption entirely, claiming to purchase initial access from brokers and pressure victims into Bitcoin payments under threat of leaked data rather than locked systems. No MITRE ATT&CK techniques are yet catalogued for this group, leaving its actual intrusion tooling and lateral-movement methods unconfirmed. The pace of claims against a short operational history suggests either a highly efficient access-buying pipeline or aggressive relisting of victims to inflate visibility.