CSIDB logo
Threat actor

Chaos

Attribution profile

Type
Criminal
Location
-
Known incidents
2 incidents
Sources
0 sources
First seen
2026-06-09
Last seen
2026-08-25
Updated
2026-09-09 08:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias Chaos appeared in a ransomware leak site entry dated 2026-06-09. The entry placed the victim AireSpring in the Recent Victims section of the site. The leak site is accessible at https://ransomware.live/. This listing indicates that the actor is associated with ransomware activity.

AireSpring is described as a managed services provider. The company specializes in unified communications and related IT solutions. The leak site entry includes a brief description of the firm’s business focus. The compromise was noted as having been discovered recently relative to the listing date. No further details about the scope of the attack or any data exfiltration are provided in the source. Consequently, the exact scale of the incident remains unspecified.

The information originates solely from the ransomware.live leak site entry. No additional public reporting attributes the incident to any specific threat actor beyond the alias Chaos. Therefore, any broader targeting patterns, geographic focus, or strategic objectives for Chaos cannot be derived from the available source. The profile is limited to the confirmed details of this single observed incident. Consequently, further analysis would require additional independent reporting or disclosures.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 0 sources.

CSIDB