Radiant is a newly emerged cybercriminal extortion and ransomware group that became publicly visible in 2025. The group is primarily known for an attack against Kido International, a nursery and preschool operator, in which it claimed to have stolen sensitive data relating to thousands of children, families, and staff and used that material for coercive extortion. Radiant also later claimed a separate intrusion affecting an unnamed hospital in Minnesota, indicating an opportunistic victimology spanning education and healthcare. Radiant has operated through a leak site and follows a data-theft-led extortion model consistent with modern ransomware ecosystems, where public exposure and reputational pressure can be as important as, or more important than, encryption. Reported behavior includes publishing stolen records as proof of compromise, issuing ransom demands, threatening broader disclosure, and directly contacting victims’ stakeholders to intensify pressure. In the Kido case, the group reportedly escalated beyond conventional leak-site pressure by contacting parents and exposing children’s personal information and images, an unusually aggressive tactic that drew condemnation even from other cybercriminal actors. Open reporting has described Radiant as a financially motivated operation. At least one public description attributed to the group characterized it as conducting single- and double-extortion activity and operating without affiliate support, although Radiant later claimed that a partner or affiliate had acted improperly in the Kido incident. Following backlash, the group stated that the childcare targeting violated its rules, claimed it deleted the stolen child-related data, and said it would avoid future intrusions involving children’s information. Those self-serving claims should be treated cautiously, but they are part of the group’s known public posture. Radiant’s tradecraft, as reported, includes use of stolen access obtained through third-party or brokered credentials, maintenance of unauthorized access for a period before extortion, exfiltration of sensitive data, leak-site publication, and direct victim or stakeholder harassment. The group’s behavior aligns with extortion-centric techniques such as data theft, public shaming, coercive communications, and pressure through exposure of regulated or highly sensitive information. Its known aliases include Radiant Group and radiant_group. Law-enforcement reporting linked the Kido investigation to the arrest of two 17-year-old suspects in the United Kingdom in October 2025, and some commentary has suggested the operators may be young, native English-speaking actors rather than a mature state-backed or traditional Russian-language ransomware crew. However, Radiant is best characterized on currently available information as a criminal extortion actor, not a nation-state threat actor. High-confidence public attribution beyond that remains limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion actor noted for extreme personal-data targeting: allegedly leaked photos and identifying details of children/staff to maximize psychological pressure; activity reportedly ceased after UK law-enforcement action.
Claimed responsibility for attacks (including a London nurseries chain), involving theft of personal data of children/families and attempted extortion for ransom paid in Bitcoin.
Radiant is a ransomware group known for leaking sensitive personal data, including images and contact details of children, as part of their extortion tactics.
Radiant is a ransomware group actively targeting organizations in Germany and globally, with recent attacks on Magna Foodservice and other entities. They use leak sites for extortion and data publication.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.