Hackers operating under the name 'Radiant' claimed responsibility for stealing sensitive data from Kido, a nursery chain with operations in the UK, US, China, and India. The attackers posted samples of the stolen data, including pictures and profiles of children, on their darknet website to prove their possession and issued a ransom demand to Kido, threatening to release more data if their demands were not met. The group escalated their threats by adding more children's profiles and publishing private data of dozens of Kido employees, such as names, addresses, National Insurance numbers, and contact details. In a further escalation, the criminals reportedly contacted parents directly with threatening phone calls, increasing the pressure on Kido to pay the ransom. Public backlash and condemnation from the cybersecurity community led the attackers to initially blur the children's images, though the data remained online. Eventually, the hackers removed all the data and issued an apology, claiming to have deleted all the children's data and expressing regret for their actions. Despite these claims, cybersecurity experts cautioned that data, once exposed online, is difficult to fully erase and may resurface in the future. The attackers also revealed that they had paid an initial access broker for entry into Kido’s systems, suggesting a broader criminal ecosystem at play. While the immediate threat to the children’s data appeared to subside, concerns remained about the long-term implications of the breach. In a separate but related incident, a security researcher discovered a data leak involving over 600 resumes and CVs of Kido employees or job applicants, primarily from the Amelio school in India and kidoschools.com. This leak was reported to Kido, who promptly secured the exposed data after being notified. The exposed resumes contained extensive personal information, raising additional privacy concerns for affected individuals. The data leak was found in a publicly accessible storage bucket, which had been listed on Grayhatwarfare, indicating the possibility that others may have accessed the information before it was secured. Kido’s spokesperson confirmed the data had been locked down, but the company was still investigating the extent of unauthorized access. The dual incidents highlight significant weaknesses in Kido’s data security practices and underscore the risks faced by organizations handling sensitive information about children and employees. The breaches prompted discussions about the adequacy of Kido’s incident response and the need for improved security controls. The events also serve as a warning to other educational institutions about the importance of safeguarding personal data and monitoring for potential exposures. The public and regulatory scrutiny following these incidents is likely to drive further changes in Kido’s security posture and notification practices. The situation remains fluid as Kido continues to assess the full impact and potential obligations to notify affected individuals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Radiant added an unnamed hospital in Minnesota to its leak site and threatened to publicly identify the victim if extortion demands were not met. Reports said the group gave the hospital seven days, with an Oct. 13 deadline mentioned for compliance.
Kido International said it observed Radiant remove the previously published information and that it was following authorities' guidance not to pay a ransom. The company said it was working with law enforcement and cybersecurity experts to investigate and confirm permanent deletion of the stolen data.
Radiant said it removed the Kido data from its leak site, claimed an affiliate had 'gone rogue,' and stated it would not continue leaking the nursery chain's data. The group also said it would stop intrusions against organizations holding children's information and provided a security report and deletion log.
After the Kido leak, the Nova ransomware group publicly criticized Radiant on the Russian-language RAMP forum for exposing children's data. The criticism became a key factor in Radiant's subsequent response.
Radiant targeted Kido International, also known as Kido Schools, and published stolen data including images of preschoolers and parents' contact details. The incident drew significant backlash because it involved children and families.
Radiant Group began operating in September 2025 and appeared with a small number of victims on its leak site. Reporting later described it as a newly emerged ransomware operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcemalwarebytes.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.