Two 17-year-old boys were arrested in Bishop’s Stortford, Hertfordshire, in connection with a cyberattack and attempted extortion targeting the British nursery school chain Kido. The Metropolitan Police Service led the investigation after receiving a referral about a ransomware attack on September 25. The attackers gained unauthorized access to sensitive data, including pictures and names of children enrolled at Kido’s nursery schools, as well as addresses and contact details for their parents and carers. The perpetrators published images and personal information of 20 children online, out of an estimated 8,000 children affected by the breach. This exposure significantly increased the risk to the children’s safety and wellbeing, prompting widespread concern among parents, carers, and the cybersecurity community. The attackers used the stolen contact information to make threatening phone calls to parents and carers, escalating pressure on Kido to pay an extortion demand in bitcoin. The incident was described by cybersecurity experts as a disturbing evolution in criminal tactics, given the targeting of vulnerable children and the use of their personal data for extortion. The Metropolitan Police’s cybercrime unit worked swiftly to identify and apprehend the suspects, who remain in custody for questioning on suspicion of computer misuse and blackmail. The breach and subsequent extortion attempt have been condemned by both law enforcement and cybersecurity professionals, highlighting the emotional and psychological impact on the affected families. The authorities have reassured the public that they are taking the matter seriously and are providing support to those impacted. The case has raised broader concerns about the security of sensitive data held by educational institutions and the potential for such information to be weaponized by cybercriminals. The incident has also sparked discussions about the need for enhanced cybersecurity measures and awareness in the education sector. Law enforcement officials have emphasized the importance of reporting cyber incidents promptly to facilitate rapid response and investigation. The arrests represent a significant development in the ongoing investigation, but the full extent of the breach and its long-term consequences for the victims are still being assessed. The Kido nursery chain is cooperating with authorities and has taken steps to notify affected families and bolster its cybersecurity defenses. The case serves as a stark reminder of the evolving threat landscape and the need for vigilance in protecting sensitive information, especially when it concerns children.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The UK Metropolitan Police arrested two 17-year-old boys in England in connection with the Kido nursery cyberattack and the online doxing of children. Police said the investigation was ongoing, and officials described the incident as deeply distressing.
On 2025-10-02, the attackers reportedly removed the leaked files from their dark web site after failing to extort Kido. One report says the group later claimed it had deleted the stolen data following backlash.
Kido stated that the compromised children's data had been stored in the Famly software platform used by nurseries to share information and photos with parents. Famly's CEO said Famly's own infrastructure was not breached and that no other customers were affected.
After the breach, the attackers published some children's photos and home address information on a dark web leak site and reportedly made threatening calls to parents. They demanded a £600,000 Bitcoin ransom from Kido as part of the extortion campaign.
On 2025-09-25, the Radiant Group targeted London-based nursery chain Kido in a ransomware attack. Reports say the attackers stole sensitive data relating to children and families, including photos, contact details, and other personal records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcehackread.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.