Cyber Insights: Kido Schools

Concise Cybersecurity Intelligence for Decision-Makers

Kido Schools Image

Download Our Cyber Insights Document on the Kido Schools Cyber Attack

Kido International — a UK-based nursery chain with locations in London and abroad — fell victim to a harrowing ransomware and data-extortion attack carried out by a threat actor calling itself “Radiant.” The attackers claimed to have exfiltrated personal data on approximately 8,000 children and their families, including names, photographs, home addresses, and safeguarding records, and threatened publication if a ransom was not paid. 

What made this incident especially disturbing was the direct targeting of minors and the use of threats against parents, placing it among the most serious data-breaches in the education and early-years sector. 

In our Cyber Insights document, we break down not only the timeline and technical vectors of the incident but also the strategic lessons for all organisations. 

Key take-aways include: 

  • Treating sensitive personal data—especially that of children—as a top-tier asset
  • Strengthening visibility and controls over third-party and SaaS vendor access
  • Enforcing least-privilege and strong authentication
  • Building Incident Response and Crisis Communication pathways with the greatest urgency to avoid reputational and regulatory fallout 
Looking to translate this real-world breach into actionable improvements within your organisation? Download our full Cyber Insights Document today for a complete understanding of this devastating. 
 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of CMA Cyber Insights on the Kido Schools Cyber Attack

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the Kido Schools Ransomware Attack

  • 1. What happened in the Kido Schools cyber attack?
    Kido International, a nursery and early-years education provider, suffered a ransomware and data-extortion attack in September 2025. The threat actor known as Radiant claimed to have stolen highly sensitive personal information relating to approximately 8,000 children and their families and threatened to publish the information unless a ransom was paid.
  • 2. What data was compromised in the Kido Schools cyber attack?
    The attackers claimed to have accessed sensitive information including children's names, photographs, home addresses and safeguarding records, as well as information relating to parents and carers. Employee information was also reportedly compromised. The nature of the stolen information made the incident particularly serious because of the potential privacy and safeguarding implications for minors.
  • 3. Who was responsible for the Kido Schools ransomware attack?
    A cybercriminal group calling itself Radiant claimed responsibility for the attack. The group used stolen information as leverage in an attempt to extort Kido and initially published samples of children's data on its leak site. The incident attracted widespread condemnation because of the deliberate use of children's personal information as an extortion tactic.
  • 4. Did the Kido hackers contact parents directly?
    Yes. Reports indicated that some parents were contacted directly by the attackers as part of their attempts to pressure Kido into paying the ransom. This escalation demonstrates how modern extortion attacks can move beyond targeting an organisation itself and directly involve customers, employees or other individuals whose information has been compromised.
  • 5. Did the hackers eventually delete the stolen Kido Schools data?
    Radiant subsequently removed the children's information from its leak site and claimed that it had deleted the stolen data following intense public and cybercriminal-community backlash. However, organisations and affected individuals should treat claims of data deletion by cybercriminals cautiously because there is generally no independent way to guarantee that additional copies have not been retained.
  • 6. Why are cyber attacks involving children's personal data particularly serious?
    Children's information can include highly sensitive and long-lived personal identifiers, photographs, addresses and safeguarding information. Unlike passwords, much of this information cannot simply be changed following a breach. Organisations handling children's data should therefore treat it as a high-value information asset requiring particularly strong access controls, monitoring, data minimisation and incident-response procedures.
  • 7. What cybersecurity lessons can organisations learn from the Kido Schools attack?
    The Kido incident reinforces the need to identify highly sensitive data, enforce least-privilege access, implement strong authentication and maintain visibility over third-party and SaaS access. Organisations should also have well-rehearsed incident response and crisis communication procedures so that technical containment, regulatory obligations and communication with affected individuals can happen quickly and effectively.
  • 8. How can schools and childcare providers reduce the risk of ransomware and data-extortion attacks?
    Education and childcare organisations should strengthen identity and access management, use multi-factor authentication, restrict privileged accounts, monitor unusual access and data transfers, maintain secure backups and carefully assess third-party technology providers. Regular cyber incident response and ransomware tabletop exercises can also help leadership teams prepare for difficult decisions involving data theft, ransom demands, regulatory reporting, safeguarding concerns and communications with parents.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.