The Kido Nursery Ransomware Attack: How Cyber Attacks are Worsening in the UK

In the past week, it has come out that a ransomware attack on Kido Nurseries has seen critical information on 8000 children be ransomed for money. The hacker group, which is calling itself Radiant, has posted 10 profiles of children as proof. They are threatening to release more unless a ransom is paid.
This disgusting act shows just how far criminals will go to make money. It shows a complete lack of ethics and morals in Radiant, if it will target the most vulnerable people in our society.
“Cyber criminals will target anyone if they think there is money to be made, and going after those who look after children is a particularly egregious act.” – Jonathon Ellison, NCSC Director for National Resilience
The Metropolitan Police and the National Cyber Security Centre are investigating. The incident has prompted concerns about data security in education, given the sensitive nature of children’s personal data. According to The Guardian, the breach came via a third party system, some kind of platform the nursery uses. This is important as even if your own company has high-levels of defence against data breaches, it shows how third-party software can be a weakness that cyber criminals can exploit. It will not be easy for the police to apprehend the criminals, as they are experts at shrouding themselves online.
A cybersecurity industry briefing analysed that there was a slight awkwardness in the English language used by the group, hinting that perhaps they are of non-western origin. This is one of the most difficult aspects of cyber criminality – you can be halfway across the world and cause a world of pain to companies and the people impacted.
It follows a worrying trend of relentless cyber attacks, this year alone headlines broke about a M&S data breach, last month Jaguar Land Rover had to suspend production for over a month due to a cyber attack and now this attack has surfaced as being the most unethical one yet. It signifies how it doesn’t matter what industry you are in, you are at risk of cyber attacks. Whether it’s retail, manufacturing or schooling.
It highlights the need for a renewed effort to shore up defences and to build practices that can better punish and catch these criminals. Organisations with sensitive data are common ransomware targets, so hopefully this attack will ensure that other educational institutions will ensure they are as protected as possible. Public sector organisations are at risk, as they hold a lot of sensitive data.
In summary, the Kido nursery ransomware attack illustrates how cybercriminals are increasingly willing to target institutions caring for children – entities that hold extremely sensitive data yet may lack robust cyber-defences. This is part of a wider trend of ransomware attacks getting bolder. Unless organisations, especially in education, health, childcare and similarly sensitive sectors, dramatically improve their cybersecurity posture, these attacks are likely to increase in severity.
We are hosting The Public Sector Cyber Security Conference 2026 on the 5th of February, 2026. It is free to attend, and we aim to build upon the award-winning event, bringing more speakers and sponsors to create a day of meaningful learning and connection. Keep an eye out on our LinkedIn, as we are hosting a free-to-attend online webinar in November, where industry leaders will introduce you to some of the topics being discussed in the February conference.
