The Containment Era is here. →Explore

Executive Summary

In September 2025, the Kido International nursery chain, operating in several countries and serving over 15,000 families, suffered a ransomware attack orchestrated by the Radiant Group. Attackers accessed sensitive data and photographs of more than 1,000 children, their families, and nursery employees. Some stolen data, including children's pictures and residential addresses, were leaked on a dark web site to pressure Kido into paying a ransom. When extortion attempts failed, the attackers removed the leaked files, but only after making threatening calls to parents, intensifying the distress of the incident.

This event underscores the alarming targeting of childcare and educational institutions by cybercriminals, reflecting a broader trend of ransomware attacks exploiting organizations that handle sensitive personal data. The swift arrests by London police of suspects involved demonstrate growing law enforcement action, yet also highlight increased risks for sectors entrusted with children's safety and privacy.

Why This Matters Now

This incident highlights the urgent need for educational and childcare organizations to enhance their cybersecurity posture as ransomware groups increasingly target institutions with sensitive personal data. With regulatory and parental scrutiny mounting, organizations must address gaps in data security, segmentation, and threat response to protect vulnerable populations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach highlights the need for stronger data encryption in transit, east-west network security, and zero trust segmentation to meet regulatory requirements like PCI DSS, HIPAA, and NIST 800-53.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust network segmentation, east-west workload isolation, encrypted traffic controls, and egress policy enforcement would have limited adversary access, lateral movement, and blocked data exfiltration, minimizing incident impact. Continuous threat detection and anomaly response could have enabled rapid detection and containment during early and mid-stages of the attack.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Reduced initial exposure surface by restricting unauthorized access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevented unauthorized privilege elevation between identities or workloads.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked or detected unauthorized lateral movement within cloud and SaaS infrastructure.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected and blocked command-and-control activity.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented unauthorized exfiltration of sensitive data.

Impact (Mitigations)

Enabled early detection to reduce incident scale and response time.

Impact at a Glance

Affected Business Functions

  • Childcare Services
  • Parent Communication
  • Employee Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Personal information of approximately 8,000 children, including names, photographs, dates of birth, and addresses, as well as data on parents, carers, and employees, was compromised and leaked online.

Recommended Actions

  • Rapidly implement egress security and FQDN filtering to prevent unauthorized data exfiltration from cloud and SaaS environments.
  • Enforce Zero Trust segmentation and least-privilege access across all cloud workloads, databases, and user identities.
  • Deploy cloud-native inline IPS and traffic anomaly detection to identify and block attack communications and lateral movement.
  • Centralize multi-cloud visibility and audit logging to accelerate threat hunting and incident response.
  • Regularly validate account and workload access policies with microsegmentation and real-time policy enforcement.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image