Ransomware activity has reached unprecedented levels in 2025, with a significant increase in both the number of victims and the proliferation of ransomware groups. According to a mid-year report by Searchlight Cyber, 3,734 victims were listed on public extortion sites from January through June, marking a 20% rise over the previous half-year and a 67% increase compared to the same period in 2024. This surge is largely attributed to the Ransomware-as-a-Service (RaaS) model, which allows core groups to rent out their tools to affiliates, thereby expanding their operational reach. The report identified 88 active ransomware groups in the first half of 2025, up from 76 in late 2024, with 35 of these being entirely new entities. This constant turnover, with groups frequently merging, splitting, or rebranding, complicates efforts to track and attribute attacks. Affiliates often move between groups, ensuring that even when a group dissolves, its members remain active in the ransomware ecosystem. The evolving landscape has also led to changes in attack tactics, with groups increasingly relying on data exfiltration and extortion rather than just encryption, as improved backup and restoration capabilities have reduced the effectiveness of traditional ransomware. The emergence of new, aggressive groups such as the Radiant Group exemplifies this trend. Radiant Group recently targeted Kido International, a preschool and daycare provider, leaking highly sensitive data including images, names, and addresses of children, as well as contact details of their parents. This attack, which affected UK-based families, demonstrates the extreme lengths to which some groups will go to pressure victims, including publishing personal data and threatening to contact regulators and associates. The Radiant Group’s tactics are among the most aggressive seen, and their willingness to target vulnerable populations highlights the ethical depravity of some actors in the ransomware space. The group operates without affiliates and has described itself as financially motivated, engaging in both double- and single-extortion attacks. The incident at Kido International has drawn attention from cybersecurity experts, who stress the responsibility of organizations holding sensitive data to implement robust security measures. The rapid evolution of ransomware tactics and the increasing number of groups present a growing challenge for defenders, who must continually adapt their strategies. Law enforcement and regulatory bodies have been notified of the Kido International breach, but responses are still pending. The overall trend indicates that ransomware will remain a dominant and evolving threat, with attackers becoming more brazen and innovative in their extortion methods. Organizations across all sectors, especially those handling sensitive personal data, are urged to strengthen their defenses and incident response plans. The combination of technical innovation, organizational churn, and aggressive extortion tactics underscores the complexity and severity of the current ransomware threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The incident was reported to the Information Commissioner's Office, indicating regulatory notification in the UK. This was disclosed in coverage of the breach as scrutiny of the handling of children's data intensified.
Kido International informed parents that it was aware of the breach and contacted them about the incident while an investigation was underway. Affected parents later confirmed to reporters that the organization had already notified them.
According to reporting cited in the references, the attackers directly contacted some parents and urged them to get the nursery chain to pay, escalating the extortion beyond the victim organization. This raised concerns about follow-on extortion and harassment of affected families.
To prove access and pressure Kido, Radiant posted sample data on its dark web leak site, including images and profiles of 10 children along with associated family details. Multiple reports described this as an unusually aggressive extortion tactic and noted it was the first leak posted on the group's site.
A ransomware group calling itself Radiant allegedly compromised Kido International, a preschool and daycare organization, and stole sensitive data relating to nearly 8,000 children and their parents or carers. Reported data types include names, photos, home addresses, dates of birth, and in some accounts safeguarding or medical information.
5 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcehelpnetsecurity.com
Open sourcemalwarebytes.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.