Desk live·
ForensicPost
Ransomware/Extortion/File 25-0926

Attackers Published Nursery Children's Details and Images as Extortion Pressure

Attackers who reached the nursery group Kido International published children’s details and images as extortion pressure. The corpus has recorded nothing else quite like it.

Constructed geometry · not a chart of case data
TargetKido International
ActorUnattributed
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Attackers who compromised the nursery group Kido International published details and images relating to children in its care as a means of applying extortion pressure, in an incident reported in September 2025.

Extortion Works By Finding Who Cannot Refuse

The corpus has traced this logic repeatedly. School districts were extorted after a vendor had already paid, at 25-0507. Clients and personnel were contacted directly after CRM data was taken, at 25-1029. Suppliers carried the cost of a manufacturer’s outage at 25-0928.

In each case the pressure is routed to a party with the least ability to make the decision and the most to lose. Publishing material relating to children is the endpoint of that logic, and it is the point at which the corpus stops being able to write about mechanism without saying plainly that this is different in kind.

The Remediation Frameworks Reach None Of It

This desk filed at 26-0113 that children have no credit file to freeze and that identity data belonging to a young child has a useful life to a fraudster measured in decades.

Published images are further outside the framework still. There is no monitoring product, no reissue, no freeze and no expiry. Nothing in the apparatus of notification and remediation described across this database addresses it at all.

A Nursery Group Is A Small Organisation

It holds identity records, medical and dietary information, family circumstances, safeguarding notes and photographs, because operating a childcare setting requires all of it.

And it has the security capability of a small business. That is the funding mismatch at 25-0910 and 25-1211 — the party best placed to protect the material cannot fund the protection — with the most sensitive data class in this corpus attached.

What This Desk Will Not Do

We do not describe the published material, quantify it, or name affected settings. Graded medium: the incident is well reported and this desk has deliberately not sought detail beyond what the argument requires.

How we reported this

Compiled from public reporting, listed below. We have not reviewed the published material and will not describe it. No affected individuals are identified. Corrections: corrections@forensicpost.com.

Sources
  1. Kido International cyberattackWikipedia
  2. The biggest cybersecurity and cyberattack stories of 2025BleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary