Nursery chain Kido was the victim of a cyberattack in September 2025.
Hackers stole the personal information of thousands of nursery-aged children. By late September, profiles of 20 children had been published on the dark web. The attackers threatened to release more unless Kido paid a ransom.
The attack was a chilling sign of how far cybercriminals will go to extort money. It also showed why organisations that hold sensitive information cannot assume their sector makes them an unlikely target.
As one hacker behind the Kido attack said to a BBC reporter, “This isn’t my first time and will not be my last time.”
If you own or operate a small to medium business, this blog will explain simple steps you can take now to protect against similar data breaches and other cyber threats.
The nursery attack is more than just a shocking story – it’s a warning. Data itself is now a valuable asset in the criminal economy.
And if cybercriminals are willing to leak the personal details of children to extort money, then every business, in every sector, must consider itself a target.
The government Cyber Security Breaches Survey 2025/2026 shows just how widespread the threat has become:
- 46% of small UK businesses identified at least one cyber breach or attack in the preceding 12 months.
- 65% of medium-sized businesses did so, compared with 42% of micro businesses.
The survey also notes that many smaller organisations likely experience attacks without even realising it, as limited resources and defences make detection harder.
The outcomes of these attacks vary.
For example, Marks & Spencer said in May 2025 that it expected its cyber incident to reduce 2025/26 operating profit by around £300 million before mitigating actions.
Jaguar Land Rover’s September 2025 cyberattack disrupted production at its UK factories. The effects also reached smaller businesses in its supply chain.
For large firms with deep reserves or diversified revenue streams, such losses may be survivable. For smaller or mid-sized organisations, a comparable hit would likely be crippling.
In the Cyber Security Breaches Survey 2025/2026, the median estimated cost for micro and small businesses whose most disruptive breach had an actual outcome was £560. At the 90th percentile, it was £10,000.
These are businesses’ estimates of identifiable costs, including staff time and other indirect costs. The higher figure shows why a modest typical cost does not tell the whole story.
Cybercriminals use many different methods to steal data, extort money, or disrupt operations. But most attacks succeed because of a single, universal weakness – people.
Hackers exploit trust, curiosity, or pressure to persuade someone to click a suspicious link, download an unsecured attachment, or disclose sensitive information.
Below are several threats every organisation should recognise and prepare for:
Phishing is the most common form of cyberattack.
It typically involves a text message or email that looks genuine, often from a colleague, manager, or government body. The fake message asks the recipient to click a link, download a file, or share information. A malicious link may lead to a fake login page or a harmful download, while an infected attachment can install malware.
Phishing is so successful because it exploits our willingness to please others. Most people act without thinking when an authority figure or friend wants something urgently. Attackers use this instinct against us, pressuring people to click links to avoid a disaster or beat a deadline.
And the sophistication of these scams is growing. Attackers now use realistic branding, AI-generated messages, and even cloned websites to boost the reach and credibility of their phishing attempts.
How to reduce the risk: Pause before clicking. Check who the message really came from and verify unusual requests through another channel. Encourage employees to report suspicious emails rather than delete them.
AI makes it quicker and cheaper to research targets and write convincing fraudulent messages. Criminals can approach more businesses with requests that appear to come from a manager, supplier or customer. For a small business, that means an apparently personal message is no longer a reliable sign that the sender is genuine.
How to reduce the risk: Verify unexpected requests for payments, passwords or sensitive information through a contact method you already trust. Apply the same check to a familiar sounding voice call.
Ransomware is a form of digital extortion.
Hackers gain access to a company’s systems and encrypt its data, locking users out until a ransom is paid. In some cases, the attackers also steal sensitive files and threaten to release them publicly if payment isn’t made, which is exactly what happened to nursery operator Kido.
These attacks work because organisations can’t function without access to their data. Each passing hour adds pressure, and the pressure to restore operations can become intense.
Ransomware typically enters through phishing emails, infected attachments, or stolen passwords. Once inside a system, it spreads quickly, targeting shared drives and backups to maximise the impact.
How to reduce the risk: Back up data regularly and store copies securely offline. Keep all software and devices updated to close security gaps. Use strong, unique passwords reinforced with multi-factor authentication (MFA).
Supply chain attacks target your organisation through trusted partners or suppliers.
Instead of breaching your systems directly, hackers compromise a company you rely on – such as a software provider or logistics partner – and use that connection to gain access. Again, this was a factor in the Kido hack.
The risk depends on what data a supplier holds and what access it has to your systems. If a supplier’s account is compromised, attackers may be able to use that access or expose information the supplier holds.
How to reduce the risk: Vet suppliers carefully and ensure they meet recognised cybersecurity standards, such as Cyber Essentials. Constantly review who has access to your systems and data, and restrict permissions to what’s strictly necessary. Regularly audit third-party access to confirm it’s still needed.
Data-theft extortion happens when criminals steal sensitive information and threaten to publish it unless they are paid. They can put an organisation under pressure without locking it out of its files.
This is the tactic publicly reported in the Kido attack. The criminals published profiles of 20 children, threatened further releases and reportedly called some parents to pressure the nursery into paying. The affected data was stored in Kido’s Famly account, but Famly says its own systems were not breached. How the attackers obtained access has not been publicly established.
The attackers later removed the published profiles and claimed to have deleted the stolen data. Their claim should not be treated as proof that every copy was gone.
How to reduce the risk: Limit access to sensitive records, enable multi-factor authentication on the accounts that hold them and promptly remove access when someone leaves. Make sure staff know whom to tell if they spot unusual account activity.
Cybersecurity isn’t complicated – it’s mainly about awareness and consistency. Small improvements made today can protect your business from serious damage tomorrow.
Not every exposure of sensitive data begins with a cyberattack. An email sent to the wrong recipient or a file shared too widely can also put customer information at risk. Staff should check recipients and sharing settings, and report mistakes promptly so the business can limit the harm.
- Use strong passwords. Avoid reusing passwords across systems. Enable multi-factor authentication (MFA) for email and accounts holding business or customer data.
- Keep software updated. Regularly install updates for all devices, apps, and operating systems to close security gaps.
- Back up your data. Keep a separate backup of essential files and check that you can restore them.
- Control access. Give employees access only to the data and systems they need for their work.
- Secure your network. Protect Wi-Fi with strong passwords and avoid public or shared networks for work devices.
- Plan ahead. Have a simple incident response plan so everyone knows what to do if a breach occurs.
- Train your team. Teach staff to spot suspicious emails, links, and attachments. Give staff a simple way to report suspicious requests quickly.
For more guidance, the Federation of Small Businesses offers practical cybersecurity advice for small businesses on protecting business data, devices and customer information.
Awareness campaigns can help staff recognise and report suspicious activity. They work alongside measures such as multi-factor authentication, restricted access, updates and tested backups.
Human Focus offers a range of online cyber security and data protection courses covering cyber security, data security and GDPR essentials, including Cyber Security Awareness Training, which covers how to recognise phishing, vishing and other common threats.
Certificates show that learners have completed a course; they do not certify an organisation’s security or satisfy the technical requirements of Cyber Essentials on their own.