Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Ransomware News

UK Police Arrest Teens in Radiant Ransomware Nursery Attack

🇬🇧 United Kingdom - Two Teenagers Arrested in Radiant Ransomware Nursery Attack

October 8, 2025
Reading Time: 1 min read
UK Police Arrest Teens in Radiant Ransomware Nursery Attack

United Kingdom law enforcement has arrested two teenagers, aged 17 and 18, in connection with a ransomware attack against a London-based nursery chain that operates approximately 90 sites. The attack was attributed to the Radiant ransomware group.

The initial attack vector was a critical, yet common, security oversight. The threat actors gained access after discovering hardcoded credentials publicly exposed in a GitHub repository. Developers for the nursery chain had inadvertently left sensitive information, including a plain-text SMTP username and password, within a code file accessible to the public.

This type of vulnerability provides a direct and easy entry point for attackers, allowing them to compromise email systems, which can then be leveraged to move laterally and escalate the attack across the organization’s network.

In an unusual turn, the Radiant group reportedly issued an apology for the attack approximately a week before the arrests, subsequently removing the sensitive photos of children from their data leak site. Despite this, the National Crime Agency (NCA) and the Metropolitan Police proceeded with their investigation, arresting the two suspects on October 7th.

According to reports on the group’s initial extortion tactics, the compromised data included extremely sensitive information. Though later removed by the attackers, the data that was temporarily leaked allegedly included:

  • Photographs of children attending the nursery
  • Personal and administrative information related to the children and their families
Tags: credential exposurecybercrimedata-breachGitHub leakhardcoded credentialsnursery attackRadiant ransomwareSMTPteenagers arrestedUnited Kingdom
ShareTweet

Related Posts

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal
Ransomware News

Qilin Ransomware: Inspira, Muller, A&A, Longwood, Exclusive, Istarpal

April 27, 2026
Narteks Tekstil A.S. Suffers Krybit Ransomware Attack
Ransomware News

Narteks Tekstil A.S. Suffers Krybit Ransomware Attack

April 27, 2026
Synmosa Biopharma Hit by Dragonforce Ransomware Attack
Ransomware News

Synmosa Biopharma Hit by Dragonforce Ransomware Attack

April 27, 2026
K2 Electric Inc Targeted in Genesis Ransomware Attack
Ransomware News

K2 Electric Inc Targeted in Genesis Ransomware Attack

April 22, 2026
Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup
Ransomware News

Rutan & Tucker Law Firm Suffers Data Breach by Silentransomgroup

April 22, 2026
Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk
Ransomware News

Qilin Breach: Sea Air, Kolin, INDCAR, PTS, Huonker, Ferguson, SEL, Sterimed, Avitrans, Rusk

April 22, 2026
Next Post
Acuna Fombona (AFOM) Targeted in Space Bears Ransomware Attack

Acuna Fombona (AFOM) Targeted in Space Bears Ransomware Attack

Charter Industrial Supply Hit by Sarcoma Ransomware Attack

Charter Industrial Supply Hit by Sarcoma Ransomware Attack

Recommended Stories

Gerar (gerar.org.br) Targeted in Massive Data Breach

Gerar (gerar.org.br) Targeted in Massive Data Breach

October 22, 2025
NRJ Mobile Database Breach Raises Privacy Concerns

NRJ Mobile Database Breach Raises Privacy Concerns

December 25, 2024
Telegram’s Policy Changes Continue to Drive Criminal Groups Off the Platform

Telegram’s Policy Changes Continue to Drive Criminal Groups Off the Platform

September 27, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?