radiant
First seen October 12, 2025Active8 claimed victims
The claims below are reproduced as posted by radiant on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Spijkermat | October 29, 2025 | ransomware_live | — |
| Dutch ??? | October 16, 2025 | ransomware_live | — |
| Docurail | October 16, 2025 | ransomware_live | — |
| UK Rail Services | October 12, 2025 | ransomware_live | — |
| Retail Texas | October 12, 2025 | ransomware_live | — |
| Minnesota Hospital | October 12, 2025 | ransomware_live | — |
| Magna Foodservice | October 12, 2025 | ransomware_live | — |
| Kido Schools | October 12, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).