Date range: 18 September – 1 October 2025
A clear, plain-English round-up of the most significant breaches and security incidents reported in the last two weeks. What happened, why it matters, and what to do next.
1) Kido nurseries breach and ransom: children’s photos and details stolen
Criminals calling themselves Radiant claim to have stolen data on roughly 8,000 children from Kido’s London nursery network, posting sample profiles and threatening further releases unless a ransom is paid. Parents report direct contact from the attackers. The NCSC called the reports “deeply distressing” and urged vigilance.
Why it matters: This is an egregious targeting of highly sensitive data. Expect phishing and pressure tactics aimed at families and staff.
2) European airports disrupted after supplier ransomware
A ransomware attack on Collins Aerospace passenger processing software forced airports including Heathrow, Brussels and Berlin to revert to manual check-in and baggage procedures, with delays and cancellations across Europe. Authorities have since arrested a UK suspect as the provider works on full restoration.
Why it matters: A single supplier outage cascaded across airlines and airports. This is a textbook example of third-party concentration risk.
3) Harrods customer data exposed via third-party provider
Harrods warned that a supplier breach exposed customer contact details. Passwords and payment data were not affected. Follow-up reporting suggests hundreds of thousands may be notified.
Why it matters: Retail continues to be hit through partners. Expect targeted scams that reference recent purchases or loyalty accounts.
4) Jaguar Land Rover: phased restart and government support after shutdown
Following a September cyberattack that halted production, JLR began a phased manufacturing restart while the UK announced loan-guarantee support for wider supply-chain stability.
Why it matters: The operational and financial impact of major incidents now extends through national supply chains.
5) Comcast breach claim (unconfirmed)
The Medusa group claims to have exfiltrated more than 800 GB of data from Comcast and is demanding a ransom. At the time of writing there is no official confirmation from the company; treat details as claims by the threat actors.
Why it matters: Even unconfirmed claims can fuel spear-phishing and market rumours. Verify before you trust any outreach that references this story.
For the best cyber security protection, contact us today. We will help you reduce supplier risk, harden identities, and build real incident resilience so your organisation stays out of the headlines.