As students return to classrooms, a different kind of "back-to-school" activity is ramping up: Hack-to-School. Cybercriminals and nation-state actors are intensifying their focus on educational institutions. According to Bitsight Threat Intelligence, the education sector is now the third-most targeted industry by cyber threat actors, facing a wide range of persistent and emerging risks.
Educational institutions, from K–12 to major universities, are increasingly vulnerable due to their reliance on digital platforms and often limited cybersecurity infrastructure. Nation-state actors and financially motivated groups alike are exploiting this weakness.
Key findings from Bitsight Threat Intelligence
- Ransomware attacks: A total of 562 ransomware events targeting the education sector have been recorded, affecting organizations in Spain and Canada recently.
- Nation-state activity: The education sector ranks second in targeting by nation-state actors. Chinese threat actors account for 22 percent of these attacks, with a particular focus on universities involved in advanced research.
- Phishing and QR code exploits: QR code phishing has become a prominent tactic, enabling attackers to bypass traditional email filters and gain unauthorized access to sensitive data.
- Vulnerabilities: The widespread use of legacy systems and expansion into remote learning environments has significantly increased the sector's attack surface. These factors contribute to a high Cyber Risk Index (CRI) score for the industry.
Massive threat activity detected in education
According to Bitsight Threat Intelligence—by scanning thousands of clear, deep, and dark web sources—we found 3,686,102 results referencing or targeting the education sector. From this extensive pool, we extracted the most critical threat intelligence and patterns shaping current risks.
In a Bitsight TRACE research study (2023), we identified the Education sector as the most commonly targeted industry in terms of Known Exploited Vulnerabilities (KEV), accounting for 54.3% of observed incidents. Importantly, activity against education has not declined in the past two years, underscoring the sector’s persistent exposure to cyber threats.
Comparatively, we examined the average time to remediate a KEV across sectors. The Education sector averaged 151 days, placing it in the middle of the pack. By contrast, the Technology sector demonstrated the fastest remediation times, reflecting stronger patch management practices and more agile security operations.