Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Global Education Report Says Some Schools Endure Over 2,500 Attempted Cyberattacks a Day
Study & Research Latest News News & Analysis Security

Global Education Report Says Some Schools Endure Over 2,500 Attempted Cyberattacks a Day

Adam ParlettBy Adam ParlettMarch 21, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Education
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The latest report from cybersecurity company KnowBe4 begins with the staggering revelation that ‘Some schools endure over 2,500 attempted cyberattacks a day’ – and the learning doesn’t stop there for the education sector. 

The report, entitled ‘From Primary Schools to Universities, the Global Education Sector is Unprepared for Escalating Cyber Attacks,’ follows up its opening statement by examining risks and vulnerabilities across the sector. It draws from several sources to chart the scale of attacks in 2024 and lists some of the most significant attacks from 2024. It also takes a closer look at the most prominent attack methods. 

Vulnerable Students 

Both primary and higher education have vulnerabilities and risks that are specific to each, as well as some common factors that apply to both. 

Primary Education 

Although there are some variations, globally, primary education applies to children between the ages of 6 and 11. The main vulnerability is undoubtedly the age of the children. Targeting young children for their personal data or for predatory reasons elicits an emotional response from parents, teachers, and society at large. Malicious actors leverage this as they are aware institutions are keen to avoid reputational damage while parents and caregivers are predisposed to protect children in their care. Away from the emotive angle, schools are often underfunded institutions that are operating on legacy systems that hackers can more easily infiltrate. 

Higher Education 

Higher education encompasses schools for children between the ages of 11 and 18 and colleges and universities for adults over 18. The main vulnerability here is the amount of sensitive data institutions hold on a mix of legacy and modern systems. This data is often shared across different networks or accessed via remote learning, making it vulnerable if unsecured. Students in the younger age range of this spectrum also lack a developed understanding of security awareness. 

Common Factors 

Some of the common factors for both are balancing open access for collaboration and a reliance on third-party vendors providing software-as-a-service, cloud storage, and other IT services. 

Register of Attacks 

The report cites the Verizon 2024 Data Breach Investigation Report (DBIR), which examined 30,458 security incidents. Out of these recorded incidents, 10,626 were classified as data breaches, with 1,780 incidents of attacks targeting the education system, of which 1,537 had confirmed data disclosure. These statistics placed education in the top five of all industries breached globally. 

A different study highlighted in the report from Check Point Research found that education was the most targeted industry in terms of the global average of weekly attacks per organization by sector. They identified that educational institutions suffered, on average, 3,574 weekly attacks, a 75% increase from the previous year. 

Some of the largest attacks recorded in 2024 that were listed in the report included: 

  • The Toronto District School Board which was targeted by LockBit ransomware. A ransomware attack that compromised personal data, including names, email addresses, student numbers, dates of birth, and more. 
  • An attack on thirty-four schools in the Highline Public School district in Washington State which saw them forced to close and cancel activities due to a ransomware attack. 
  • Global digital classroom management platform Mobile Guardian, which was breached by a malicious actor in an attack that saw data from over 13,000 students wiped. 

Repeatable Methods 

The report states that “Ransomware attacks are easily the most prominent form of attack in the education sector,” with Phishing being identified as the “most commonly exploited method for gaining an initial foothold in an organization.” According to the report, phishing attacks have three main objectives: inserting malware by getting users to interact with documents containing attachments, stealing credentials through emails or forms containing malicious executables, or obtaining personal information by duping applicants for courses/jobs through social engineering techniques. 

Lessons to be Learned 

Stu Sjouwerman, the KnowBe4 CEO, believes that some important lessons can be derived from the report. “Educational institutions have inadvertently become prime targets for sophisticated threat actors due to an overall lack of resources. The most concrete, effective step that an educational institution can take to secure vital and sensitive data is to ensure that all individuals who access IT systems are equipped with the proper tools, education, and awareness to protect against cyber threats and reduce human risk.” 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Verizon DBIR 2026: What the experts are saying 

May 21, 202614 Mins Read

Online Safety Act failing to deliver “step change” for children, report warns

May 11, 20264 Mins Read

The quiet revolt: what the world happiness report 2026 tells security professionals

April 7, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}