Identity-based attacks played a role in 85% of ransomware incidents involving schools and universities, according to a new Sophos report.

The State of Ransomware in Education 2026 report found that attackers commonly used malicious emails, phishing, stolen login details, and repeated password attempts to gain access to education systems. The rate was higher than the 79% average across all industries surveyed.

Malicious email was the most common technical cause, accounting for 31% of ransomware attacks in lower education and 29% in higher education.

Sophos, a cybersecurity solutions provider, said education institutions remain vulnerable because they store large amounts of personal information but often have limited cybersecurity staff, skills, and budgets.

“Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, chief information security officer, Sophos. “Identity compromise has become one of the most effective paths into an organization, and AI is only increasing the speed, scale, and sophistication of these attacks.”

The report found that 77% of higher education institutions and 71% of lower education institutions considered their ransomware incident their most serious identity-related attack.

Schools and universities also took longer to recover. About 26% needed one to three months to resume normal operations, nearly double the 14% average across all sectors. Lower education institutions recorded the slowest recovery, with 31% taking at least a month.

The average ransomware recovery cost across the education sector reached $2.26 million, compared with the cross-sector average of $1.7 million. The median ransom demand was $775,200, higher than the $698,000 median across all industries.

In lower education, the percentage of organizations that had their data encrypted rose from 29% in 2025 to 61% in 2026. Overall, data was encrypted in 58% of ransomware attacks on education institutions.

Most affected institutions recovered their data from backups. This included 77% of lower education institutions and 69% of higher education institutions.

More than half of higher education institutions said they did not have enough skilled employees to detect and stop attacks. Lower education institutions attributed this to staff mistakes, poor security protection, security gaps they did not know about, and limited resources.

Ransomware attacks also put pressure on employees. About 39% of education institutions reported staff absences due to stress or mental health issues. Leadership changes followed attacks at 29% of higher education institutions and 27% of lower education institutions.

The report was based on a survey of 226 IT and cybersecurity leaders in 17 countries. All respondents worked for education institutions that had experienced ransomware in the past year. The survey was conducted from January to March 2026.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading