TL;DR: Education attacks increased by 75% in the past year, schools faced an average of 3,574 weekly attacks, ransomware against K-12 and higher education rose 105%, and schools were hit by more than 15,000 malicious QR phishing emails daily, according to KnowBe4. The sector’s weak identity and awareness controls turn routine phishing into rapid compromise.
NHIMG editorial — based on content published by KnowBe4: Target Rich, Cyber Poor: Global Education Is Unprepared For Escalating Cyberattacks
By the numbers:
- Cyberattacks on education increased by 75% in the past year.
- Schools faced an average of 3,574 weekly attacks.
- Ransomware attacks against K-12 and higher education surged by 105%.
Questions worth separating out
Q: What breaks when phishing succeeds in a school or university environment?
A: Phishing becomes dangerous in education when a single stolen credential can reach shared files, administrative systems, or remote services.
Q: Why do education organisations stay exposed to repeated phishing attacks?
A: Education has large, changing user populations, many external collaborators, and limited security staffing.
Q: How can security teams lower ransomware risk after a phishing foothold?
A: They should shrink the blast radius before they try to perfect detection.
Practitioner guidance
- Harden email and QR-based phishing controls Block or inspect QR-linked landing pages, require safe-link rewriting where possible, and add mobile-friendly credential harvesting detection because many education users now authenticate from phones and tablets.
- Reduce standing privilege across education systems Review staff, contractor, and administrator access to shared drives, learning platforms, finance systems, and remote management tools so one compromised account cannot move laterally across critical services.
- Improve identity verification at login Require stronger authentication for staff, privileged users, and sensitive systems, and make recovery workflows harder to abuse because password resets and account takeover often follow phishing.
What's in the full report
KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Sector-specific attack statistics broken down for primary schools, K-12, and universities
- Practical mitigation ideas for reducing user susceptibility to phishing and QR-based lures
- The report's fuller discussion of education-sector vulnerabilities and common attack patterns
- Context on how institutions can translate awareness into better access and identity controls
👉 Read KnowBe4's education sector cybersecurity whitepaper →
Education cyberattacks and phishing risk: what should schools do now?
Explore further
Education cyber risk is fundamentally an identity governance problem. The article focuses on phishing, but the real failure mode is the sector’s inability to reliably verify users, limit access, and contain compromise once a credential is stolen. That makes IAM, PAM, and lifecycle governance central to resilience, not supporting functions. Institutions that treat this as only an awareness issue will keep losing ground because the attack path ends in authenticated misuse, not just mailbox compromise.
A question worth separating out:
Q: What should schools prioritise first if they want better resilience against social engineering?
A: Prioritise authentication and access boundaries before adding more alerts. Stronger MFA, tighter privileged access, and clearer offboarding reduce the value of stolen credentials. User awareness still matters, but it is not sufficient on its own when attackers can turn one successful phishing message into authenticated access.
👉 Read our full editorial: Education cyberattacks are outpacing sector defences