Sophos report: identity compromise involved in 85% of education ransomware attacks

0

Sophos’ latest State of Ransomware in Education 2026 report found identity-based techniques were used in 85% of ransomware attacks against education institutions, exceeding the cross-sector average of 79%.

The company said identity-based techniques included malicious email, phishing, compromised credentials and brute force attacks. Malicious email was identified as the leading technical root cause of ransomware attacks in both lower education (31%) and higher education (29%), according to the report.

Sophos reported average ransomware recovery costs in education reached $2.26 million, above the cross-sector average of $1.7 million. It also said more than a quarter (26%) of education institutions required one to three months to fully recover, nearly double the cross-sector average (14%).

The report found 77% of higher education organisations and 71% of lower education organisations said their ransomware incident was also their most significant identity attack.

Education institutions were also described as slower to recover than other sectors. Sophos said lower and higher education institutions were roughly twice as likely as the cross-sector average to require one to three months to fully recover. In lower education, 31% took a month or more to recover, the highest share of any sector, according to the report.

“Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, chief information security officer at Sophos. “Today’s attackers don’t need a crowbar when they can steal the keys. Identity compromise has become one of the most effective paths into an organisation, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”

Additional findings listed in the report included operational challenges and skills shortages. More than half (53%) of higher education institutions said they lacked the skills or expertise to detect and stop attacks in time, compared with 35% across all sectors. Lower education institutions most commonly cited human error (52%), lack of protection (47%), unknown security gaps (42%) and limited capacity (41%) as contributing factors.

Sophos also reported data encryption rates increased in lower education, with the percentage of lower education organisations reporting encrypted data rising from 29% in 2025 to 61% in 2026. Across the education sector, it said 58% of ransomware attacks resulted in encrypted data.

According to the report, data restoration relied heavily on backups, with 77% of lower education institutions and 69% of higher education institutions restoring encrypted data using backups, compared with a 66% cross-sector average.

The median ransom demand for education institutions was reported as $775,200, above the cross-sector median of $698,000. Sophos said median ransom demands for education fell for a second year, while payments increased by $15,000 from the 2025 report to 2026.

The report also highlighted workforce impacts following ransomware incidents. It said 53% of higher education teams reported increased pressure from senior leaders, versus 40% across all sectors, and 39% of education organisations reported staff absences due to stress or mental health issues after an attack, compared with 29% across all sectors. Sophos also reported leadership turnover following incidents, with 29% of higher education and 27% of lower education teams seeing their leadership replaced after an attack, compared with a cross-sector average of 21%.

Sophos said the findings were based on an independent survey of 226 IT and cybersecurity leaders in the education sector across 17 countries whose organisations were impacted by ransomware in the past year. It said the research was conducted between January and March 2026, and that it defines lower education as typically students up to age 18 and higher education as typically students over 18.

You can read the full report here.

Share.