Skip to content

Identity-based attacks involved in 85% of education ransomware incidents

Intelligentciso September 1, 2026

Sophos research has found identity-based techniques were used in 85% of ransomware attacks against education institutions, while average recovery costs reached US$2.26 million.

Identity-based attack techniques were used in 85% of ransomware attacks against education institutions over the past year, according to new research from Sophos.

The State of Ransomware in Education 2026 report found that techniques including malicious email, phishing, compromised credentials and brute force attacks played a role in the majority of ransomware incidents. The figure compares with a cross-sector average of 79%.

Malicious email was the leading technical root cause, accounting for 31% of ransomware attacks in lower education and 29% in higher education. Some 77% of higher education organisations and 71% of lower education organisations also said their ransomware incident was their most significant identity attack.

Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, Chief Information Security Officer, Sophos. “Today’s attackers don’t need a crowbar when they can steal the keys. Identity compromise has become one of the most effective paths into an organisation, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”

The research also identified challenges around institutions’ ability to detect and respond to attacks. More than half (53%) of higher education respondents said a lack of skills or expertise prevented them from detecting and stopping attacks in time, compared with 35% across all sectors.

In lower education, 52% cited human error as a contributing factor, while 47% identified insufficient protection, 42% unknown security gaps and 41% limited capacity.

Data encryption rates in lower education increased from 29% in 2025 to 61% in 2026. Across education as a whole, 58% of ransomware attacks resulted in data being encrypted.

Backups remained an important part of recovery, with 77% of lower education institutions and 69% of higher education institutions using backups to restore encrypted data. The cross-sector average was 66%.

However, the financial impact of ransomware remained significant. Average recovery costs across education reached US$2.26 million, compared with US$1.7 million across all sectors. The median ransom demand in education was US$775,200, compared with a cross-sector median of US$698,000.

Recovery also took longer in education. Some 26% of affected institutions required between one and three months to recover fully, compared with 14% across all sectors. In lower education, 31% took at least a month to recover.

The report also examined the impact of ransomware incidents on IT and cybersecurity employees. Some 53% of higher education teams reported increased pressure from senior leaders following an attack, while 39% of education organisations experienced staff absences associated with stress or mental health issues.

The findings are based on an independent survey of 226 IT and cybersecurity leaders at education institutions across 17 countries that had experienced ransomware during the year. The research was conducted between January and March 2026.

A Intelligent Global Media Brand