Itpro Surge in Cyberattacks Targeting UK Education Sector
Article Content
- •UK education sector saw 19.3 million cyber intrusion attempts in 2026, a 67% increase.
- •Path traversal and directory manipulation attacks accounted for 10.2 million hits.
- •Ransomware incidents remain low, with only 36 reported events across the sector.
UK academic institutions are facing a significant increase in cyberattacks, with SonicWall reporting over 19.3 million medium and high-severity intrusion attempts in 2026, a 67% rise from 2025. The education sector accounted for 87% of these attacks, primarily targeting web-facing infrastructure. Path traversal and directory manipulation attacks were particularly prevalent, generating 10.2 million hits. Legacy vulnerabilities, such as the Apache Log4j2 Remote Code Execution, were notably exploited, affecting primary and secondary schools with around 660,000 hits. Despite the high number of intrusion attempts, ransomware incidents remain low, with only 36 events reported. A government report indicated that over 70% of secondary schools and nearly 90% of further education colleges experienced breaches in the past year. The National Cyber Security Centre (NCSC) continues to provide resources to help institutions bolster their defenses.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ShinyHunters and Newcastle University in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
Kiteworks Issues Urgent Shutdown Advisory Amid Zero-Day Threat Kiteworks has alerted its customers to shut down their servers due to credible threat intelligence indicating an imminent cyberattack exploiting a zero-day vulnerability. The advisory, which applies globally, recommends a six-hour shutdown window starting September 26, 2026. This precautionary measure comes as…