Identity-based attacks account for 85% of ransomware incidents in education, Sophos finds

Identity-based attack techniques were involved in 85% of ransomware attacks against education institutions, according to Sophos’ State of Ransomware in Education 2026 report. The figure was higher than the 79% cross-sector average.

The techniques covered in the report include malicious email, phishing, compromised credentials and brute-force attacks. Malicious email emerged as the leading technical root cause, accounting for 31% of ransomware attacks in lower education and 29% in higher education.

The report also found that 77% of higher education organisations and 71% of lower education organisations said their ransomware incident was also their most significant identity attack.

Recovery from ransomware was also slower in education than across other sectors. About 26% of education organisations required one to three months to fully recover, compared with 14% across sectors. Lower education institutions recorded the highest proportion of organisations taking a month or more to recover, at 31%.

Average ransomware recovery costs reached $2.26 million across the education sector, compared with $1.7 million across sectors. The median ransom demand was $775,200, above the cross-sector median of $698,000.

“Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, chief information security officer, Sophos. “Identity compromise has become one of the most effective paths into an organization, and AI is only increasing the speed, scale and sophistication of these attacks.”

The report found that 58% of ransomware attacks across education resulted in encrypted data. In lower education, the proportion more than doubled from 29% in 2025 to 61% in 2026.

Backups remained the primary means of restoring encrypted data. Some 77% of lower education institutions and 69% of higher education institutions used backups for data restoration, compared with 66% across sectors.

Education organisations also reported skills and operational challenges. More than half of higher education institutions, or 53%, said they lacked the skills or expertise needed to detect and stop attacks in time, compared with 35% across sectors. In lower education, human error was the most commonly cited contributing factor at 52%, followed by lack of protection at 47%, unknown security gaps at 42% and limited capacity at 41%.

The impact extended to IT and security teams. Around 39% of education organisations reported staff absences related to stress or mental health issues following a ransomware attack, compared with 29% across sectors. Leadership turnover was also higher, with 29% of higher education and 27% of lower education organisations reporting leadership replacement after an attack.

The findings are based on an independent survey of 226 IT and cybersecurity leaders at education organisations across 17 countries that experienced ransomware attacks in the preceding year. The research was conducted between January and March 2026.

reportsecuritySophos
Comments (0)
Add Comment