Education & Research — Cyber Threat Activity

Education and research is targeted for openness, and our log records more than 550 incidents against it across 58 countries, over 140 in the trailing 180 days. 51 groups have been attributed at least one claim, led by Qilin (67), INC Ransom (48), SafePay (38), LockBit (29) and RansomHub (28). Universities are structurally difficult to defend: they run large transient user populations, decentralised IT owned by individual faculties, and networks built to share rather than to restrict, all while holding student records, health data, payment systems and unpublished research on the same infrastructure. Schools and districts sit at the other end of the same problem with a fraction of the staff. The FBI has warned specifically about ransomware crews concentrating on education institutions, and the sector's incident rate is visibly term-driven. Alongside the extortion, education carries a distinct espionage profile that no other commercial sector shares. Iranian-linked operators have run sustained credential phishing against universities using spoofed library and login pages, at one point covering 76 universities across 14 countries from a single infrastructure set, with the objective of reaching subscription research and intellectual property rather than student data. That is theft of the sector's actual product. Our graph records 98 groups in total once profile-level research associations are included. Recorded geography is heavily United States at 363 claims, then the United Kingdom, Canada, France, Brazil and India. Treat the totals as leak-site claims rather than confirmed breaches. The instructive point for the sector is that its two threats want opposite things: one wants the network stopped, the other wants it working and unobserved for as long as possible.

All sectors

Recent incidents

Threat actors targeting Education & Research

Where these victims are

Malware used against Education & Research

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions