ITSecurityGuru

Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School


Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year.

Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per organisation, an 8% rise on the same period in 2025 and more than double the cross-industry average of 2,150 weekly attacks. Education topped all 23 industries tracked by Check Point, recording attack volumes roughly 70% higher than government, the next most-targeted sector. In July alone, weekly attacks against education organisations climbed to 4,848, up 14% year-on-year, as the new term approached.

Regional picture: Europe among the fastest-growing hotspots

APAC recorded the highest overall volume, with organisations facing an average of 7,452 weekly attacks between January and July. But Europe and Latin America saw the sharpest year-on-year growth, up 18% (to 4,759 weekly attacks) and 42% (to 4,299 weekly attacks) respectively, a trend researchers link to the sector’s growing reliance on cloud platforms, digital learning tools and online collaboration systems that widen the potential attack surface. A successful breach, they note, can ripple out beyond the institution itself to affect students, parents, research partners, government bodies and third-party suppliers connected to the education ecosystem.

Attackers building dedicated ‘back-to-school’ infrastructure

To track how threat actors prepare for the academic calendar, Check Point Research monitored newly registered domains containing education-related terms such as “school”, “university”, “college” and “student”. In July 2026 alone, researchers identified 18,954 newly registered education-themed domains, up 5% month-on-month and 3% year-on-year.

More striking is the rise in malicious activity among those registrations. Check Point ThreatCloud data shows that in June 2026, one in every 305 newly registered education-related domains was flagged as malicious; by July, that ratio had worsened to one in every 226. Examples uncovered include deceptive domains such as education-gov[.]com, students-portal[.]com, and checkmyschool[.]org, built to mimic legitimate education and government institutions. Researchers also identified coordinated registration campaigns, including a set of ten student loan-themed domains following a studentloansYYYY.com pattern spanning 2026 to 2035, and a network of 48 bootcamp-student domains, evidence, the researchers say, of large-scale, automated registration activity aimed squarely at students and prospective learners.

Phishing campaigns target students and staff directly

Beyond domain registration, researchers documented active campaigns exploiting the seasonal surge in online activity from students, parents and institutions. One scheme used the domain studentdiscount[.]online to impersonate a major US retail chain’s student rewards promotion, dangling a fake $750 reward before redirecting victims to fraudulent offers and gambling-related content.

Researchers also uncovered malicious PDF campaigns impersonating specific schools, routing victims through multiple compromised websites before landing on counterfeit Microsoft 365 and OneDrive login pages designed to harvest credentials. A separate case involved a malicious URL hosted on a compromised school website in Bangladesh, flagged by multiple threat intelligence sources as an information-stealer and malware distribution point; the page had previously displayed a fake Spotify-branded CAPTCHA, a technique often used to deliver malware or dodge automated security analysis.

Taken together, the findings point to a consistent tactic: abusing trusted brands, compromised legitimate websites and familiar academic workflows to make phishing lures more convincing and credential theft more effective.

What institutions should do before term starts

The back-to-school period is a prime opportunity for attackers, thanks to the spike in digital activity that comes with new student onboarding, document sharing, financial transactions and higher email volumes. Researchers recommend institutions act now, ahead of the return, to:

  • Train staff and students to recognise phishing emails, fake reward offers and suspicious login pages
  • Verify website addresses carefully before entering credentials or personal information
  • Enable multi-factor authentication (MFA) on Microsoft 365, email and academic systems
  • Regularly update and patch devices, learning platforms and administrative systems
  • Monitor newly registered domains for education-themed impersonation attempts
  • Review access permissions and secure sensitive student, research and administrative data

As cybercriminals continue to align their campaigns with the academic calendar, researchers say cybersecurity needs to become a core part of back-to-school preparedness and not an afterthought once term is already underway. The data suggests attackers are targeting not just schools and universities, but the wider ecosystem of students, families, and partners that surrounds them.



Source link