Ransomware Attacks on K-12 Trend Down, Higher Ed Trend Up in 2026 | #ransomware | #cybercrime


Ransomware attacks on U.S. schools fell sharply in the first half of 2026 compared the second half of 2025, according to a recent report by cybersecurity research firm Comparitech. But dozens of institutions were still targeted, with some attacks canceling classes, shutting down systems and exposing the personal information of students and staff.

Comparitech recorded 34 ransomware attacks against U.S. educational institutions in the first half of 2026, a 44 percent decline from the 61 it recorded in the last six months of 2025. Even with that decline, the U.S. accounted for 33 percent of the 104 education-sector attacks Comparitech recorded worldwide and had more attacks than any other country.

But this decrease was not consistent across education levels, the data showed: K-12 attacks worldwide declined 26 percent, while attacks on higher education institutions increased by more than 8 percent.


Trends also varied considerably by country. The United Kingdom recorded the second-highest number of attacks at 13, a 225 percent increase from four in the previous six months. Brazil recorded eight attacks, up 33 percent, while Thailand recorded five, an increase of 150 percent.

The decline comes as schools and colleges contend with a growing range of data security threats, including attacks on the technology providers that hold education data.

An attack this spring on ed-tech provider Instructure illustrated how a breach involving a widely used platform can extend across institutions. The company disclosed in May that an unauthorized party had accessed its Canvas platform, affecting millions of users across K-12 and higher education. Compromised information included user names, email addresses, course names and internal messages, according to Instructure’s website, which later added that the company reached a deal with the hackers that included recovery of the stolen data and digital verification that the information had been destroyed.

In June, the Federal Trade Commission (FTC) finalized an order requiring another ed-tech company, Illuminate Education, to improve its data security practices and limit collection and retention of student data, following a breach disclosed in 2022 that the FTC said exposed personal data belonging to 10.1 million students.

Moreover, Comparitech’s report showed that while the overall number of U.S. attacks declined, several incidents disrupted school operations or resulted in data breaches.

Alamo Heights Independent School District in Texas, for example, had its systems down for five days following a March ransomware attack. More than 26,600 Texas residents were notified of the resulting data breach, according to Comparitech’s report.

Other documented ransomware attacks that disrupted school operations included an incident in May that prompted Delano Public Schools in Minnesota to cancel classes for a day, for which LockBit, a data extortion group, later claimed responsibility and issued a $1.2 million ransom demand. The district confirmed that it did not pay and said it was confident a data breach had not occurred because the hackers were locked out of its systems early.

And at Lehigh Carbon Community College in Pennsylvania, an attack caused widespread outages and led to classes being canceled for more than a week in March.

Comparitech’s report cautioned, however, that not all of the attacks in its data set were verified by the institutions involved. Of the 104 attacks recorded worldwide, the report said 36 were confirmed and 68 remained unconfirmed — the U.S. had 12 confirmed attacks, the most of any country.

The report defined “confirmation” as an institution publicly disclosing a ransomware attack or acknowledging a cyber attack that matches a ransomware group’s claim. It defines attacks as unconfirmed when a ransomware group claims responsibility but the institution does not publicly acknowledge the incident.





Click Here For The Original Source.

——————————————————–

..........

.

.