Identity compromise is playing a central role in ransomware attacks against education organisations, according to new research from Sophos, which found that identity-based techniques were used in 85 per cent of attacks against the sector.
The figure, from Sophos’ State of Ransomware in Education 2026 report, is above the 79 per cent cross-sector average and includes techniques such as malicious emails, phishing, compromised credentials, and brute-force attacks.
You’re out of free articles for this month
Malicious emails were the leading root cause, accounting for 31 per cent of ransomware attacks against lower education organisations and 29 per cent in higher education.
The overlap between ransomware and identity attacks was also significant, with 71 per cent of lower education and 77 per cent of higher education organisations saying their ransomware incident was also their most significant identity attack.
“Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” Ross McKerchar, chief information security officer at Sophos, said in a statement.
“Today’s attackers don’t need a crowbar when they can steal the keys. Identity compromise has become one of the most effective paths into an organisation, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”
Recovering from attacks is particularly painful for the sector. Twenty-six per cent of education organisations said they needed between one and three months to fully recover from ransomware, almost twice the 14 per cent cross-sector average. Lower education organisations fared even worse, with 31 per cent taking at least a month to recover.
Average recovery costs reached US$2.26 million across education, compared with $1.7 million across all sectors. The median ransom demand was US$775,200, above the cross-sector median of US$698,000, despite education ransom demands declining for the second consecutive year.
Data encryption also increased sharply in lower education, rising from 29 per cent of ransomware incidents in 2025 to 61 per cent in 2026. Across education, 58 per cent of attacks resulted in encrypted data.
Backups remained the primary recovery mechanism, with 77 per cent of lower education and 69 per cent of higher education organisations using them to restore encrypted data.
Education organisations also reported serious operational challenges. More than half of higher education respondents, 53 per cent, said they lacked the skills or expertise to detect and stop attacks in time, compared with 35 per cent across all sectors. Lower education organisations most commonly identified human error, cited by 52 per cent, as a contributing factor.
The impact of incidents in the sector is also causing negative outcomes among education workers. Thirty-nine per cent of education organisations reported staff absences due to stress or mental health issues following a ransomware attack, compared with 29 per cent across sectors. Leadership turnover was also higher, with 29 per cent of higher education and 27 per cent of lower education organisations reporting leadership replacement after an attack.
The report is based on a survey of 226 IT and cyber security leaders across 17 countries whose organisations experienced ransomware during the previous year. Research was conducted between January and March 2026.
You can read the full report here.
