Education has become the world's most-attacked industry, with organisations facing an average of 4,696 weekly cyberattacks between January and July 2026, an 8% year-on-year rise and more than double the cross-industry average, according to Check Point Research. Europe and Latin America saw the sharpest growth in attacks (18% and 42% respectively), while researchers tracked a surge in malicious education-themed domain registrations ahead of the new school year, including phishing campaigns impersonating retailers, schools, and Microsoft 365 login pages. Institutions are urged to train staff, enable MFA, patch systems, and monitor for domain impersonation before term starts.

4m read timeFrom itsecurityguru.org
Post cover image

Questions this post answers

How many weekly cyberattacks does the average education organization face compared to other industries?

Education organizations faced an average of 4,696 weekly cyberattacks between January and July 2026, more than double the cross-industry average of 2,150. This was an 8% increase year-on-year, and education topped all 23 industries tracked, with attack volumes roughly 70% higher than government, the next most-targeted sector. Security teams tracking sector-specific threat trends can follow ongoing coverage of education cybersecurity on daily.dev.

What ratio of newly registered education-themed domains were found to be malicious in 2026?

In June 2026, one in every 305 newly registered education-related domains was flagged as malicious, worsening to one in every 226 by July. Researchers identified 18,954 new education-themed domain registrations in July alone, including deceptive sites like education-gov[.]com and students-portal[.]com mimicking legitimate institutions. Anyone monitoring domain-based phishing threats can keep tabs on emerging research via daily.dev.

What phishing tactics are attackers using against schools and students during back-to-school season?

Attackers used malicious PDF campaigns impersonating specific schools that routed victims through compromised websites to counterfeit Microsoft 365 and OneDrive login pages harvesting credentials. Other schemes impersonated a major US retailer's student rewards promotion with a fake $750 offer, and a compromised Bangladeshi school website distributed malware via a fake Spotify-branded CAPTCHA. Staff defending academic systems against seasonal phishing waves can follow related security writeups on daily.dev.

551 Impressions