Kaspersky's Global Emergency Response Team (GERT) shares incident response statistics and case studies from Brazilian educational institutions between January 2025 and June 2026. Key findings show 40% of incidents were high-severity, primarily ransomware attacks using DragonForce and LockBit 3 (via leaked builder). Most common initial access vectors were valid accounts, exposed public-facing applications, and insiders. Three detailed cases cover a LockBit attack using PsExec for lateral movement, a DragonForce deployment via AnyDesk, and a Python keylogger used by an insider to steal credentials. Recommendations include enforcing MFA, eliminating shared accounts, isolating backups, patching legacy systems (many still run Windows 10 and Server 2016), and improving forensic visibility through artifacts like Amcache, Prefetch, and USN Journal.