Rising Cybersecurity Threats in Education
As students and educators prepare to return to classrooms and campuses, a concerning trend has emerged: an alarming increase in cyberattacks targeting educational institutions. According to the latest findings by Check Point Research (CPR), a prominent cybersecurity solutions provider and global leader, the education and research sectors are facing a significant rise in cyber risks as a new academic year looms.
From January to July 2026, educational organizations—including universities, colleges, and schools—suffered an average of 4,696 cyberattacks per week per organization. This statistic marks an 8% increase compared to the previous year and is more than double the global average of 2,150 cyberattacks across all sectors. Notably, the education sector experienced the highest number of attacks among the 23 industries investigated, surpassing the second-most targeted sector—government and military—by approximately 70%.
The escalation is especially pronounced as July 2026 alone recorded an average of 4,848 attacks on educational institutions, representing a staggering 14% increase year-on-year.
Regional Breakdown of Cyberattacks
Geographically, the Asia-Pacific region (APAC) witnessed the highest frequency of attacks, averaging 7,452 incidents per organization weekly from January to July 2026. Meanwhile, Europe and Latin America saw swift increases in attack rates, with averages of 4,759 (18% increase) and 4,299 (42% increase), respectively.
These figures underline a growing challenge for schools, universities, and research institutions that increasingly rely on cloud platforms, digital learning environments, and online collaboration tools. Successful breaches could affect not only the institutions themselves but also students, parents, research partners, government agencies, and third-party service providers within the academic ecosystem.
Preparations by Threat Actors
To gain insight into how cybercriminals are gearing up for the new academic year, CPR monitored new domain registrations containing educational terms such as “school,” “university,” and “student.” In July 2026, they identified 18,954 newly registered educational-related domains, marking a 5% increase from the previous month and a 3% rise year-over-year.
More concerning is the rise in malicious activities associated with these registered domains. According to Check Point ThreatCloud AI, one out of every 305 newly registered educational domains in June 2026 was deemed malicious, with that figure deteriorating to one in 226 by July. Domains like “education-gov[.]com,” “students-portal[.]com,” and “checkmyschool[.]org” have been highlighted as examples designed to mimic legitimate sites, thus leveraging the trust associated with educational institutions and government bodies to propagate fraudulent activities.
Additionally, a network of 10 domains corresponding to student loans from 2026 to 2035 was identified, along with 48 domains under the “bootcamp-student” category, suggestive of large-scale automated registration tactics targeting students and learners.
Phishing Campaigns Targeting Students and Faculty
Cyber actors are taking advantage of the uptick in online activities by students, parents, and educational institutions during the academic year. With millions of educational domains being registered monthly, attackers are crafting phishing sites and email campaigns disguised as student discounts, perks, and enrollment processes to steal personal and financial data.
One such campaign capitalized on the U.S. retail giant Target’s student discount initiative, presenting a false offer valued at $750 while redirecting victims to predatory content. Furthermore, malicious PDFs disguised as school communications prompted users to input credentials on fraudulent Microsoft 365 and OneDrive login pages after redirecting them through compromised websites.
A particular URL, hosted on a compromised site of Cambodia’s Cambrian School, was labeled as a distribution point for information-stealing tools and malware. Initially, this page displayed a fraudulent security CAPTCHA resembling Spotify, a known tactic utilized to mask malware distributions while evading security checks. However, subsequent visits were met with different error or access denied messages, indicating possible cloaking techniques or deletion of malicious content.
Defense Strategies for Educational Institutions
With the new academic term coinciding with increased digital activities—ranging from the admission of new students, sharing of documents, financial transactions, and heightened email communications—this season presents a prime opportunity for cybercriminals. Thus, instituting cybersecurity as a core component of preparations for the academic year is crucial. Recent studies have shown that attackers are targeting not only schools and universities but the entire associated ecosystem, making heightened vigilance and proactive defensive measures more critical than ever.
Educational institutions are advised to implement several strategies to mitigate the cyber risks associated with the new academic year:
1. Educate faculty and students to recognize phishing emails, fake promotions, and suspicious login pages.
2. Scrutinize web addresses before entering credentials or personal information.
3. Enable multi-factor authentication (MFA) for Microsoft 365, email, and internal systems.
4. Regularly update learning platforms, administrative systems, and devices to apply necessary security patches.
5. Monitor newly registered domains and look out for educational impersonations.
6. Review access privileges to protect sensitive data related to students, research, and administrative functions.
This article synthesizes findings from a blog post published by Check Point on August 19, 2026, highlighting urgent cybersecurity issues facing the education sector as the new academic year unfolds.