Identity-Based Attacks Are Responsible for 85% of Ransomware in Education, Sophos Report Finds
Malicious email is the leading attack method, and recovery costs now average $2.26 million
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
OXFORD, U.K., Aug. 27, 2026 (GLOBE NEWSWIRE) — Sophos, a global cybersecurity leader, today released its annual State of Ransomware in Education 2026 report, which found that identity-based attack techniques were used in 85% of ransomware attacks against education institutions. Those techniques include malicious email, phishing, compromised credentials and brute force attacks. The 85% rate exceeded the cross-sector average of 79%, underscoring the role identity compromise continues to play in ransomware incidents targeting lower and higher education institutions.
Malicious email was the leading technical root cause of ransomware attacks in both lower education (31%) and higher education (29%). The report also found that 77% of higher education organizations and 71% of lower education organizations said their ransomware incident was also their most significant identity attack.
Education institutions also recover more slowly from attacks. Lower and higher education institutions are roughly twice as likely as the cross-sector average to need one to three months to fully recover. Lower education fared worst of all: 31% took a month or more to get back on their feet, the highest share of any sector.
“Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, chief information security officer, Sophos. “Today’s attackers don’t need a crowbar when they can steal the keys. Identity compromise has become one of the most effective paths into an organization, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”
Additional findings from the report include:
- Education organizations reported greater operational challenges than the cross-sector average. More than half (53%) of higher education institutions said they lacked the skills or expertise to detect and stop attacks in time compared with 35% across all sectors, while lower education institutions most commonly cited human error (52%), lack of protection (47%), unknown security gaps (42%) and limited capacity (41%) as contributing factors.
- Data encryption rates more than doubled in lower education. The percentage of lower education organizations whose data was encrypted during a ransomware attack more than doubled year over year, rising from 29% in 2025 to 61% in 2026. Across the education sector, 58% of ransomware attacks resulted in encrypted data.
- Data restoration relied heavily on backups. Over three quarters (77%) of lower education institutions and 69% of higher education institutions restored encrypted data using backups, both above the 66% cross-sector average.
- Ransom demands remained elevated despite a multi-year decline. The median ransom demand for education institutions was $775,200, above the cross-sector median of $698,000. Education median ransom demands have gone down two years in a row, while payments increased by $15,000 from the 2025 report to 2026.
- Recovery costs increased and recovery times remained lengthy. Average ransomware recovery costs reached $2.26 million across the education sector, exceeding the cross-sector average of $1.7 million. More than a quarter (26%) of education institutions required one to three months to fully recover from an attack, nearly double the cross-sector average (14%).
- The human toll on IT and security teams intensified. Over half (53%) of higher education teams reported increased pressure from senior leaders, versus 40% across all sectors. Around 39% of education organizations reported staff absences due to stress or mental health issues following a ransomware attack, compared to 29% across all sectors. Education also reported elevated leadership turnover, with 29% of higher education and 27% of lower education teams seeing their leadership replaced after the attack, compared with a cross-sector average of 21%.
The findings are based on an independent survey of 226 IT and cybersecurity leaders in the education sector across 17 countries whose organizations were impacted by ransomware in the past year. Research was conducted between January and March 2026. For the purposes of this report, age cohorts are defined as lower education (typically students up to age 18) and higher education (typically students over 18). This is the sixth year Sophos has tracked this data.
To download the full State of Ransomware in Education 2026 report, visit https://www.sophos.com/en-us/resources/white-papers/state-of-ransomware-in-education
About Sophos
Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry’s first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer’s defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Contact: Samantha Powers, sophos@walkersands.com
