Beyond phishing — the cyber risks facing education as a new academic year begins
How delays in incident response and recovery leave institutions exposed to ransomware and account takeover
Key takeaways
- Barracuda Research threat data reveals that education institutions are hit with around 1,200 phishing emails every day.
- A new international survey shows that the education sector is among the most affected by email-driven ransomware and account takeover incidents.
- Skills shortages combined with delays in investigation and recovery give attackers more time to escalate attacks and increase damage.
The start of a new academic year brings a surge in activity for schools, colleges and universities around the world — and one of the busiest periods for the IT and security teams that support them. As students, staff and researchers reconnect with digital services, education institutions face heightened cyber risk, driven by the valuable data, limited security resources and large, diverse user communities.
A new international survey by Barracuda reveals the email threats targeting the education sector over the last 12 months and how prepared institutions are to respond and recover. The findings underscore a critical reality: Effective cybersecurity is about more than threat prevention; it is about being able to identify and neutralize incidents before they have a chance to unfold into something more damaging.
Phishing attacks targeting education are relentless
Barracuda Research detected 58.8 million phishing emails targeting a sample of 536 educational institutions over a three-month period. That translates into around 1,200 phishing emails hitting each institution every day.
As attackers increasingly use AI to refine phishing tactics, identifying and blocking every malicious email is becoming more difficult for security teams.
Visibility gaps suggest attacks are being missed
Barracuda recently surveyed 2,000 IT and security leaders in the U.S., Europe and Asia Pacific, including 113 working in the education sector. More than three-quarters (77%) of the respondents from education said their institution had experienced an email security incident in the last 12 months.
While 34% of respondents reported successfully detecting and blocking phishing attacks, education organizations were four times more likely than the global average to say they could not determine whether they had experienced an email security incident. This uncertainty suggests some attacks may have gone undetected altogether.
Email threats escalate to ransomware and account takeover
Education organizations reported comparatively higher levels of severe and sophisticated email-borne attacks. According to the results, education has the joint-highest rate of ransomware incidents that started through email, at 38% compared with a global figure of 28%, and the highest rate of account-takeover, 27% compared with a global figure of 20%.
This data suggests that when attacks bypass initial defenses, education institutions can struggle to investigate and contain them quickly enough to prevent further escalation.
Up to 44% of education institutions struggle to react within a day
Education trails the overall global number at every “within one day” stage of email incident handling, with the biggest gaps for investigation and recovery.
Security activity |
Education |
Overall |
Difference |
Detect suspicious email activity within one day |
65% |
69% |
-4 pts |
Investigate suspicious email activity within one day |
58% |
66% |
-8 pts |
Contain or respond to an email security incident within one day |
62% |
68% |
-6 pts |
Secure accounts and restore operations within one day |
56% |
64% |
-8 pts |
Just under a fifth (18%) of the educational institutions surveyed take up to a week to restore normal operations, double the 9% average and the highest result across all industries.
Skills and expertise gaps
Education respondents were more likely than average to cite user behavior and human error as contributors to incidents. Just over half (53%) point to user behavior and human error as a leading contributor to incidents, compared with 48% overall.
At the same time, many organizations also identified challenges within their security operations. More than a third (36%) reported a lack of expertise in incident response and decision-making under pressure, while 33% said responding quickly during live incidents was difficult.
If security teams lack the capacity or expertise to investigate, respond to and recover from incidents quickly, attackers gain valuable time to deepen their access and increase the potential impact of an attack.
When asked what would most improve security effectiveness, 41% of respondents say they would welcome AI-assisted detection and investigation tools they can trust, versus 32% overall — the highest of any industry.
What this means for IT security teams in education
The findings suggest that education institutions face a compounded challenge. They experience higher rates of email-driven ransomware and account takeover incidents while also taking longer to investigate, contain and recover from attacks. Skills shortages and operational pressures appear to be extending the time attackers can remain active in compromised environments, increasing the potential impact of an incident.
Integrated AI-powered security will reduce pressure on overstretched teams, improve decision-making during incidents and accelerate response times. By shortening the time between detection and recovery, institutions can reduce the likelihood that routine email threats develop into major security incidents.
Rapporto sulle minacce via email 2026
Scopri come l'IA e il phishing come servizio stanno rimodellando il panorama delle minacce via email e come rimanere protetti.
Iscriviti al blog di Barracuda.
Iscriviti per ricevere i Threat Spotlight, commenti del settore e altro ancora.
Report sulle minacce globali di Managed XDR
Risultati chiave sulle tattiche adottate dagli attaccanti per colpire le organizzazioni e sui punti deboli della sicurezza che cercano di sfruttare