Education sector faces higher email-driven ransomware and account takeover risks
https://etimg.etb2bimg.com/thumb/msid-134400731,imgsize-1052440,width-1200,height=627,overlay-etciso,resizemode-75/cybercrime-fraud/education-sector-faces-higher-email-driven-ransomware-and-account-takeover-risks.jpg
A new international survey has highlighted email security threats targeting the education sector over the last 12 months, with institutions reporting higher rates of email-driven ransomware and account takeover incidents than the global average.
Research based on a sample of 536 educational institutions detected 58.8 million phishing emails targeting the sector over a three-month period. That translates into around 1,200 phishing emails hitting each institution every day.
As attackers increasingly use AI to refine phishing tactics, identifying and blocking every malicious email is becoming more difficult for security teams.
The survey covered 2,000 IT and security leaders in the U.S., Europe and Asia Pacific, including 113 working in the education sector. More than three quarters (77%) of respondents from education said their institution had experienced an email security incident in the last 12 months.
While 34% of respondents reported successfully detecting and blocking phishing attacks, education organizations were four times more likely than the global average to say they could not determine whether they had experienced an email security incident. This uncertainty suggests some attacks may have gone undetected altogether.
Education organizations reported comparatively higher levels of severe and sophisticated email-borne attacks. According to the results, education has the joint-highest rate of ransomware incidents that started through email, at 38% compared with a global figure of 28%, and the highest rate of account-takeover incidents, at 27% compared with a global figure of 20%.
The data suggests that when attacks bypass initial defences, education institutions can struggle to investigate and contain them quickly enough to prevent further escalation.
Education trails the overall global number at every “within one day” stage of email incident handling, with the biggest gaps for investigation and recovery. Some 65% of education respondents said they could detect suspicious email activity within one day, compared with 69% overall. For investigating suspicious email activity, the figures were 58% and 66%, respectively.
Some 62% of education respondents said they could contain or respond to an email security incident within one day, compared with 68% overall. For securing accounts and restoring operations within one day, the figures were 56% for education and 64% overall.
Just under a fifth (18%) of the educational institutions surveyed take up to a week to restore normal operations, double the 9% average and the highest result across all industries.
Education respondents were more likely than average to cite user behavior and human error as contributors to incidents. Just over half (53%) pointed to user behavior and human error as a leading contributor to incidents, compared with 48% overall.
At the same time, many organizations also identified challenges within their security operations. More than a third (36%) reported a lack of expertise in incident response and decision-making under pressure, while 33% said responding quickly during live incidents was difficult.
If security teams lack the capacity or expertise to investigate, respond to and recover from incidents quickly, attackers gain valuable time to deepen their access and increase the potential impact of an attack.
When asked what would most improve security effectiveness, 41% of respondents said they would welcome AI-assisted detection and investigation tools they can trust, versus 32% overall, the highest of any industry.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












