Aug 20: As students, teachers and families return to classrooms, campuses and online learning platforms at the end of summer, cybercriminals are preparing for the new school year as well. According to Check Point Research, the education sector remains the world's most targeted industry, facing significantly more cyberattacks than any other sector.
Between January and July 2026, educational organisations such as colleges and universities, research institutes, and K-12 school systems alike, faced an average of 4,696 weekly cyberattacks per organisation, representing an 8% increase compared to the same period in 2025 and more than double the global cross-industry average of 2,150 attacks. Education also ranked highest among all 23 tracked industries, experiencing attack volumes approximately 70% higher than the government sector, the second-most targeted industry.
The pressure intensified as the school year approached. In July 2026 alone, educational organisations recorded an average of 4,848 weekly attacks, a 14% increase year-over-year.
Regions Under Growing Pressure
While educational institutions worldwide remain under pressure, APAC recorded the highest attack volume, averaging 7,452 weekly attacks per organisation between January and July 2026. Europe and Latin America experienced the fastest growth, with attacks rising 18% to 4,759 weekly attacks, and 42% to 4,299 weekly attacks, year-over-year respectively.
These figures highlight a growing challenge for schools, universities and research institutions, which increasingly rely on cloud platforms, digital learning environments and online collaboration tools. A successful breach can impact not only education providers, but also students, parents, research partners, government agencies and third-party service providers connected to the academic ecosystem.
Attackers Are Building Back-to-School Infrastructure
To understand how threat actors prepare for the academic year, Check Point Research monitored newly registered domains containing education-related terms such as "school", "university", "college" and "student". In July 2026, researchers identified 18,954 newly registered education-themed domains, an increase of 5% from June and 3% year-over-year.
More concerning is the growing level of malicious activity among those registrations, as flagged by Check Point ThreatCloud. In June 2026, one in every 305 newly registered education-related domains was malicious. By July, that ratio had increased to one in every 226 domains.
Examples included deceptive domains such as education-gov[.]com, students-portal[.]com and checkmyschool[.]org, designed to appear legitimate and exploit trust in education and government institutions.
Researchers also identified coordinated domain-registration campaigns, including 10 student loan-themed domains studentloansYYYY.com, spanning years 2026 to 2035 and a network of 48 bootcamp-student domains, indicating large-scale automated registration activity targeting students and prospective learners.
Phishing Campaigns Target Students and Educators
Threat actors are also leveraging seasonal moments like back-to-school to exploit the surge in online activity from students, parents, and educational institutions. Against the backdrop of the tens of thousands of new education-themed domains registered each month, attackers stand up fraudulent sites and email campaigns to harvest personal and financial data under the guise of student rewards, discounts, and enrollment.
One campaign used studentdiscount[.]online to impersonate major US retail chain, Target student rewards promotion, offering a fake $750 student reward before redirecting victims to fraudulent offers and gambling-related content.
Researchers also uncovered malicious PDF campaigns impersonating schools and educational institutions. The files globeschool.pdf 6d0bd9615d730b0b828f7f91c346085f and beths-grammar-school.pdf 325d5de03758e3850dfae33e509afee9 directed users through multiple compromised websites before landing on counterfeit Microsoft 365 and OneDrive login pages designed to steal credential
Researchers also identified a malicious URL hosted on the compromised website of Bangladesh's Cambrian School, cambrianschoolbd[.]com/mail/, which was flagged by multiple threat intelligence sources as an information-stealer and malware distribution site. The page previously displayed a fake Spotify-branded security verification CAPTCHA, a tactic commonly used to deliver malware or evade security analysis. Subsequent visits returned varying error and access-denied messages, suggesting cloaking techniques or that the malicious content had been removed.
The findings demonstrate how attackers increasingly exploit trusted brands, legitimate websites and familiar academic workflows to improve the effectiveness of phishing campaigns and increase the chances of credential theft.
What Education Organisations Can Do Now
The back-to-school period presents a unique opportunity for cybercriminals because of increased digital activity, new student onboarding, document sharing, financial transactions and heightened email communications.
To reduce risk, educational institutions should:
- Train staff and students to recognise phishing emails, fake reward offers and suspicious login pages.
- Verify website addresses carefully before entering credentials or personal information.
- Enable multi-factor authentication on Microsoft 365, email and academic systems.
- Regularly update and patch devices, learning platforms and administrative systems.
- Monitor newly registered domains and education-themed impersonation attempts.
- Review access permissions and secure sensitive student, research and administrative data.
As cybercriminals continue to align their campaigns with the academic calendar, cyber security must become a core part of back-to-school preparedness. The latest research shows that attackers are not only targeting schools and universities themselves, but the entire ecosystem surrounding education, making vigilance and proactive protection more important than ever.



