New research has found that education has become the single most targeted sector for cyberattacks anywhere in the world, ahead of government, healthcare and finance, as criminals ramp up activity in the weeks before the new school and university term begins.
The findings come from Check Point Research, which found that between January and July 2026, education organisations faced an average of nearly 4,700 cyberattacks a week each, more than double the average across all other industries, and around 70% higher than government, the next most-targeted sector.
By July, as the new academic year approached, that figure had climbed even further, up 14% on the same month last year.
Europe Seeing Some Of The Fastest Growth
While Asia-Pacific saw the highest overall volume of attacks, Europe recorded one of the steepest year-on-year increases, up 18%, with Latin America close behind at 42%.
Researchers believe the rise is being driven by schools, colleges and universities relying more heavily than ever on cloud tools, online learning platforms and digital collaboration systems, all of which give criminals more ways in. Because education touches so many people, a single successful attack can affect not just the institution itself, but students, parents, staff and outside partners connected to it.
Thousands Of Fake ‘School’ Websites Created Every Month
Researchers also tracked how criminals prepare for the school year by registering new websites using words like “school”, “college”, “university” and “student” in the domain name.
In July 2026 alone, almost 19,000 new education-themed websites were registered and by that point, roughly 1 in every 226 of them was found to be malicious, a noticeably worse ratio than just a month earlier.
Some of these sites were designed to closely copy real school, university or government websites, aiming to catch out staff or students who don’t look closely at the web address. Researchers also spotted signs of organised, large-scale operations, including one group of sites all built around fake student loan offers, and another network of nearly 50 sites impersonating bootcamp and training courses.
More from Cybersecurity
- UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally
- Anthropic Discloses Fourth Unauthorised Claude Access Incident – Is The Security Industry Prepared For AI Breaches?
- Bot Traffic Vs Human Traffic: What Decodo Found
- SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now The Leading Path Into The Enterprise
- Your Smart TV Might Be Eavesdropping: Behind The Security Flaws Compromising Your Living Room
- Reflectiz Launches Agentic Pentesting For Websites: Up To 10x Coverage Vs Conventional Pentests
- Hackers Are Hijacking Brazilian Government Websites To Run a Global Gambling Scam
- Hackers Shut Down A UK Power Plant – Are Cyberattacks Moving From Data Theft to Physical Interruption?
Fake Giveaways And Scam Login Pages
The research also uncovered specific scams already in circulation. One used a fake website to impersonate a major US retailer’s student discount scheme, luring victims in with the promise of a $750 reward before redirecting them to gambling sites and other fraudulent offers.
In another case, scammers impersonated a specific school using a fake document, sending victims through a chain of compromised websites before landing on a convincing fake Microsoft login page designed purely to steal usernames and passwords.
A separate malicious link, found on a school website that had itself been hacked, had previously been used to trick visitors with a fake Spotify pop-up, a common trick used to sneak past security software and infect devices.
Why Criminals Target Back-To-School Season
The start of the academic year is a particularly attractive window for scammers: new students are signing up for accounts, families are making payments and schools are sending out far more emails and paperwork than usual, all of which makes it easier for a fake message or fake website to blend in.
With a few weeks still to go before UK schools, colleges and universities return, researchers are urging institutions, staff, students and parents to get ahead of the risk by:
- Being wary of emails or offers that seem too good to be true, especially unexpected rewards or discounts
- Double-checking website addresses before entering a password or personal details
- Turning on two-factor (or multi-factor) authentication wherever it’s offered
- Keeping laptops, phones and school software up to date
- Reporting suspicious emails or websites to IT or school staff rather than clicking through
The message from researchers is simple: the back-to-school rush isn’t just a busy time for schools and families but for scammers too, and the preparation needs to start before term does, not after.
