Skip to content

Security1 publisher3 min readPublished

Education's attack curve has a start date: 4,696 weekly hits per organisation in 2026

Check Point's telemetry puts the education sector at more than double the cross-industry average, with July the worst month. That makes back-to-school a rota problem, not an awareness campaign.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Education's attack curve has a start date: 4,696 weekly hits per organisation in 2026
Generated illustration

What happened

  • Between January and July 2026, educational organisations (colleges and universities, research institutes and K-12 school systems) faced an average of 4,696 weekly cyberattacks per organisation, an 8% increase compared with the same period in 2025.
  • The global cross-industry average was 2,150 weekly attacks per organisation.
  • Education ranked highest among all 23 tracked industries, with attack volumes approximately 70% higher than the government sector, the second-most targeted industry.
  • In July 2026 alone, educational organisations recorded an average of 4,848 weekly attacks, a 14% increase year over year.
  • APAC recorded the highest attack volume, averaging 7,452 weekly attacks per organisation between January and July 2026.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Check Point Research reports that educational organisations absorbed an average of 4,696 cyberattacks per organisation per week between January and July 2026, an 8% rise on the same period in 2025 and 2.18 times the 2,150-attack global cross-industry average [1][2][1][14]. The useful detail is not that education tops the table again, it is that the peak lands on a date every registrar and district IT lead already has in the calendar: July alone averaged 4,848 weekly attacks, up 14% year over year and about 3% above the seven-month mean [4][3].

Education ranked first among the 23 industries Check Point tracks, roughly 70% higher than government in second place [3], which back-figures to somewhere near 2,760 weekly attacks per government organisation [2]. The load is not spread evenly. APAC recorded the heaviest volume at 7,452 weekly attacks per organisation, around 59% above the sector's global figure [5][6], while Europe grew fastest in percentage terms alongside Latin America: up 18% to 4,759 and up 42% to 4,299 respectively [6].

The supporting infrastructure is being built in advance, and it is measurable. Check Point counted 18,954 newly registered education-themed domains in July 2026, 5% more than June and 3% more than a year earlier [7]. The share flagged as malicious by Check Point ThreatCloud moved from one in every 305 registrations in June to one in every 226 in July [8][14] - from about 0.33% to about 0.44%, a 35% increase in the hit rate [4] - which works out to roughly 84 malicious education domains registered in July alone [5]. Researchers also found bulk pre-registration: ten student loan domains following a studentloansYYYY.com pattern covering 2026 through 2035, and a network of 48 bootcamp-student domains [10]. Names such as education-gov[.]com, students-portal[.]com and checkmyschool[.]org were built to borrow trust from education and government bodies [9].

The payloads point at one place. A campaign using studentdiscount[.]online impersonated a Target student rewards promotion with a fake $750 reward before pushing victims to fraudulent offers and gambling content [11]. Malicious PDFs named globeschool.pdf and beths-grammar-school.pdf routed users through multiple compromised websites to counterfeit Microsoft 365 and OneDrive login pages built to harvest credentials [12]. Researchers also found a malicious URL hosted on the compromised website of Bangladesh's Cambrian School, flagged by multiple threat intelligence sources for information-stealer and malware activity [13]. That is a credential-theft problem aimed squarely at tenant logins, arriving in the fortnight when help desks are resetting the most passwords and verifying the fewest identities.

Two caveats. These are one vendor's sensor counts, so read them as blocked activity across Check Point's estate rather than a census of breaches. And the consequence does not stop at the institution: a successful breach reaches students, parents, research partners, government agencies and connected third-party providers [15].

What to watch: whether September and October volumes exceed July's 4,848, which would mean the surge is not just pre-term staging [4]; whether the malicious ratio among new education domains keeps deteriorating past one in 226 [8]; and what happens to the studentloans domains registered for 2027 through 2035, which are dormant assets today and cheap phishing infrastructure later [10]. If the number is this predictable, the staffing plan for the first three weeks of term is the control that matters, not the awareness email.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories