Education isn't just a target - it's the target. In 2024, Education/Research was the most attacked industry worldwide, averaging 3,086 attacks per organization per week - a 37% jump year over year. That outpaced government, healthcare, and manufacturing.
Why schools? They hold gold: student identities, parent contacts, health and safeguarding notes, financial aid, even research IP. Pair that with legacy systems, thin security budgets, and thousands of untrained users, and you've got a dream target list for criminals. (If you've seen a district network map, you know - it's half cables, half hope.)
What changed - and why it's spreading
This is systemic, not anecdotal. Across July 2023–December 2024, 82% of reporting K-12 organizations experienced cyber-threat impacts - about 14,000 security events and 9,300 confirmed incidents. That's the baseline now.
"One breach → many districts." The PowerSchool intrusion disclosed in Dec 2024 rolled into 2025 with criminals extorting individual districts using stolen tables - names, contact details, even medical alerts and SSNs. PowerSchool confirmed it paid a ransom yet districts were still targeted months later.
Even early-years data is in play. The Kido nursery hack (London) exposed data for 8,000+ children; attackers published names, photos, and home addresses and contacted parents directly. That's preschool, not college.
Leaky governance tools. A 2025 BoardDocs glitch left confidential board files publicly accessible for months - proof that "back-office" vendors can quietly expose sensitive student and legal records.
Why criminals love school data (and why families should care)
Student data never expires. You can't rotate a date of birth. A single SIS or board-portal leak can hand over names, emails, special-ed flags, and even transport details - enough to phish families, impersonate staff, or map a child's routine. Mix in public rosters or geotagged posts and you've drawn a route to a student - no "elite hacking" required.
What to do (minimum viable security for schools)
Pick a framework you'll actually finish. In the UK, start with NCSC Cyber Essentials (five controls, school-focused guidance). If you need a step up without ISO overhead, IASME Cyber Assurance is pragmatic.
Close the three biggest holes this month:
- Identity: Turn on MFA for all staff systems (email, SIS, VPN/RDP).
- Backups: 3-2-1 with one offline/immutable copy; test restores quarterly.
- Email: Domain-wide anti-phish and targeted training for office/admin staff first (they touch HR/finance/SIS).
Kill obvious data leaks. Lock down what you publish via board portals (stop the PDF sprawl). Don't post rosters, homerooms, or transport details on public pages - ever.
Contract like you mean it. Require 72-hour breach notice, MFA/logging, annual pen-test attestation, and no resale/sharing of student data.
Use the free help. UK schools: NCSC training and toolkits. US schools: join MS-ISAC for alerts, guidance, and no-/low-cost protections.
This isn't alarmism; it's the new normal. We have global telemetry showing education at the top of the target chart, nationwide data showing most schools already impacted, and named incidents - from a national SIS breach feeding district-by-district extortion, to a nursery hack where criminals called parents. The only question is whether your defenses are ready before the inbox lights up.
