Attacks on the education sector dropped by 13 percent in the first half of 2026, declining from 120 attacks in H2 2025 to 104 attacks in H1 2026. This decline wasn’t consistent across all levels of education, however.
Attacks on K-12 (primary and secondary education) decreased 26 percent from H2 2025 but attacks on higher education increased more than eight percent.
Some of the increase in attacks on higher education can be attributed to the rise in attacks from a ransomware group called The Gentlemen. The group’s attacks on education increased 275 percent from H2 2025 to H1 2026. 80 percent (12 out of 15) of its attack claims were against higher education institutions.
Of the 104 attacks we recorded in H1 2026, 36 were confirmed by the targeted entities.
Attacks on education–regardless of whether or not it’s a K-12 school or higher ed institute–remain incredibly disruptive, both in terms of system encryption and data theft.
A key example was last month’s attack on Mount Royal University in Canada. The attack, which started on June 17, is still causing system disruptions at the time of writing, over a month later. A data breach has also been confirmed. The group CMD Organization said it stole 10 TB of data.
*Please note: this report was written after our H1 2026 report, so figures may have changed slightly as more attacks have been confirmed.
Key findings for H1 2026 ransomware attacks on educational institutions
- 104 attacks in total
- 36 confirmed attacks
- 68 unconfirmed attacks
- Nearly 693,000 records are known to have been breached in the confirmed attacks
- Median ransom demand: $420,620 – up 53% from $275,000 in H2 2025
- The ransomware strains that made the most attack claims were The Gentlemen and Qilin (15 each), LockBit (9), Interlock and Nova (6 each)
- The Gentlemen claimed the most confirmed attacks (6), followed by Interlock (4) and Qilin and LockBit (3 each)
Education data breaches via ransomware in H1 2026
Nearly 693,000 people have been notified of a data breach following a ransomware attack on an education provider in H1 2026. Most of these stem from one attack on a Japanese education provider:
- CKC Network, Inc. and Gakusan Co., Ltd., Japan – 664,000 affected: The education provider was targeted in an attack by unknown hackers in May 2026.
- Alamo Heights Independent School District, US – 26,629 affected: To date, over 26,600 Texas residents have been notified of this March 2026 data breach, which was claimed by Qilin. The school district’s systems were also down for five days.
- Monmouth University, US – 1,500+ affected: Data breach notifications are still being issued for this February 2026 breach, but figures for nearly 1,500 across four US states have been confirmed. None of these states (Massachusetts, New Hampshire, Texas, and Vermont) are where the university is located (New Jersey), suggesting the breach figure could be much higher. PEAR claimed the attack and said it had stolen 16 TB of data.
- Campbell University, US – 500+ affected: The university has started notifying people of a breach from March 2026, which was claimed by INC. A placeholder of 500 has been added to the HHS US healthcare breach reporting tool while final figures are confirmed.
- Kyushu University, Japan – 43 affected: Unknown hackers targeted the Japanese university’s systems in May 2026. 43 patients from the university’s hospital are confirmed to have been impacted.
The biggest ransom demands on the education sector in H1 2026
No ransom payments were confirmed in H1 2026 but five entities confirmed they hadn’t met their hackers’ demands.
Across the confirmed attacks, the following four organizations were hit with the biggest known demands (confirmed attacks only):
- Mount Royal University, Canada – $1.9 million: Earlier this month, CMD Organization came forward to claim this June 2026 attack on MRU. It issued the Canadian university with a 30-bitcoin (USD $1.9 million) ransom, stating it had stolen 10 TB of data.
- Delano Public Schools, US – $1.2 million: In May 2026, classes were canceled for a day following a ransomware attack on the school district’s systems. In June, LockBit claimed the attack. Delano confirmed that no ransom had been paid due to LockBit being a sanctioned organization. The school district was also confident no breach had occurred as the hackers were locked out of its systems early on.
- Onze-Lieve-Vrouw Instituut, Belgium – $115,000: Hackers targeted the Belgian institute in early January 2026, issuing a €100,000 ransom demand, which the institute refused to pay. The hackers then started contacting parents, demanding €50 for every child. In the message, the hackers claimed to be “Lock-Bit” but indications suggest this isn’t connected to LockBit.
- Lehigh Carbon Community College, US – $100,000: Medusa issued LCCC with a $100,000 demand in mid-March 2026. The attack caused widespread outages at the college with classes being canceled for more than a week. A data breach has occurred but the number of people affected is unknown.
Ransomware attacks on schools, colleges & universities by country
Of the 104 attacks noted in H1 2026, 33 percent (34) hit educational institutions in the US. This was a 44 percent decline from H2 2025 when we logged 61 attacks.
The UK was targeted with the second-highest number of attacks. Here, we recorded 13 attacks, a 225 percent increase from H2 2025 (4). Brazil (8) and Thailand (5) followed where attacks increased by 33 and 150 percent, respectively.
The US saw the most confirmed attacks with 12 in total. As well as those mentioned above, Wagon Mound Public Schools and Community College of Beaver County confirmed attacks via Interlock, Denmark School District was targeted by INC, and an attack on Alcorn School District was claimed by LockBit. Spring Lake Park School District, Hanover County Public Schools, and Evanston Township High School District 202 also confirmed attacks but the hackers remain unknown.
Three attacks each were confirmed in Brazil, Poland, and Japan. Two of Brazil’s attacks were claimed by The Gentlemen (Centro Universitário Filadélfia – UniFil and Universidade Federal de Sergipe) and one was claimed by DragonForce (Fundação Getulio Vargas). In Japan, an attack on Musashino University was claimed by Qilin, while the hackers remain unknown in the two aforementioned attacks (CKC Network, Inc. and Gakusan Co., Ltd. and Kyushu University).
Interlock (Uniwersytetu Warszawskiego), The Gentlemen (Akademia Leona Koźmińskiego – Kozminski University), and Nova (Wyższa Szkoła Biznesu – National Louis University) claimed the three attacks in Poland.
Which ransomware gangs are targeting the education sector?
As The Gentlemen gained notoriety in H1 2026, the education sector wasn’t spared. Here, the gang claimed 15 attacks, which was a 275 percent increase in claims from H2 2025 (4).
Six of the attacks via The Gentlemen were confirmed. As well as the two in Brazil and one in Japan, attacks were confirmed by CHS Villach in Austria, Vysoká škola finanční a správní (University of Finance and Administration) in the Czech Republic, and Sasin School of Management in Thailand.
Qilin also claimed 15 attacks, a 38 percent decrease from H2 2025 when 24 were noted. Three of Qilin’s attacks were confirmed. Alongside the two mentioned above (Musashino University and Alamo Heights ISD), the Australian College of Business Intelligence also confirmed it had been targeted in an attack in May 2026. The colleges said student data hadn’t been impacted.
Four of Interlock’s attacks were also confirmed (across six claims in total). Three were mentioned above (Uniwersytetu Warszawskiego, Community College of Beaver County, and Wagon Mound Public Schools). Reynella East College in Australia also confirmed an attack in June 2026. Interlock’s attacks remained at a similar level when compared to H2 2025 with six in H1 2026 and seven in H2 2025.
Attacks via LockBit and Nova increased in the first half of 2026, rising by 29 and 50 percent, respectively.
Confirmed vs unconfirmed attacks
We label a ransomware attack as “confirmed” when a) the targeted organization publicly discloses an attack that involved ransomware, or b) the targeted organization publicly acknowledges a cyber attack that matches a claim made by a ransomware group. If a ransomware group claims that it successfully attacked an organization, but the organization never acknowledged an attack, then we label the attack as “unconfirmed.”
An attack might be unconfirmed because the ransomware group making the claim is lying, or because the targeted organization chose not to disclose the attack to the public. Ransomware groups post their attack claims on their respective websites, where the data is auctioned or released when organizations don’t meet their ransom demands.
Organizations in the US are required to disclose data breaches, which often result from ransomware attacks, to state officials when they meet certain thresholds. Not all countries have breach disclosure laws.
When an attack is confirmed, it is removed from our list of unconfirmed attacks. Therefore, we must allow for some changes in figures when comparing monthly figures, especially when using unconfirmed attacks. Claims from ransomware groups often come about a month after the attack, if not longer. For example, if a ransomware gang claims an attack in January 2025, it may later be confirmed as an attack in December 2024 and will, therefore, be attributed to a different month.
All data is derived from our worldwide ransomware tracker (updated daily) – here.