Education hit hardest by cyber attacks, SonicWall says
Thu, 3rd Sep 2026 (Today)
SonicWall has published a report on cyber threats facing the education sector, which it says has the highest per-device attack intensity of any industry it tracks.
Education networks recorded 81,879 intrusion prevention system hits per device in the first half of 2026, according to the report. It also identified one Voice over Internet Protocol exploitation signature as the dominant source of activity across the sector.
SIPVicious VoIP exploitation generated 90 million combined hits and accounted for 50.5% of all intrusion prevention events detected in education environments. The signature ranked first and second on the sector's attack list, indicating repeated attempts to exploit exposed telephony systems on school and university networks.
The findings reflect the way education institutions operate open networks across student devices, faculty systems, public portals, third-party learning tools, and administrative databases. That mix leaves many connected endpoints exposed to the same infrastructure, especially where bring-your-own-device use is routine.
Malware activity was also elevated. Education organisations recorded 16,242 malware hits per device, nearly 3.5 times the rate seen in retail.
Older vulnerabilities also remained visible in the data. The Hikvision IP camera command injection flaw, first disclosed in 2021, was detected on 605 devices and appeared across 28% of education networks in SonicWall's dataset.
Apache Log4j2, another long-running security issue, generated 6.7 million hits in the sector, suggesting learning management systems and administrative middleware were still running vulnerable software.
A separate cluster of activity involved MongoBleed, which produced 2.5 million hits against research and learning management system back ends. Together with the older camera and logging software flaws, the data suggests many institutions still carry legacy systems and delayed patching cycles.
Attack pressure
The report also tracked ransomware detections. It found that 44 education organisations identified active ransomware campaigns in the first half of 2026, with 75.7% of related hits coming from what SonicWall described as concentrated, targeted intrusions against student records and research data.
Ryuk was among the ransomware families cited in the data. Those attacks appeared alongside less targeted threats, though the volume was lower than for intrusion and malware activity overall.
Michael Crean, Senior Vice President of Managed Services at SonicWall, linked the figures to the structure of education networks. "Education has the most exposed attack surface of any industry we track, and the data shows attackers know it," he said.
"Education endpoints endure the heaviest per-device attack pressure in our entire dataset. Unlocked network doors remain the operating reality, and threat actors are actively taking advantage."
The report argued that legacy SIP systems present a particular problem because they often sit on the same networks as sensitive applications and records. In that model, a compromised phone system can become an entry point into wider campus systems rather than remain a standalone communications issue.
Crean said spending priorities do not always match the pattern of attacks. "Half of all attacks against education are going after one thing, and it isn't the thing most districts are budgeting to defend," he said.
"Firewalls are essential perimeter security, but they can't defend what they aren't configured to inspect. Leaving legacy SIP endpoints unhardened inside the network negates the investment at the perimeter."
Legacy exposure
The persistence of years-old vulnerabilities stood out across the research. SonicWall said the continued presence of the Hikvision flaw on more than a quarter of observed education networks showed that internet-connected devices such as cameras still offer routes into administrative and research systems when they share access with broader campus infrastructure.
The findings also supported SonicWall's case for a zero-trust approach, in which access is verified continuously rather than granted once at the network edge. That model is designed to limit movement across systems after a user account or device is compromised.
Crean said education institutions need a security model that reflects the openness of their networks. "The highest per-device attack intensity of any vertical we track requires a security model built for it, not a patched-together version of what worked for a smaller, less open network," he said.
"Education doesn't need to close its doors to be secure. It needs to know who's walking through them."