
Legacy Systems in Industrial Plants: The Challenge of Protecting Protocols That Were Never Designed to Be Secure
10 de September de 2026Every week, an educational institution receives an average of 4,696 cyberattacks, more than twice the global average across all sectors (2,150 attacks per week), according to Check Point Research for the January–July 2026 period. In July, that figure reached 4,848 attacks per week, 14% more than a year earlier (Check Point Software, press release). Based on these figures, education ranks first among the 23 sectors analysed by Check Point, 70% above government, the second most targeted sector.
This is not an isolated anomaly: it is a direct consequence of how universities, business schools and educational institutions have transformed the way they operate in recent years.

About the figures. These are not figures from a single week or a one-off report: they reflect a sustained trend. According to the same Check Point Research index, education was already the world’s most targeted sector during the first seven months of 2024, with an average of 3,086 attacks per week per institution (+37% year on year). This figure rose to 3,828 weekly attacks in the third quarter of that year, before ending 2024 at 3,574 attacks per week, 75% more than in 2023. By October 2025, the figure had already reached 4,470 weekly attacks, and in 2026 it stands at the 4,696–4,848 attacks cited above. Three consecutive years, using the same methodology and the same source, produce the same result: education ranks first, well ahead of the second most targeted sector, government.
Why Education Has Become a Priority Target
A university or educational institution is not an organisation with a clearly defined perimeter. From a cybersecurity perspective, it is one of the most open and heterogeneous structures there is: students, teaching staff, administrative personnel, researchers, alumni, technology providers, external collaborators and visitors all connect to the same networks, platforms and cloud services, often from personal devices that the institution neither manages nor directly controls.
That combination —a large and diverse community, a culture of openness and collaboration, and heavy reliance on academic platforms, institutional email, research repositories and hybrid working environments— is exactly what cybercrime groups are looking for, as described by the Cybersecurity Service of Comillas Pontifical University: service continuity that cannot be interrupted without cost, and high-value information concentrated within a single environment.
There is also a structural factor: the widespread use of BYOD (Bring Your Own Device). Students and teaching staff access sensitive systems and data from personal laptops, smartphones and tablets, often without encryption or up-to-date software. ESET notes that using personal devices on educational networks can provide a direct route to sensitive data and systems when it is not accompanied by an appropriate security policy. Each of these devices expands the attack surface without the IT team having genuine visibility or control over it.
There is also a calendar-related factor: peaks in malicious activity consistently coincide with the start of the academic year. Check Point identified 18,954 new education-related domains registered in July 2026 alone; approximately 1 in 226 proved to be malicious, many of them designed to impersonate official educational institution portals. By region, attacks against European educational institutions increased by 18% during the first seven months of 2026, reaching an average of 4,759 attacks per week, while Latin America recorded the highest percentage increase, at 42% (Andalucía Buenas Noticias, via Check Point Software).
How They Do It
The attack pattern targeting educational institutions follows, with nuances specific to the sector, the chain that dominates the ransomware landscape in Spain in 2026, as described by Secra Solutions and ConnectaSec:
1. Initial access. The most common route is no longer forcing a door open, but entering with a stolen key: compromised valid credentials obtained through infostealers (Lumma, RedLine, Stealc), targeted phishing or purchased on access markets. In educational environments, that first email is often disguised as an academic collaboration message or enrolment notice, as described by the Comillas cybersecurity service. VPNs and remote desktops without multi-factor authentication remain, according to ConnectaSec, the most widely exploited entry points in Spain in 2026.
2. Reconnaissance and lateral movement. Once inside, the attacker moves through the network for days or weeks, identifying which systems and data are most valuable before taking action.
3. Data exfiltration. Before encrypting anything, ransomware groups extract sensitive information, sometimes using legitimate channels to evade data loss prevention tools (Secra Solutions).
4. Encryption and double extortion. The dominant model in 2026 is no longer simply “encrypt and demand a ransom”: attackers threaten to publish the stolen data regardless of whether the institution pays (ConnectaSec).
Several recent cases, two of them in Spain, illustrate this attack chain in practice:
- University of Alicante, July 2026. On 3 July, the UA’s monitoring systems detected unusual activity on its servers; the university’s own Vice-Rectorate for Digital Transformation described it as the largest attempted cyberattack the institution had experienced to date, with signs consistent with ransomware. The security team contained the incident to a small number of secondary servers and proactively disabled several virtual campus services; the enrolment schedule was not affected (Escudo Digital).
- University of Barcelona, August 2026. On 31 August, the UB reported a cybersecurity incident that required it to activate its protocols, renew credentials and strengthen monitoring of its infrastructure, in collaboration with the Cybersecurity Agency of Catalonia and the Consortium of University Services of Catalonia (CSUC) (Bit Life Media).
- Sapienza University of Rome, February 2026. With more than 100,000 students, the university suffered a ransomware attack (Rorschach variant) that left its systems completely unavailable for several days, with its website inaccessible until 5 February (El Ecosistema Startup).
What They Achieve: Three Types of Impact
Economic Impact
The global average cost of a data breach reached $4.44 million in 2025, according to the IBM Cost of a Data Breach Report 2025; education falls within a range of $3.82 million to $4.43 million per incident, one of the highest among sectors operating with tighter budgets (Stingrai, analysis of the IBM 2025 report). Added to this is the cost of downtime: Comparitech estimates the average cost of each day a US school district remains encrypted by ransomware at $550,000. As for ransom payments, the Sophos State of Ransomware in Education 2025 puts the median payment at $800,000 in lower education and $463,000 in higher education —figures that are down from the previous year but still represent a severe blow to public-sector budgets.
Academic Impact
The disruption is not confined to a technical problem: it can bring teaching and academic activity to a standstill at the worst possible moment. On 8 May 2026, a cyberattack attributed to the ShinyHunters group targeting Instructure, the company behind the Canvas platform, disrupted services for several hours across approximately 9,000 educational institutions and 30 million users worldwide, right in the middle of final exam week. Universities including Harvard, Columbia, Princeton, Northeastern and the University of Maryland had to postpone assessments and reorganise schedules at short notice (Infobae). Weeks earlier, in September 2026, a cyberattack against Springfield Public Schools in Massachusetts forced schools to close for four days, leaving more than 23,000 students without classes, in an incident that also prevented nursing staff from accessing students’ medical records.
Impact on People
Behind every figure for “exposed records” are real students, families and teachers. The most serious case documented to date is that of PowerSchool, a school management software provider used in the US and Canada: between late 2024 and 2025, an attacker stole data belonging to more than 60 million students and 10 million teachers, including Social Security numbers and medical information, according to INCIBE-CERT. The perpetrator, a 19-year-old university student, demanded a $2.85 million ransom; although the company paid, extortion emails continued to reach schools in Canada and North Carolina, creating what the prosecutor in the case described as fear among families over their children’s privacy (Infobae). PowerSchool had to provide two years of identity protection and credit monitoring to everyone affected (BleepingComputer) —a measure that illustrates the scale of the fraud and identity theft risk faced by people who**, in many cases, are not even adults.**
Moreover, the impact rarely remains confined to the institution itself: a breach at a university can also compromise public bodies and technology providers connected to the institution, triggering the corresponding obligation to notify the Spanish Data Protection Agency (AEPD) within a maximum of 72 hours and, for essential or important entities under NIS2, INCIBE-CERT within even tighter deadlines.
The Challenge: Protecting an Environment That Cannot Be Closed Off
Unlike a company that can harden its perimeter by restricting who can connect and from where, a university depends on remaining open: to students connecting from home, teaching staff working from their own devices, researchers collaborating with other institutions, and educational technology providers. Closing off that access is not an option; security has to be built around that openness, not against it.
Conclusion
No single data point proves on its own that education is “the most targeted sector” in absolute terms. What the sources cited throughout this article do show —and what is reinforced by the incidents involving Alicante, Barcelona, Sapienza, Canvas, Springfield and PowerSchool in recent months— is that the education community operates under sustained attack pressure, with tangible and measurable economic, academic and personal consequences. The relevant question for an educational institution is not whether it will face an intrusion attempt, but when —and whether its architecture for accessing critical systems is designed so that, when that moment comes, the event remains a contained incident rather than escalating into a crisis that disrupts the academic year, compromises budgets and exposes thousands of people.
This is precisely where the approach behind Endurance, a product developed by Cosmikal, comes into play. As a Remote Shielded Workspace (RSW) solution, Endurance does not focus protection on securing every personal device that connects —a virtually impossible task in such a heterogeneous BYOD environment— but instead on isolating the critical asset itself. The connection is established through an air gap between the endpoint and the asset, so that a compromised device —a student’s laptop, a teacher’s smartphone, or a shared computer in a research facility— does not compromise either the connection or the systems being accessed. This allows students, teaching staff and researchers to work securely from any device, without relying on every individual device being properly patched or managed, while the institution’s access policies are applied consistently to anyone requesting access.





