Back to school, back to cyberattacks

Back to school, back to cyberattacks

Mick Leach, Field CISO at Abnormal AI, warns that as students return for a new academic year, cyber threats across schools, colleges and universities are escalating — making cybersecurity as essential as the subjects on the curriculum.

We don’t need education (apart from when it comes to cybersecurity)

Over the past few weeks, students have made their way back to schools, colleges and universities. For many, the focus has been on the usual back-to-term logistics of checking bus schedules, finding classrooms and settling into new routines.

But this year, there’s another lesson outside the usual timetable that both students and staff need to take seriously; the growing threat of cyberattacks.

Educational institutions are prime targets for opportunistic cybercriminals. Their vast networks hold enormous amounts of sensitive data covering students, staff, alumni and partner organisations.

This term must be about more than textbooks and timetables. A new subject needs to be added to the curriculum, that of cyber awareness. Institutions must manage their attack surface, while students and staff alike must recognise that digital vigilance is essential.

Why expanding digital education means a broader attack surface

Schools, colleges and universities face a complex security challenge due to their broad and ever-shifting attack surface. Educational institutions connect thousands of students, faculty, staff, alumni and external partners with each being a potential entry point for attackers.

The data schools hold adds to this challenge. Student records, financial aid details, payroll information, health data and proprietary research are gold for a cybercriminal. A single breach can expose both personal identities and intellectual property, causing significant reputational and regulatory damage – beyond the raw financial losses.

Recent incidents highlight this problem. Earlier this year, Western Sydney University confirmed a major data breach exposing sensitive student and staff information. Similarly, data belonging to thousands of individuals across 30 Oxfordshire schools was stolen and leaked. It’s clear that the size of the institution doesn’t matter.                                            

As stated in the Cyber Security Breaches Survey:

“Prevalence of cyber security breaches or attacks in the last 12 months was high among secondary schools (60%), further education colleges (85%) and higher education institutions (91%). They were all more likely to experience a breach or attack than businesses overall (43%).”

In line with all this, email is the point of highest vulnerability, used as the central channel for collaboration and communication. Students and staff receive and send such a high volume of messages that it becomes fertile ground for phishing, impersonation and business email compromise (BEC).

A perfect storm of complexity

These attacks are cleverly timed to predictable moments like the beginning of term, when users are overwhelmed and more likely to trust a well-crafted impersonation.

Whereas smaller schools often lack dedicated cybersecurity staff, larger universities struggle to manage the scale of having to monitor thousands of users across multiple campuses. Simultaneously, adversaries are becoming more sophisticated through AI-driven phishing and domain spoofing to slip past traditional defences.

In short, every user, system and external connection adds to the attack surface. For schools, this complexity creates significant vulnerabilities. The vast diversity of users also makes it nearly impossible to enforce uniform security standards. For attackers, this provides a wealth of opportunity that can only be countered with modern defences and continuous vigilance.

In the past year alone, over 40 compromised educational organisations were impacted across multiple countries in a phishing campaign that harvested both user credentials and the one-time authentication codes used in multi-factor authentication (MFA), covering both steps of a secure login. Attacks were customised to each institution, targeting anything from payroll updates to staff appreciation notices.

In many cases, they were sent from compromised university accounts, making them appear perfectly legitimate to the next victim. This constant connectivity and unfamiliar accounts across education networks, combined with trust in institutional branding, makes it easy for impersonators to slip through the cracks.

The threat beneath the surface

The danger doesn’t end with a single phishing email. Once inside, attackers move laterally and create hidden rules within mailboxes to launch further phishing attacks and siphon sensitive data. Some campaigns have even leveraged automated scripts to forward salary-related communications to attacker-controlled inboxes for large-scale fraud without triggering alerts.

Dormant student accounts are another overlooked weakness. Student turnover leaves thousands of inactive logins still connected to valuable systems or containing personal data. Without proper deactivation, these accounts become silent backdoors for future breaches.

Remote and hybrid learning models have compounded the issue further. With more students and staff logging in from personal devices and home networks, the boundary of the institution’s security perimeter has dissolved entirely. The result is a digital landscape too vast and dynamic for traditional defences to manage effectively.

Why traditional defences are failing

Although organisations rightly invest in antivirus software, firewalls and MFA, attackers are using more subtle tactics to bypass them. Traditional tools are too rigid and only look for indicators such as malicious URLs, suspicious attachments or signature-based detection. Modern attacks driven by AI, however, don’t look malicious at first glance.

The latest phishing campaigns targeting universities use legitimate services like Google Docs and compromised WordPress sites to host fake login pages. As the visible domains appear trusted, these links easily evade filters. Attackers now use phishing kits capable of intercepting one-time passcodes in real time to gain immediate access before the codes expire.

With the increase of advanced attacks, institutions must evolve their strategies to detect the behavioural patterns that reveal when something isn’t quite right.

A behavioural approach to defence

A behavioural approach focuses on understanding and identifying abnormal user behaviour rather than chasing specific threat signatures.

Behavioural systems learn what ‘normal’ looks like for each individual and department, from typical login locations to communication patterns and device usage. When an account suddenly behaves differently, such as an individual logging in from another country, AI-driven systems can flag or automatically remediate that activity in real time.

This approach not only detects compromised accounts faster but also reduces the need for constant manual intervention by overstretched IT teams. Behavioural defence offers proactive protection where traditional methods react too late.

Building a culture of digital vigilance

The education sector needs to realise that technology alone can’t solve the problem. People are the most common entry point for attackers, so awareness and education must be part of any cybersecurity strategy.

That means learning to recognise subtle impersonation tactics. For students, it means understanding that their university credentials are not just keys to campus Wi-Fi, but potential gateways to the entire institutional network.

Targeted awareness programmes, regular phishing simulations and clear reporting processes are vital. As attackers grow more sophisticated, so too must the users they target.

Protecting an institution’s digital identity isn’t just an IT responsibility; it’s a collective one. Every staff member, student and partner plays a role in defending the integrity of the academic community.

As we begin a new academic year, one lesson stands above the rest. Cybersecurity must be a core focus where vigilance and behaviour-aware defences are deployed to stay one step ahead of attackers.

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive