Lossless Blog

Three out of Four Cyberattacks in the Education Sector are Associated with a Compromised on-premises User or Admin Accounts


About 69% of educational institutions experienced a security incident within the last 12 months.

A survey by Netwrix, a Texas-based IT security company, where about 1,610 IT and security professionals carried out a survey on the education sector across more than 100 countries has reported their findings.

It has put the organizations in the education sector that suffered cyberattacks within the last 12 months at 69%. Phishing and user account compromise were the most common attack paths for these organizations, while phishing and malware (such as ransomware) topped the list for other verticals. What’s more, 3 out of 4 attacks (75%) in the education sector were associated with a compromised on-premises user or admin account, compared to 48% for other sectors.

“Organizations in the education sector handle a variety of accounts – staff, third-party contractors, educators, students, alumni – that have a high turnover rate. Even if identity management is automated, it is a challenge to keep users trained in security best practices because there is a continual supply of newcomers,” says Dmitry Sotnikov, VP of Product Management at Netwrix. “In addition, students may lack experience in spotting phishing emails or fake websites asking for their credentials. To address these challenges, it is essential to mandate security training within the first few weeks and repeat it on a regular basis.”

“To enable research and collaboration, educational institutions often provide a variety of shared devices and systems exposed to the internet – creating a massive attack surface,” says Dirk Schrader, VP of Security Research at Netwrix. “To mitigate risk, it is crucial to enforce strong password policies that prevent the issue of use of weak and compromised passwords, implement multifactor authentication (MFA), and adhere to the least privilege principle. In addition, automated detection and response solutions can help IT deal with account compromise and abuse in a controlled and efficient manner.”


Leave a Reply

Your email address will not be published. Required fields are marked *