Sophos, a global cybersecurity leader, recently released its annual State of Ransomware in Education 2026 Sophos State of Ransomware in Education report, which found that identity-based attack techniques were used in 85% of ransomware attacks against education institutions. Those techniques include malicious email, phishing, compromised credentials and brute force attacks. The 85% rate exceeded the cross-sector average of 79%, underscoring the role identity compromise continues to play in ransomware incidents targeting lower and higher education institutions.
Malicious email was the leading technical root cause of ransomware attacks in both lower education (31%) and higher education (29%). The report also found that 77% of higher education organizations and 71% of lower education organizations said their ransomware incident was also their most significant identity attack.
Recovery costs increased and recovery times remained lengthy. Average recovery costs reached $2.26 million, compared with $1.7 million across sectors. 26% of education institutions took one to three months to fully recover.
The human toll on IT and security teams intensified. 53% of higher education teams reported increased leadership pressure, while 39% reported staff absences due to stress or mental health issues. Leadership replacement was reported by 29% of higher and 27% of lower education teams.
The findings are based on an independent survey of 226 IT and cybersecurity leaders across 17 countries, conducted between January and March 2026. This is the sixth year Sophos has tracked ransomware trends in education.