{"id":23783,"date":"2024-01-24T14:10:10","date_gmt":"2024-01-24T22:10:10","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/01\/24\/news-17513\/"},"modified":"2024-01-24T14:10:10","modified_gmt":"2024-01-24T22:10:10","slug":"news-17513","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/01\/24\/news-17513\/","title":{"rendered":"2024 State of Ransomware in Education: 92% spike in K-12 attacks"},"content":{"rendered":"\n<p><em>This article is based on research by Marcelo Rivero, Malwarebytes\u2019 ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, \u201cknown attacks\u201d are those where the victim&nbsp;<strong>did not<\/strong>&nbsp;pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far higher.<\/em><\/p>\n<p>2023 was the worst ransomware year on record for Education: according to original ThreatDown research, the sector witnessed a staggering<strong> 70% surge<\/strong> in attacks in the past year, increasing from 129 incidents in 2022 to 265 in 2023.<\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button has-custom-width wp-block-button__width-75 is-style-fill\"><a class=\"wp-block-button__link has-white-color has-dark-blue-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/try.threatdown.com\/k12-bundle-quote\/?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2b_cm_global_k12_bundle_quote_170611984571\"><strong>Protect your school with the ThreatDown K-12 Bundle<\/strong><\/a><\/div>\n<\/p><\/div>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1251\" height=\"913\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/CORP_SOR_Education_Blog_Graph1.png?w=1024\" alt=\"\" class=\"wp-image-102647\" \/><\/figure>\n<p>The spike is further underscored by the increase in median monthly attacks. In 2022 there was an average of 11 attacks per month, but by 2023, this number leapt to 21\u2014marking an <strong>91% uptick<\/strong> in monthly attacks. <\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1428\" height=\"830\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-3.16.11\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102526\" \/><\/figure>\n<p>Although the attacks were carried out by several ransomware gangs, two in particular were responsible for the lion\u2019s share of 2023 attacks (50%)\u2014<strong>LockBit and Rhysida<\/strong> (a rebrand of Vice Society). The data also shows that, while ransomware attacks against education are a global phenomenon, the <strong>US<\/strong> (with 80% of known attacks) and the <strong>UK<\/strong> (with 12%) were hit the most frequently attacked countries between January 2023 and December 2023.<\/p>\n<p>Let\u2019s break down attacks on the education sector by the ransomware gangs involved, the countries of target, and which gangs attacked which countries the most.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-threat-landscape\">The Threat Landscape<\/h2>\n<p>The top gangs that targeted the education sector between January 2023 and December 2023 include<strong> LockBit (60), Vice Society\/Rhysida (44)<\/strong>, CL0P (22), Medusa (17), and Akira (15). Together, these 5 gangs were responsible for about 81% of all Education ransomware attacks.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1280\" height=\"1056\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-3.30.02\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102529\" \/><\/figure>\n<p>When we look at which gangs attack educational institutions most <strong>consistently<\/strong> (with attacks in at least six different months), however, the data tells a slightly different story. While top gangs such as CL0P and Royal may have targeted a significant amount of educational institutions, they tend to attack a majority of their victims in just one or two months.<\/p>\n<p>Again, LockBit and Vice Society\/Rhysida emerge as the most consistently prolific attackers against the Education sector. Notice too that Vice Society hasn\u2019t been active since June 2023\u2014the same month we witnessed the rise of Rhysida.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1251\" height=\"913\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/CORP_SOR_Education_Blog_Graph2.png?w=1024\" alt=\"\" class=\"wp-image-102653\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-geographic-distribution\">Geographic Distribution<\/h2>\n<p>When we break down education sector attacks by country, it becomes clear that the US and the UK have a huge target on their back. The US, however, bore the brunt of the onslaught, with <strong>169<\/strong> reported attacks.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1288\" height=\"1062\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-3.50.13\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102536\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-k-12-vs-higher-ed\">K-12 vs Higher Ed <\/h2>\n<p>In 2023, <strong>43% <\/strong>of all ransomware in education attacks in 2023 targeted Higher Ed and <strong>36% of attacks targeted K-12<\/strong>. <\/p>\n<p>Some of the most high profile attacks on Higher Ed and K-12 in 2023 include an attack against <a href=\"https:\/\/www.mlive.com\/news\/kalamazoo\/2023\/02\/wmu-it-services-return-to-full-operations-following-breach-by-unauthorized-user.html\">Western Michigan University<\/a>, which caused a 13-day service disruption, and against the <a href=\"https:\/\/www.fox9.com\/news\/minneapolis-public-schools-ransomware-attack\">Minneapolis School District<\/a>, which resulted in over 300,000 files leaked and a $1 million ransom.<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1042\" height=\"868\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-4.20.53\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102540\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-k-12-trends-yoy\">K-12 trends YoY<\/h2>\n<p>Ransomware attacks on K-12 increased<strong> 92% between 2022 and 2023<\/strong>, with 51 attacks in 2022 and 98 total attacks in 2023. <\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-2 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button has-custom-width wp-block-button__width-75 is-style-fill\"><a class=\"wp-block-button__link has-white-color has-dark-blue-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/try.threatdown.com\/k12-bundle-quote\/?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2b_cm_global_k12_bundle_quote_170611984571\"><strong>Learn more about the ThreatDown K-12 Bundle<\/strong><\/a><\/div>\n<\/p><\/div>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1410\" height=\"814\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-4.10.08\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102538\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-higher-ed-trends-yoy\">Higher Ed trends YoY<\/h2>\n<p>Ransomware attacks on Higher Ed increased <strong>70% between 2022 and 2023<\/strong>, with 68 attacks in 2022 and 116 total attacks in 2023. <\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1414\" height=\"808\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-23-at-3.03.24\u202fPM.png?w=1024\" alt=\"\" class=\"wp-image-102525\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-looking-ahead\">Looking Ahead<\/h2>\n<p>The reality is that tight budgets of many educational institutions force them to struggle with outdated equipment and limited staff, making education an easy target for ransomware gangs. To recap, our key findings include:<\/p>\n<ul>\n<li>2023 witnessed a worrying <strong>70% rise in ransomware attacks<\/strong> on the education sector, increasing from 129 incidents in 2022 to 265.<\/li>\n<li>The median number of monthly attacks <strong>surged by 91%<\/strong>, indicating a heightened and consistent threat throughout the year.<\/li>\n<li>LockBit and Rhysida emerged as the primary attackers, responsible for about <strong>50%<\/strong> of all attacks.<\/li>\n<li>The US and the UK bore the brunt of ransomware in education attacks, with over <strong>90% of all attacks <\/strong>being against these two countries.<\/li>\n<li>Both K-12 and higher education institutions faced significant increases in attacks, with a <strong>92% rise in attacks on K-12 and 70% in higher education<\/strong>, showing widespread vulnerability across all levels of the educational sector, but especially K-12.<\/li>\n<\/ul>\n<p class=\"has-text-align-left\">Ready to shield your school against threats like LockBit and Rhysida? <\/p>\n<p>The ThreatDown K-12 Bundle integrates AI-driven endpoint security, constant expert monitoring, comprehensive device management, and advanced mobile defense\u2014all at a price that makes sense. <\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-layout-3 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button has-custom-width wp-block-button__width-75 is-style-fill\"><a class=\"wp-block-button__link has-white-color has-dark-blue-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/try.threatdown.com\/k12-bundle-quote\/?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2b_cm_global_k12_bundle_quote_170611984571\"><strong>Fight ransomware with the ThreatDown K-12 Bundle<\/strong><\/a><\/div>\n<\/p><\/div>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2024\/01\/2024-state-of-ransomware-in-education-92-spike-in-k-12-attacks\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> 2023 was the worst ransomware year on record for Education. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[1001,3765,12040],"class_list":["post-23783","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-business","tag-ransomware","tag-threat-intelligence"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23783"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23783\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23783"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}