U.S. authorities warned that malicious cyber actors were actively targeting K-12 schools and other educational institutions as remote learning expanded, using ransomware, malware, phishing, DDoS attacks, and video-conference intrusions to disrupt classes and steal sensitive data. The joint FBI, CISA, and MS-ISAC advisory said schools had become targets of opportunity, with ransomware incidents rising sharply and commonly involving data theft and extortion; families observed in attacks included Ryuk, Maze, Nefilim, AKO, and Sodinokibi/REvil, while malware such as ZeuS and Shlayer also affected the sector.
Separate reporting on criminal forums showed underground sellers offering remote access to compromised schools and universities in the U.S., U.K., Australia, Israel, and Germany, with listings priced from $200 to $17,000 based on victim size and privilege level. The activity coincided with leaked credentials, exposed FTP servers, and student-data incidents tied to education and e-learning platforms, reinforcing concerns about weak remote-access security, exposed RDP and SMB services, end-of-life software, and third-party edtech risks; officials urged patching, MFA, network segmentation, offline backups, DDoS protections, tighter conferencing controls, and stronger vetting of service providers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On December 10, 2020, the FBI, CISA, and MS-ISAC published a joint cybersecurity advisory warning that malicious cyber actors were targeting U.S. K-12 educational institutions. The advisory described ransomware, malware, DDoS attacks, data theft, and distance-learning disruptions affecting schools.
According to MS-ISAC data cited in the joint advisory, 57% of ransomware incidents reported in August and September 2020 involved K-12 schools. This was a sharp increase from 28% of reported ransomware incidents from January through July 2020.
KELA reported that during August it tracked more than 45 remote-access listings across major underground forums, including 7 involving educational institutions. The listings primarily affected schools and universities in the US and UK, with additional victims in Australia, Israel, and Germany.
The CISA/FBI/MS-ISAC advisory says that since March 2020 the agencies had received numerous reports of uninvited users disrupting live video-conferenced classroom sessions. Reported disruptions included harassment, pornography or violent imagery, and doxing of attendees.
The KELA article states that data tied to K7math, an Australian e-learning service, had previously been leaked for free in March. It says a later listing linked to an Australian Education Department was connected back to this earlier K7math leak.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.