The education sector has become the most targeted industry for cyberattacks globally, with Check Point reporting that schools, colleges, universities, and research institutions averaged 4,696 weekly attacks from January through July 2026—well above the cross-industry average and up 8% year over year. Researchers said attacker activity is intensifying ahead of the academic term, with 18,954 newly registered education-related domains observed in July and the share flagged as malicious worsening from 1 in 305 in June to 1 in 226 in July. Regional pressure was strongest in APAC by attack volume, while Europe and Latin America saw notable growth.
Threat actors are using education-themed phishing, credential theft, and malware delivery to exploit routine school workflows and trusted brands. Observed lures included fake student discount and reward sites, spoofed education and government portals, and malicious PDFs that redirected victims to counterfeit Microsoft 365 and OneDrive login pages designed to harvest credentials. Researchers also identified malware distribution through a compromised school website in Bangladesh, underscoring how attackers are combining fraudulent domains with abused legitimate infrastructure to target students, staff, and institutions for account compromise and theft of personal and financial data.

See the actors and campaigns active against you right now.
10 events from the most recent confirmed update back to the earliest known activity.
In July 2026, the proportion of newly registered education-related domains flagged as malicious worsened to one in every 226. Check Point assessed this as part of a seasonal back-to-school buildup in attacker infrastructure.
Researchers identified 18,954 newly registered education-themed domains in July 2026, up 5% month over month and 3% year over year. Examples included deceptive domains such as education-gov[.]com, students-portal[.]com, and checkmyschool[.]org.
In July 2026, weekly attacks against education organizations climbed to 4,848. The July figure represented a 14% year-over-year increase, with APAC posting the highest regional volume and Europe and Latin America showing notable growth.
Check Point ThreatCloud data showed that in June 2026, one in every 305 newly registered education-related domains was flagged as malicious. This established the baseline before a worse ratio was observed the following month.
During summer 2026, multiple Vermont school districts, including Slate Valley Unified Union School District and Orleans Central Supervisory Union, were targeted by a credential-phishing campaign using trusted real email accounts and an "excel secure portal" lure. Officials said the malicious link triggered scripts that read and deleted emails and sent further phishing messages, but they found no evidence of student or staff data theft or monetary loss.
Researchers identified a coordinated registration campaign of 10 student loan-themed domains following the studentloansYYYY.com pattern for 2026 through 2035, along with a network of 48 bootcamp-student domains. The registrations were assessed as evidence of large-scale automated activity targeting students and prospective learners.
Check Point reported that education became the most targeted industry worldwide in 2026. Between January and July 2026, education organizations averaged 4,696 weekly attacks per organization, ranking first among 23 tracked sectors and exceeding both the cross-industry average and government sector volumes.
Researchers identified a malicious URL at cambrianschoolbd[.]com/mail/ hosted on the compromised website of Bangladesh’s Cambrian School. Threat intelligence sources flagged the URL as an information-stealer and malware distribution point, and the site had previously displayed a fake Spotify-branded CAPTCHA linked to malware delivery or evasion.
Researchers uncovered malicious PDF campaigns, including files named globeschool.pdf and beths-grammar-school.pdf, that impersonated specific schools. The PDFs routed victims through compromised websites to counterfeit Microsoft 365 and OneDrive login pages designed to harvest credentials.
Researchers documented an active phishing scheme using studentdiscount[.]online that impersonated a Target student rewards promotion. The lure promised a fake $750 reward and redirected victims to fraudulent offers and gambling-related content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
vtdigger.org
Open sourceitsecurityguru.org
Open sourceitsecurityguru.org
Open sourceblog.checkpoint.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.