Identity attacks drive 85 % of ransomware incidents in education
SentinelOne and Tenable: Attackers target vendor ecosystems
CISO news
Identity attacks drive 85 % of ransomware incidents in education
ophos has released its annual State of Ransomware in Education 2026 report, revealing that identity-based attack
S techniques were used in 85 % of ransomware attacks against educational institutions.
These techniques included malicious email, phishing, compromised credentials and brute-force attacks. The 85 % figure exceeded the cross-sector average of 79 %, highlighting the significant role identity compromise continues to play in ransomware incidents targeting both lower and higher education institutions.
Malicious email was the leading technical root cause of ransomware attacks across the education sector, accounting for 31 % of attacks in lower education and 29 % in higher education.
The report also found that 77 % of higher education organisations and 71 % of lower education organisations said their ransomware incident was also their most significant identity attack.
Ross McKerchar, Chief Information Security Officer, Sophos
“ Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints,” said Ross McKerchar, Chief Information Security Officer, Sophos.“ Today’ s attackers don’ t need a crowbar when they can steal the keys. Identity compromise has become one of the most
effective paths into an organisation, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”
SentinelOne and Tenable: Attackers target vendor ecosystems
entinelOne and Tenable have released joint research revealing that cyber attackers are increasingly targeting
S vulnerable vendor ecosystems and technology surfaces rather than focusing on individual vulnerabilities.
The research combines Tenable’ s exposure data across thousands of organisations and remediation telemetry with SentinelOne’ s endpoint and post-exploitation detection data. The findings point to a growing disconnect between vulnerability discovery, disclosure and real-world exploitation.
The most significant finding is that nation-state and criminal threat actors are concentrating their efforts on particular vendors and susceptible areas of the attack surface rather than individual CVEs.
This trend is becoming increasingly important as attacker timelines accelerate. Frontier AI models are compressing vulnerability discovery from months to hours, while attackers can move from
Vlad Korsunsky, Chief Technology Officer, Tenable
disclosure to exploit code in around a week. Meanwhile, the median organisation takes five months to remediate known vulnerabilities.
The research found that exposure data and runtime detection converge on the same edge-device vendor surfaces 79 % of the time, compared with just 21 % overlap at the individual vulnerability level.
“ Attackers systematically target specific vendor ecosystems that could provide access. They aren’ t obsessing over single vulnerabilities, and neither should defenders,” said Vlad Korsunsky, Chief Technology Officer, Tenable.“ Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. This research underscores exposure management principles: seeing, prioritising and fixing exposures that create real business risk. As attackers weaponise AI to breach defenses faster, organisations that embrace exposure management will win.”
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 9