19,300,000+ cyberattacks put UK education on alert

19,300,000+ cyberattacks put UK education on alert

UK schools, colleges and universities are being subjected to a surge of automated cyberattacks, with SonicWall threat intelligence recording more than 19.3 million medium and high-severity intrusion attempts so far this year.

The total has already surpassed the 11.5 million events recorded across the whole of 2025, with SonicWall data showing a 67% annualised increase in intrusion activity across UK education.

Educational infrastructure and institutions probed

According to the data, the majority of activity was concentrated in SonicWall’s Educational Services category, which accounted for 16.8 million events or 87% of the sector total.

Attackers are primarily probing web-facing education infrastructure. Path traversal and directory manipulation attacks generated 10.2 million hits across the four leading signatures, while web-based attacks accounted for 17.3 million events overall.

The data also highlights continued exposure to legacy vulnerabilities. Apache Log4j2 Remote Code Execution was the leading signature targeting UK primary and secondary schools, generating around 660,000 hits, almost 7x higher than similar attacks on healthcare. SonicWall also recorded 71,000 attempts against TFTP Server Directory Traversal signatures, targeting network boot infrastructure commonly used across school IT environments.

Ransomware a rarity

Despite the surge in intrusion activity, ransomware remains comparatively rare. Just 36 ransomware events were detected across SonicWall’s UK education sensor fleet, the lowest level recorded across any UK sector tracked.

“Education is showing us that cyber-risk shows more than a ransomware gang breaking through the front door,” said Spencer Starkey, Executive Vice President, EMEA, SonicWall. “We’re seeing relentless automated scanning of the systems schools and universities depend on every day, from student portals to learning platforms, as attackers look for something that has been left exposed.

“The low number of ransomware events is encouraging, but it shouldn’t create a false sense of security. If attackers find an unpatched vulnerability, exposed directory or overlooked network service, that initial intrusion can quickly become a much bigger problem.”

SonicWall’s analysis is based on Intrusion Prevention System (IPS) data from UK-registered education sensors in 2026.

Browse our latest issue

Intelligent CISO

View Magazine Archive