Ransomware attacks on schools spiked in June, reaching a new record high. On average, ransomware groups claimed more than one attack per day on educational institutions.
In June, there were 37 attacks on schools, which is more than the 24 attacks that occurred the month before. This information is from Recorded Future, who collected data from various sources such as extortion sites, government agencies, news reports, and hacking forums.
By infosecbulletin
/ Friday , May 9 2025
Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
By infosecbulletin
/ Thursday , May 8 2025
The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
By infosecbulletin
/ Thursday , May 8 2025
SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
By infosecbulletin
/ Thursday , May 8 2025
From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
By infosecbulletin
/ Thursday , May 8 2025
Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
The increase was mainly caused by the Clop ransomware group from Russia. They used vulnerability in the MOVEit file transfer tool to access computer networks globally. The attacks have targeted a wide range of organizations — including Shell, Siemens Energy, and the largest public pension fund in the U.S. — and hit the education sector especially hard.
ALSO READ:
The GPT-4 API Available To Everyone
“There was a significant impact on schools due to the Cl0P MOVEit attacks,” stated Allan Liska, a ransomware expert at Recorded Future who tracks attacks. “Cl0p was responsible for 12 attacks against schools in June — almost one-in-three — and propelled school ransomware attacks to their worst month ever.”
In contrast, Clop was only accountable for a single assault on educational institutions from January to May 2023.
While Clop gained significant attention in June due to the MOVEit attacks, it is important to note that there were other active groups as well. In total, there were 408 victims posted to ransomware sites in June, compared to 414 the previous month and just 150 in June 2022.
LockBit is behind most of the recent attacks, which includes targeting a dental insurance provider, a water utility in Portugal, and the Royal Mail in the UK.
Liska said that while Clop is responsible for a lot of activity in June, ransomware attacks in general have been very alarming. “There are more groups going after more targets and it is a never ending barrage of attacks.”




Source: the record