Higher Education's New Threat Reality

From AI-powered swatting and ransomware to doxxing and credential theft, colleges and universities face an increasingly complex landscape in which cyberattacks can rapidly escalate into physical security crises. Here's how institutions can prepare before the next academic year.

Key Highlights

  • Universities are prime targets because of their operational importance, sensitive data, and media visibility, making a quick response and resilience critical.
  • Emerging threats include AI-enhanced swatting, doxxing for ideological purposes, and ransomware attacks exploiting interconnected systems and third-party services.
  • Proactive measures such as comprehensive incident response plans, regular software updates, strong password policies, and staff training are vital for campus security.

We’re seeing more risk-centric headlines in the higher education sphere. From the highly publicized infrastructure ransomware attack to a rise in active shooter hoaxes. Colleges and universities are in the midst of a blended risk landscape in which physical and digital threats converge. Why schools? Why is this becoming much more common?

It’s a multi-faceted answer. In short, it’s a blend of their operational model, abundance of sensitive personal information, media attention, and significant financial resources. Universities cannot afford downtime. There are tests to grade, graduations to conduct, and facilities to run. When you’re dealing with thousands of students, teachers, and staff, maintaining operations is paramount. This commitment to maintaining operational normality makes any issue “marked urgent.”

Due to higher education’s cyber insurance premiums, unused state grant funding, and reserve budgets that are typically accessible, they have long been perceived (in the eyes of the cybercriminal community) as more likely to pay a ransom. But that’s just the focus of financially motivated hackers. For hacktivists or notoriety-seeking groups, attacks against the higher education sector garner media attention. For those seeking chaos or pushing a specific agenda, this is the stage to do so.

We’ve seen schools become a more common target, and I’ve witnessed the threat landscape evolve, introducing new exploitation techniques, physical targeting, and repercussions. As a result, my team and I spearheaded an analysis of the threat landscape pertaining to universities in North America. Here’s what we’re seeing.

The Attacker Landscape

Threat actors seek chaos. The disruption, drama, speculation, rumors, and all the dramatic fallout that ensues when incidents occur is what they crave. For higher education, one of the most prolific ways we’re seeing it play out is in AI-enhanced swatting. Largely the work of a group called Purgatory. For fees reportedly ranging from $20 to $95, Purgatory, which is part of a larger outfit of online extremists called the Com Group, would place calls reporting an active shooter on campus. During one stretch between Aug. 21-25 last year, the calls created panic at Villanova University, which was in the midst of a welcome ceremony for new students. However, Villanova University wasn’t the only one affected; the group reportedly also made calls to the University of Tennessee at Chattanooga and about 10 others. These calls are increasingly becoming more common.

We’re also seeing a rise in doxxing. Doxxing, or the exposure of personal information such as home addresses, is often associated with revenge. There’s a disgruntled student or colleague who wants to incite others to harass these individuals. But what we’re seeing now is doxxing being used as a tool for ideological targeting. Essentially, hacktivists, who use digital intrusion techniques to push a specific agenda, will find and leak personal information belonging to those who challenge their beliefs. Increasingly, educators have become targets for these campaigns.

Shifting gears to financially motivated cybercriminals. We’ve already touched on why universities are attractive targets for ransomware campaigns, but I want to dive a bit deeper into how they also unintentionally serve as a perfect attack surface that lets gangs get in the door in the first place. Threat actors exploit universities’ interconnectivity via the cloud and their use of third-party services to steal information, such as credentials, for network intrusion, leading to hefty ransom demands.

No matter the motivations, universities remain a prime target for digital and physical threats.

In fact, we’ve seen ShinyHunters emerge as one of the most prolific and highly active threat actor groups targeting higher education. Since 2019, ShinyHunters has carried out successful attacks on a broad range of organizations, but more recently, the group has focused on the education sector, targeting more than 10% of its ransomware and digital extortion attacks at higher ed institutions, students, educators, and administrators. Single attacks have targeted Princeton and Harvard universities and the University of Pennsylvania, for example, but the attack with the biggest blast radius began in April 2026 with the breach of Instructure, the educational technology company that offers Canvas.

A comprehensive system for managing online learning, course management, and student engagement, Canvas is the most popular learning management system in the United States and is used by 41% of higher ed institutions. Beginning on April 30, 2026, the breach quickly spread and eventually affected as many as 275 million people across 8,809 institutions, according to ShinyHunters’ claims. The breached universities included notable institutions such as Harvard, Stanford, MIT, and the University of California, Berkeley. And because it happened during finals season, Canvas paid the ransom.

To conduct the attack, threat actors gleaned information from university directories, social media platforms, networking sites, and educational records, then used it to deploy phishing and social engineering tactics to steal credentials and gain access. Once inside, they could explore SaaS applications for information, escalate privileges, and siphon information. Attackers could then use credentials and access tokens stolen from one institution to target connected organizations, taking a “credentials ladder” strategy to spread the attack.

However, ShinyHunters is far from the only group schools must worry about. In fact, between early 2025 and early 2026, the ransomware and digital extortion collective most actively targeting North American educational institutions was Qilin. Qilin’s ransomware strain recorded nearly twice as many incidents as its closest competitor, Interlock, which is followed on the most-active list by SafePay, INC Ransom, and Medusa.

How Institutions Can Stop Threat Actors in Their Tracks

No matter the motivations, universities remain a prime target for digital and physical threats.  In the coming months and years, I expect to see more ransomware, doxxing, and AI-enhanced swatting attacks targeting higher education institutions, as new tactics and techniques emerge.

  • With schools out for the summer, universities should use this time to prepare for students' return to campus next fall.
  •  Develop a comprehensive incident response strategy.
  • Work with local law enforcement to determine protocols and response needs for AI-enhanced swatting incidents
  • Deploy a holistic patch management process and ensure all IT assets are updated with the latest software updates as quickly as possible.
  • Implement secure password policies with phishing-resistant multi-factor authentication (MFA), complex passwords, and unique credentials.
  • Ensure critical, proprietary, or sensitive data is always backed up to secure, off-site, or cloud-based servers at least once per year—and ideally more frequently.
  • Deploy next-generation endpoint detection and response solutions to mitigate anomalous activity on systems.
  • Promote educational and security awareness training for faculty and staff, focusing on social engineering tactics, phishing emails, and current cyber threats.

No plan is perfect, but a good defense can stop threats from harming students and faculty on campus. The time to prepare is now. This summer, universities should prioritize assessing their digital security posture and physical security preparedness plans before students return to campus next fall. Resilience depends on preparation before the next threat arrives.

About the Author

Olga Polishchuk

Olga Polishchuk

VP of Investigations, ZeroFox

Olga Polishchuk is the VP of Investigations at ZeroFox. Olga is a security and intelligence professional with over a decade of experience in corporate security, open-source intelligence, threat & risk assessments, and a wide array of physical and information security investigations. At ZeroFox, she focuses on tactical investigations, threat assessments, and strategic intelligence. Prior to ZeroFox, Olga worked for an intelligence-focused research institute supporting the US intelligence community and at an international law firm in Washington, DC, focusing on cross-border technology protection.

Sign up for our eNewsletters
Get the latest news and updates