Cybercriminals are ramping up preparations for the new academic year by creating thousands of education-themed websites and phishing campaigns designed to steal personal and financial information from students, parents and educators, as the education sector remains the world’s most targeted industry for cyberattacks.
New research by Check Point Research, the threat intelligence arm of Check Point Software Technologies, found that educational organisations recorded an average of 4,696 cyberattacks per organisation every week between January and July 2026.
The figure represents an 8 percent increase from the same period in 2025 and is more than twice the global cross-industry average of 2,150 weekly attacks.
Education ranked as the most targeted of the 23 industries tracked by the researchers, with attack volumes about 70 percent higher than those recorded in the government sector, the second-most targeted industry.
The pressure intensified ahead of the new academic year, with educational organisations recording an average of 4,848 attacks per week in July alone, representing a 14 percent increase compared with July 2025.
Check Point Research said the threat was extending beyond schools and universities to the wider academic ecosystem, which includes students, parents, research partners, government agencies and third-party service providers.
Attackers prepare for back-to-school season
The researchers found evidence that cybercriminals are actively building infrastructure ahead of periods of increased online activity associated with the new school year.
In July, 18,954 newly registered domains containing education-related terms such as “school”, “university”, “college” and “student” were identified, representing a 5 percent increase from June and a 3 percent rise year-on-year.
The proportion of those domains flagged as malicious also increased.
According to Check Point ThreatCloud, one in every 305 newly registered education-related domains was malicious in June. By July, the ratio had risen to one in every 226 domains.
Some of the suspicious domains identified by researchers included websites designed to resemble legitimate education and government services, such as education-gov[.]com, students-portal[.]com and checkmyschool[.]org.
Researchers also uncovered coordinated registration campaigns, including 10 student-loan themed domains using the studentloansYYYY.com format for years spanning 2026 to 2035, as well as a network of 48 domains focused on bootcamps and students.
Check Point said the pattern indicated that threat actors were increasingly using automated and large-scale domain registration to establish infrastructure that could later be used in phishing and other malicious campaigns.
Students and educators targeted through phishing
The back-to-school period is particularly attractive to cybercriminals because students, parents and educators typically engage in higher volumes of online activity involving enrolment, financial transactions, document sharing, account creation and email communication.
Researchers identified campaigns using fake student discounts, rewards and enrolment offers to lure victims into providing personal or financial information.
One campaign used the domain studentdiscount[.]online to impersonate a student rewards promotion by US retailer Target, offering a fake $750 reward before redirecting victims to fraudulent offers and gambling-related content.
The researchers also identified malicious PDF files masquerading as documents from schools and educational institutions.
Two such files directed users through compromised websites before eventually taking them to counterfeit Microsoft 365 and OneDrive login pages designed to capture account credentials.
In another case, researchers found a malicious page hosted on the compromised website. The page was identified by multiple threat intelligence sources as an information-stealing and malware distribution site.
The researchers said the page had previously displayed a fake Spotify-branded security verification CAPTCHA, a technique commonly used by attackers to deliver malware or evade security analysis.
The findings demonstrate how cybercriminals are increasingly exploiting trusted institutions, familiar brands and routine academic processes to make phishing attempts appear legitimate.
APAC records highest attack volume
The threat is being recorded across regions, although Asia-Pacific had the highest attack volume during the period reviewed.
Educational organisations in the region experienced an average of 7,452 weekly attacks per organisation between January and July 2026.
Europe and Latin America recorded the fastest year-on-year increases, with average weekly attacks rising by 18 percent to 4,759 in Europe and by 42 percent to 4,299 in Latin America.
Check Point Research said the growing dependence of educational institutions on cloud platforms, digital learning environments and online collaboration tools was increasing the potential impact of successful attacks.
A breach at an educational institution could expose not only the organisation but also students, parents, research partners, government agencies and third-party service providers connected to the wider ecosystem.
The researchers urged educational organisations to make cybersecurity part of their back-to-school preparations by training staff and students to identify phishing emails, fake reward offers and suspicious login pages.
They also recommended carefully checking website addresses before entering credentials or personal information, enabling multi-factor authentication on Microsoft 365, email and academic systems, regularly patching devices and learning platforms, monitoring education-themed domain registrations and reviewing access to sensitive student, research and administrative data.
As cybercriminals increasingly align their campaigns with the academic calendar, Check Point Research said educational institutions needed to treat cybersecurity as a core component of back-to-school preparedness rather than an issue to be addressed after an incident occurs.




