The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Higher Education/Acadamia

Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.

428 threat reports
Page 1 of 36

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Higher Education/Acadamia Threat Reports

Showing 1–12 / 428 reports
Ryuk Ransomware Architect Sentenced: Lessons for Modern Enterprise Security
Impact· HIGH

Ryuk Ransomware Architect Sentenced: Lessons for Modern Enterprise Security

Karen Serobovich Vardanyan, a 35-year-old Armenian national known online as 'Maneeken' or 'Karl Lagerfeld,' was sentenced to 24 months in prison for his role in Ryuk ransomware attacks between March 2019 and June 2020. Vardanyan specialized in gaining initial access to corporate networks, helping his cybercriminal group breach multiple U.S. organizations including companies in Michigan, Texas, and Oregon. The group collected over $15 million in ransom payments, with one Michigan company alone paying 200 BTC worth over $1.1 million. Vardanyan was extradited from Ukraine in 2025 and pleaded guilty in July 2026. This sentencing highlights the ongoing global law enforcement efforts to prosecute ransomware operators, even years after attacks occurred. As ransomware groups continue to evolve and fragment into smaller units, the Ryuk-to-Conti evolution demonstrates how cybercriminal organizations adapt and rebrand while maintaining similar attack methodologies.

23 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft Takes Down EvilTokens: How AI-Powered Phishing Services Threaten Enterprise Identity Security
Impact· HIGH

Microsoft Takes Down EvilTokens: How AI-Powered Phishing Services Threaten Enterprise Identity Security

In September 2026, Microsoft successfully disrupted EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992. The AI-powered cybercrime service facilitated device code phishing attacks targeting Microsoft 365 accounts, compromising over 12,000 inboxes across 10,000+ organizations worldwide. Microsoft seized 50 websites and disabled 150+ domains, while UK authorities arrested two suspects. EvilTokens distinguished itself by automating device code authentication abuse at scale, using AI to craft tailored phishing lures, analyze compromised inboxes for high-value targets, and streamline business email compromise campaigns sold for $1,500 upfront plus $500 monthly via Telegram. This incident highlights the alarming evolution of phishing-as-a-service platforms leveraging AI to democratize sophisticated attacks. As threat actors increasingly weaponize legitimate authentication mechanisms and AI capabilities, organizations face unprecedented challenges in defending against automated, scalable identity-based attacks that bypass traditional security controls.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement
Impact· CRITICAL

ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement

In September 2026, the ShinyHunters cybercrime group claimed to have breached the FBI's systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly stealing sensitive data on current and former FBI employees and job applicants. The attackers defaced the FBI jobs website and claimed access to Criminal Justice, HR, and Medlink services. This attack was reportedly conducted in retaliation for an FBI public service announcement warning against paying the group's ransom demands following their Canvas LMS attacks in May 2026. This incident highlights the escalating boldness of cybercriminal groups directly targeting law enforcement agencies and exploiting enterprise software vulnerabilities. The targeting represents a significant shift in threat actor behavior, moving beyond traditional corporate victims to challenge government authority directly.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Macfinger ClickFix Campaign Deploys AMOS Stealer Through Social Engineering
Impact· MEDIUM

Macfinger ClickFix Campaign Deploys AMOS Stealer Through Social Engineering

The Macfinger ClickFix campaign represents a sophisticated social engineering attack targeting macOS users through compromised legitimate websites. Attackers inject malicious JavaScript that displays fake bot verification pages, tricking users into executing commands that download and install AMOS (Atomic macOS) Stealer malware. The campaign uses fingerprinting techniques to specifically target macOS environments, with victims' systems subsequently exfiltrating credentials and sensitive data to command-and-control servers at 95.163.153.80. Post-infection analysis reveals persistent credential harvesting through API endpoints designed to steal stored passwords, browser data, and system information. This incident highlights the growing sophistication of social engineering attacks targeting macOS users, who have traditionally been less targeted than Windows environments. The campaign's use of legitimate compromised websites and convincing fake verification pages represents an evolution in ClickFix techniques, making detection more challenging for users and security tools alike.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale
Impact· HIGH

EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale

EvilTokens emerged in February 2026 as a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992, compromising over 12,000 inboxes across 10,000+ organizations worldwide. The platform exploited OAuth device code authentication flows through AI-powered phishing campaigns, enabling cybercriminals to bypass multifactor authentication and steal authentication tokens at scale. EvilTokens featured 44 customizable phishing templates, automated AI assistants for crafting targeted lures, and multi-stage delivery pipelines designed to evade traditional email security controls. This incident highlights the industrialization of token-based attacks as organizations increasingly adopt MFA, forcing threat actors to evolve beyond credential theft toward authentication bypass techniques that exploit legitimate OAuth flows and cloud service integrations.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement
Impact· HIGH

ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement

In December 2024, the notorious cybercrime group ShinyHunters claimed responsibility for attacking FBI systems, specifically targeting the FBIjobs.gov website and temporarily defacing the jobs portal. The group alleged they stole sensitive data on nearly all FBI agents and job applicants, marking a direct escalation against federal law enforcement. The attack was reportedly motivated by ShinyHunters' dispute with an FBI public service announcement that contained what they claimed were false allegations about their operations. This incident represents a significant escalation in the group's targeting strategy, moving from typical corporate victims to directly confronting law enforcement agencies. This attack highlights the growing boldness of ransomware groups in 2024, as threat actors increasingly target critical infrastructure and government entities. The incident underscores the evolving threat landscape where cybercriminals are willing to directly challenge law enforcement, potentially signaling a shift toward more brazen attacks on government systems.

1 day ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
SideCopy APT Expands to Target Indian Academic Institutions with Advanced ReverseRAT Campaign
Impact· HIGH

SideCopy APT Expands to Target Indian Academic Institutions with Advanced ReverseRAT Campaign

The Pakistan-linked APT group SideCopy has expanded its targeting beyond Indian government entities to include academic institutions through sophisticated spear-phishing campaigns in 2026. The threat actors utilize weaponized ZIP archives containing malicious LNK files that abuse mshta.exe to execute obfuscated HTML applications, ultimately deploying the ReverseRAT malware for data exfiltration and remote access. The attack chain employs multi-stage obfuscation, anti-forensic self-deletion routines, and encrypted command-and-control communications to evade detection while harvesting system metadata, credentials, and sensitive documents from compromised networks. This incident highlights the evolving threat landscape where state-sponsored groups are diversifying their target profiles to include educational institutions, recognizing their value as repositories of intellectual property and research data. The sophistication of SideCopy's techniques demonstrates the growing challenge organizations face in defending against adaptive APT groups that continuously refine their tradecraft.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts
Impact· HIGH

EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts

In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms. This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities
Impact· HIGH

ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities

In September 2026, the ShinyHunters extortion gang claimed to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly accessing FBI-managed AWS GovCloud infrastructure and stealing 2-3TB of sensitive data including employee and job applicant information. The threat actors defaced the FBI Jobs website and claimed access to Criminal Justice, HR, and Medlink services before the FBI quickly took affected systems offline. ShinyHunters stated the attack was retaliation against an FBI FLASH report published in May 2026 that detailed the group's activities and demanded corrections within one week. This incident highlights the growing trend of threat actors targeting government infrastructure through supply chain vulnerabilities and using high-profile breaches as leverage against law enforcement agencies. The exploitation of zero-day vulnerabilities in enterprise applications like PeopleSoft demonstrates the critical need for enhanced security measures in government cloud environments.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sweden Imposes $183K GDPR Fine on Miljödata After Ransomware Breach Affects 2.2M Citizens
Impact· HIGH

Sweden Imposes $183K GDPR Fine on Miljödata After Ransomware Breach Affects 2.2M Citizens

In August 2025, Swedish IT systems provider Miljödata suffered a cyberattack that compromised sensitive data of 2.2 million people across over 200 municipalities. The attackers demanded 1.5 Bitcoin ransom but published the stolen data on the dark web under "Datacarry" when payment was not made. The breach exposed personal identity numbers, contact information, sickness absence records, rehabilitation data, and school incidents involving minors. Sweden's data privacy regulator IMY subsequently fined Miljödata $183,000 for GDPR violations, citing inadequate security measures including insufficient software validation and lack of automated real-time monitoring. This incident highlights the escalating regulatory enforcement of GDPR compliance following ransomware attacks, as European authorities increasingly impose substantial penalties for security negligence that enables data breaches affecting millions of citizens.

2 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026
Impact· HIGH

EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026

In September 2026, Microsoft coordinated a global takedown of EvilTokens, a sophisticated phishing-as-a-service platform that leveraged artificial intelligence throughout its attack chain. The Storm-2992 threat group operated this commercial cybercrime service, which exploited OAuth 2.0 device authorization flows to compromise over 12,000 email inboxes across 10,000 organizations worldwide. EvilTokens featured an AI-powered chatbot that analyzed victim inboxes to identify trusted relationships and recommend fraud strategies, significantly lowering the technical barriers for business email compromise attacks. The platform generated approximately $1.1 million in revenue and targeted organizations across wholesale distribution, construction, financial services, healthcare, and education sectors. This incident highlights the dangerous convergence of AI technology with cybercrime infrastructure, demonstrating how threat actors are weaponizing artificial intelligence to automate and scale sophisticated social engineering attacks at an unprecedented level.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SharePoint CVE-2026-65660: When Microsoft Gets Vulnerability Classification Wrong
Impact· HIGH

SharePoint CVE-2026-65660: When Microsoft Gets Vulnerability Classification Wrong

CVE-2026-65660 is a SharePoint Server vulnerability that Microsoft initially misclassified as a spoofing flaw with a CVSS score of 6.5, but actually enables authenticated remote code execution with a score of 8.8. Discovered by Viettel Cyber Security researcher Dinh Ho Anh Khoa, the flaw affects SharePoint Server 2016, 2019, and Subscription Edition through improper SafeControls list validation. The vulnerability allows attackers to inject malicious directives and execute arbitrary .NET classes via XamlServices.Parse() deserialization, potentially leading to in-memory webshell deployment. While patches were released on August 11, 2026, the initial misclassification as a moderate spoofing issue may have led organizations to deprioritize patching. This incident highlights the critical importance of accurate vulnerability classification and the ongoing targeting of SharePoint environments by sophisticated threat actors, particularly following recent exploitation of SharePoint flaws by Chinese state-backed groups.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports