The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Primary/Secondary Education

Breach intelligence, attack campaigns, and threat reports targeting the Primary/Secondary Education sector.

55 threat reports
Page 1 of 5

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Primary/Secondary Education Threat Reports

Showing 1–12 / 55 reports
Ryuk Ransomware Operator Sentenced: Lessons for Enterprise Security
Impact· CRITICAL

Ryuk Ransomware Operator Sentenced: Lessons for Enterprise Security

Karen Vardanyan, a 35-year-old Armenian national, was sentenced to two years in prison for his role in Ryuk ransomware attacks that occurred between March 2019 and September 2020. Operating from Ukraine and Russia, Vardanyan and his co-conspirators deployed Ryuk ransomware on hundreds of compromised servers and workstations, targeting victims including a Michigan company, an Oregon technology firm, and a Texas school district. The group received approximately 1,160 bitcoins worth over $15 million in ransom payments during their campaign. This case highlights the continued enforcement actions against ransomware operators as law enforcement agencies prioritize dismantling cybercriminal networks. With ransomware attacks resurging in 2024 and targeting critical infrastructure, prosecutions like Vardanyan's demonstrate the long-term consequences facing cybercriminals even years after their crimes.

8 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Threat Actor Weaponizes AI Agents in Massive PaperCut Exploitation Campaign
Impact· CRITICAL

Russian Threat Actor Weaponizes AI Agents in Massive PaperCut Exploitation Campaign

In September 2026, a suspected Russian-speaking threat actor leveraged hundreds of AI agents powered by OpenAI Codex and DeepSeek models to exploit CVE-2026-81578 and CVE-2026-82078 vulnerabilities in PaperCut NG/MF print management software. The attacker compromised over 440 instances across 395 organizations in 48 countries, primarily targeting educational institutions. Using an AI-driven exploitation pipeline, the threat actor achieved domain administrator access in some cases within seven minutes of initial compromise, demonstrating unprecedented speed and scale in automated attacks. This incident represents a paradigm shift in cybersecurity threats, showcasing how AI is being weaponized to accelerate every stage of the attack lifecycle from vulnerability research to exploitation at scale. As AI-powered offensive capabilities become more accessible, organizations face an asymmetric threat landscape where attackers can conduct sophisticated campaigns with minimal human intervention.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Mathspace Breach Exposes 1M+ Records: How ShinyHunters Weaponized Metabase Vulnerabilities
Impact· CRITICAL

Mathspace Breach Exposes 1M+ Records: How ShinyHunters Weaponized Metabase Vulnerabilities

On August 10, 2026, threat actors exploited a critical SQL injection vulnerability in Mathspace's self-hosted Metabase instance, gaining administrator access and stealing personal data from over 1 million students, staff, and parents across Australia and New Zealand. The attack was executed by the ShinyHunters extortion gang, who downloaded the data on August 27 before the breach was confirmed on September 3. This incident was part of a broader campaign targeting multiple organizations' Metabase installations worldwide, affecting companies including Trezor, Framework, and Tally. This breach highlights the critical importance of securing internal reporting systems and data analytics platforms, as threat actors increasingly target business intelligence tools that often have broad database access. The incident demonstrates how zero-day vulnerabilities in widely-used SaaS tools can be weaponized at scale, creating cascading impacts across multiple organizations simultaneously.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
PaperCut Vulnerabilities Exploited in Massive Credential Theft Campaign Against Schools
Impact· CRITICAL

PaperCut Vulnerabilities Exploited in Massive Credential Theft Campaign Against Schools

In September 2026, threat actors actively exploited two chained PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to conduct widespread credential theft attacks against educational institutions across the United States and Europe. The attack chain leveraged an authentication bypass vulnerability followed by remote code execution to deploy registry harvesting tools, Metasploit payloads, and create privileged accounts on compromised print management servers. Arctic Wolf researchers observed attackers systematically extracting Windows registry hives, searching configuration files for sensitive credentials, and establishing persistent access through Meterpreter sessions, targeting organizations from K-12 schools to major universities. This campaign highlights the continued targeting of educational infrastructure, which often lacks robust security controls and runs legacy systems with delayed patching cycles, making institutions particularly vulnerable to supply chain and third-party application exploits.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case
Impact· CRITICAL

Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case

In December 2024, a 17-year-old from Maine became the first minor to be federally charged and detained for crimes related to involvement in 764, a nihilistic violent extremist collective. The teenager was convicted of multiple federal crimes including conspiracy to sexually exploit children, distributing child sexual abuse material, cyberstalking, and identity theft. This case represents a significant shift in federal law enforcement policy, as authorities have historically avoided prosecuting minors for extremist activities, creating what experts called a dangerous loophole that encouraged maximum harm before age 18. This prosecution signals law enforcement's evolved approach to addressing violent online extremism that increasingly targets and recruits minors. With the FBI investigating over 500 subjects nationwide connected to 764 and affiliated groups, this case establishes precedent for holding juvenile perpetrators accountable while disrupting recruitment strategies that exploit legal protections for minors.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fatal Consequences: Nigerian Sextortion Ring Extradited After Teen Deaths
Impact· CRITICAL

Fatal Consequences: Nigerian Sextortion Ring Extradited After Teen Deaths

Two Nigerian nationals, Adebola Festus Adekunle (26) and Mudasiru Afeez Olawale (24), were extradited to the United States in August 2026 following their arrest in Nigeria during Operation Artemis in 2023. The men are charged with conducting sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. Their crimes involved coercing minors into producing explicit content, then using blackmail and threats to extort victims, leading to tragic outcomes. They face maximum life sentences with mandatory minimums of 30 years for child exploitation resulting in death. This case highlights the escalating severity of international cybercrime targeting minors, with sextortion schemes increasingly leading to fatal outcomes. The successful extradition demonstrates enhanced international cooperation in pursuing cybercriminals, while the tragic deaths underscore the urgent need for stronger digital protection measures and mental health support systems for online exploitation victims.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
PaperCut Zero-Day Exploitation: When Print Management Becomes a Gateway
Impact· HIGH

PaperCut Zero-Day Exploitation: When Print Management Becomes a Gateway

In August 2026, PaperCut Software issued an urgent security advisory warning of active zero-day exploitation targeting all versions of PaperCut NG and MF print management software. The company confirmed customer incidents involving Internet-exposed servers, with attackers exploiting an undisclosed vulnerability to gain initial access to corporate networks. PaperCut released emergency patches and provided indicators of compromise including suspicious pc-app.exe process activity and modified server.log files with specific database error patterns. The company has a documented history of being targeted by ransomware groups including Clop and LockBit who previously exploited PaperCut vulnerabilities for network access rather than direct document theft. This incident highlights the continued targeting of enterprise print management infrastructure as an attack vector, particularly relevant given the rise of ransomware groups exploiting Internet-facing business applications for initial compromise and the increasing sophistication of zero-day campaigns against widely-deployed enterprise software.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Cybercriminal 'The Com' Member Sentenced for Global Sextortion Crimes
Impact· HIGH

Cybercriminal 'The Com' Member Sentenced for Global Sextortion Crimes

In August 2026, Justin Swaddle, a 20-year-old from Leeds and member of the cybercriminal group 'The Com,' was sentenced to two years in prison for blackmail and sextortion offenses involving nearly 120 victims worldwide. Operating under aliases such as 'Epstein,' 'Rugen,' and 'Moscow' on platforms like Snapchat, Telegram, and Discord, Swaddle coerced victims, aged 13 to 17, into self-harm and the production of explicit content by threatening to expose their private information. The UK National Crime Agency (NCA) identified 117 female victims and discovered images of children as young as three on Swaddle's devices, some depicting acts he had incited. This case underscores the persistent threat posed by decentralized cybercriminal networks like 'The Com,' which exploit online platforms to target vulnerable individuals. The group's activities, including sextortion and the production of child sexual abuse material, highlight the urgent need for enhanced cybersecurity measures and public awareness to protect minors from such exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UK Man Sentenced for Exploiting Minors via 'The Com' Network
Impact· HIGH

UK Man Sentenced for Exploiting Minors via 'The Com' Network

In August 2026, 20-year-old Justin Swaddle from the United Kingdom was sentenced to two years in prison after pleading guilty to child sexual abuse offenses and blackmail. Operating under aliases such as 'Epstein,' 'Rugen,' and 'Moscow,' Swaddle was a member of 'The Com,' a decentralized cybercriminal network. He exploited social media platforms like Snapchat, Telegram, and Discord to target 117 female victims aged 13 to 17 across multiple countries, coercing them into providing explicit content under threat of exposing their personal information. ([en.wikipedia.org](https://en.wikipedia.org/wiki/The_Com?utm_source=openai)) This case underscores the evolving threat posed by 'The Com,' which has expanded from cybercrimes like SIM swapping and data breaches to more severe offenses, including sextortion and violence. The network's recruitment of minors and its use of sophisticated online platforms highlight the urgent need for enhanced cybersecurity measures and public awareness to protect vulnerable individuals from such exploitation. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2025/hacker-com-cyber-criminal-subset-of-the-community-is-a-rising-threat-to-youth-online?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Roblox Xeno Script Launcher Distributes Infostealer and RAT Malware
Impact· HIGH

Fake Roblox Xeno Script Launcher Distributes Infostealer and RAT Malware

In early 2026, a malicious campaign targeted Roblox players by distributing fake Xeno Executor installers, a popular tool for running scripts on the platform. Attackers promoted these counterfeit installers through gaming forums and Discord communities, enticing users with promises of an 'undetected' version to bypass Roblox's anti-cheat mechanisms. Upon execution, the fake installer deployed a multi-stage malware payload, culminating in a Java-based Remote Access Trojan (RAT) and information stealer. This malware exfiltrated browser data, targeted online accounts and payment information, accessed cryptocurrency wallets, and provided surveillance capabilities, including keylogging and webcam access. The campaign's sophistication and the malware's extensive capabilities underscore the evolving threats in the gaming community. This incident highlights a growing trend of cybercriminals exploiting popular gaming platforms to distribute advanced malware. The use of trusted community channels for dissemination and the malware's ability to perform comprehensive data theft and remote control operations reflect a significant escalation in threat actor tactics. As gaming platforms continue to attract large user bases, they become increasingly lucrative targets for such sophisticated attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Surge in Cyberattacks on Brazilian Educational Institutions: A 2025-2026 Analysis
Impact· CRITICAL

Surge in Cyberattacks on Brazilian Educational Institutions: A 2025-2026 Analysis

Between January 2025 and June 2026, Brazilian educational institutions experienced a significant rise in cyberattacks, predominantly ransomware incidents targeting both public and private entities. Notably, the DragonForce ransomware group claimed responsibility for an attack on Fundação Getulio Vargas in March 2026, threatening to release sensitive data unless their demands were met. Additionally, vulnerabilities like CVE-2025-8366 in the Portabilis i-Educar system exposed institutions to cross-site scripting attacks, compromising user data. These breaches led to operational disruptions, data encryption, and potential data exfiltration, highlighting the sector's vulnerability to cyber threats. ([dexpose.io](https://www.dexpose.io/dragonforce-ransomware-attack-targets-fundacao-getulio-vargas/?utm_source=openai)) The increasing frequency and sophistication of these attacks underscore the urgent need for enhanced cybersecurity measures within the education sector. With educational institutions holding vast amounts of sensitive data and often lacking robust security infrastructures, they have become prime targets for cybercriminals. This trend necessitates immediate action to bolster defenses, implement comprehensive incident response plans, and ensure compliance with data protection regulations to safeguard against future threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Europol's Crackdown on 'The Com' Network: 4,340 URLs Flagged for Removal
Impact· LOW

Europol's Crackdown on 'The Com' Network: 4,340 URLs Flagged for Removal

Between June and July 2026, Europol coordinated 'Referral Action Days' involving investigators from nine countries to target 'The Com,' a decentralized network of nihilistic violent extremist groups. This operation led to the identification and referral of 4,340 URLs containing content that promotes self-harm, child sexual exploitation, and violent attacks. The initiative aimed to disrupt The Com's online ecosystem and limit the dissemination of extremist propaganda. This crackdown underscores the persistent threat posed by decentralized extremist networks exploiting online platforms to radicalize and victimize individuals, particularly minors. The operation highlights the necessity for continuous international collaboration to monitor and mitigate the spread of such harmful content.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports