Scott County, Kentucky, schools were recently hit with a $3.7 million phishing scam. According to Superintendent Dr. Kevin Hub, a vendor reported that an invoice sent to the district’s schools had not been paid. Upon investigating the matter, the district discovered that someone else had been paid instead, via a fake email masquerading as a vendor.

The Scott County School incident is not an isolated incident among educational institutions. Out of 17 major industries, the education sector ranks as the worst in terms of cybersecurity. That's according to a report published by SecurityScorecard, a New York-based IT security firm. SecurityScorecard's research shows that there is a significant risk to students.
First, vast amounts of personal student data are being stored on school networks, including academic, health, and financial data. The education industry is also failing to take many of the necessary steps to protect students from cyberattacks. In its Global Education Security Report (2018), SecurityScorecard found that the top areas of cybersecurity weakness are application security, endpoint security, and network security.
University networks are particularly vulnerable to cyberattacks, says Sam Kassoumeh, chief operating officer and co-founder of SecurityScorecard. “There’s a big issue of data exposure at a university. There are thousands of devices distributed across a campus.”
Additionally, students often use more than one device in and out of the classroom, with varying degrees of security applied to the devices. The lack of cybersecurity resources is prevalent in the education sector and is affecting the size and quality of school IT departments.
Ed Hudson, chief information officer for the Information Security Information Service at California State University, told EdScoop: “I think Higher Education Cybersecurity is unlike any other industry.” He noted that the education sector has enough open networks to meet the needs of faculty and students. “The cybersecurity challenge is a constant balancing act of providing the most secure environment possible while also making it more open to facilitate academic research,” Hudson said.
Data shows that a U.S. is the victim of a cyberattack about every three days. Cyber incidents range from data breaches to phishing scams to ransomware attacks. Many of the incidents are extremely serious, resulting in millions of dollars in theft, identity theft or the destruction of school records.
In Malwarebytes' 2019 State of the Industry report, the education sector is revealed to be consistently one of the top 10 industries targeted by cybercriminals.
The following are a series of recent attacks on schools:
- Also reported by Bleeping Computer, “some parents of students attending St Lawrence College in Ramsgate were targeted by scammers. According to the school, parents received emails offering discounts for the spring and summer months if they agreed to send the money in advance. The scammers used a common email scam attack, promising their victims some quick paydays if they took advantage of the discounts.”
- Earlier this month, Georgia Tech announced that it was the target of a cyberattack in which its databases were compromised and the personal information of approximately 1.3 million current and former students, employees and applicants was stolen.
- Washington State University has agreed to hand over up to $4.7 million to settle a lawsuit filed after a hard drive containing the personal information of more than a million people was removed from a storage facility in 2017. The stolen hard drive contained addresses, Social Security numbers, career information, health data and college entrance exam scores.
- In Nevada, Clark County School District police are investigating a suspected hacking attempt on Foothill High School's Twitter account.
- According to CBS New York, two young students from Secaucus High School in New Jersey were detained after hacking into the school's Wi-Fi system because they didn't want to take a test.
- A former student at the College of Saint Rose in Albany, New York, Vishwanath Akuthota, hacked into over 50 college computers with a “Killer USB.”.
The poor state of cybersecurity in schools is further complicated by the fact that students are typically more skilled than teachers. So, even if restrictions are in place, many students are able to bypass them and compromise security.
There is also a potential risk when students engage in certain technological behaviors, such as using Vault apps. Vault apps provide cover for accessing the darknet, where they can pay a hacker to change their grades or purchase academic documents, fake IDs, or a gun.
