Threat Research

SonicWall Research Issues Education Cybersecurity Report Card as Attackers Exploit the Industry's Most Open Networks

New Education Protect Brief reveals 81,879 IPS hits per device, the highest attack intensity of any tracked industry

MILPITAS, Calif. – September 2, 2026 – SonicWall today released its 2026 Education Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report. The report found  that education recorded the highest per-device attack intensity of any tracked vertical in the first half of 2026, with a single VoIP exploitation signature accounting for more than half of all intrusion prevention events across the sector.

Every year, attacks look more sophisticated. AI has made them faster and more difficult to spot. But the fundamental methods have not changed, and in education, the doors are uniquely difficult to close. University campuses and school districts run networks that are, by function, open: student devices, faculty research systems, public-facing portals, third-party learning platforms, and administrative databases sharing the same infrastructure. Bring your own device (BYOD) isn't an opt-in security policy for higher education; it’s the fundamental baseline of their network architecture.

"Education has the most exposed attack surface of any industry we track, and the data shows attackers know it," said Michael Crean, SonicWall SVP of Managed Services. “Education endpoints endure the heaviest per-device attack pressure in our entire dataset. Unlocked network doors remain the operating reality, and threat actors are actively taking advantage.”

Key Findings from the 2026 SonicWall Education Protect Brief

  • Education recorded 81,879 IPS hits per device in the first half of 2026, the highest per-device attack intensity of any tracked vertical.
  • SIPVicious VoIP exploitation generated 90 million combined hits, claiming both the #1 and #2 spots on education's attack signature list and accounting for 50.5% of all IPS events in the sector, a concentration no other vertical approaches.
  • Education recorded 16,242 malware hits per device, nearly 3.5 times the rate seen in retail.
  • The Hikvision IP camera command injection vulnerability, disclosed in 2021, was detected on 605 devices, spanning 28% of all education networks in the dataset.
  • Apache Log4j2 generated 6.7 million hits, indicating learning management and administrative middleware still running vulnerable software in 2026.
  • Forty-four education organizations detected active ransomware campaigns in the first half of 2026, including the enterprise-grade Ryuk family operating alongside more opportunistic threats.

Half the Class Is Failing the Same Subject

The 90 million SIPVicious hits are not a collection of isolated, minor incidents—they represent the systematic exploitation of a massive, unhardened attack surface. Legacy Voice over Internet Protocol (VoIP) systems deployed across thousands of campus endpoints offer attackers an easy foothold. And a compromised Session Initiation Protocol (SIP) line isn't just a toll-fraud issue: these systems sit on the exact same networks that house student health records, financial aid data and proprietary research.

"Half of all attacks against education are going after one thing, and it isn't the thing most districts are budgeting to defend," continued Crean. "Firewalls are essential perimeter security, but they can’t defend what they aren't configured to inspect. Leaving legacy SIP endpoints unhardened inside the network negates the investment at the perimeter.”

An Old Vulnerability Still Passes Every Test

Education's exposure extends far beyond VoIP. Five years after its disclosure, the 2021 Hikvision command injection vulnerability still sits unpatched on more than a quarter of education networks. Because campus cameras share network access with administrative, financial, and research environments, a compromised device offers a direct pivot into core systems. 

Combined with 2.5 million MongoBleed hits against research and LMS backends, the data highlights years of unaddressed technical debt. Ransomware actors have priced this reality in: while overall volume remains low, 75.7% of hits stem from concentrated, targeted intrusions against regulated student records and irreplaceable, grant-funded research.

The Architecture Problem Has a Known Solution

Zero Trust addresses the structural issue directly: verification is applied continuously rather than once at the perimeter, so a credential from a student who graduated two years ago does not quietly retain network access, and a compromised login reaches only the application it was issued for, not the research database or the camera management interface.

"The highest per-device attack intensity of any vertical we track requires a security model built for it, not a patched-together version of what worked for a smaller, less open network," said Crean. "Education doesn't need to close its doors to be secure. It needs to know who's walking through them."

To learn more, visit SonicWall at www.sonicwall.com.  

About SonicWall
SonicWall is a partner-first unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments. For more than 30 years, SonicWall has championed a partner-first model that combines purpose-built technology, cloud-delivered security services and real-time threat intelligence to help businesses prevent breaches, reduce risk and stay operational in the face of evolving modern threats. We are committed to deliver the best security outcomes for our customers where others deliver features and functions. Through its unified cybersecurity portfolio and global community of over 17,000 partners, SonicWall enables managed service providers to actively manage, continuously optimize and measurably protect networks, cloud environments, endpoints and applications. The company is redefining cybersecurity around outcomes that matter to business leaders, including breach prevention, compliance achievement, cost efficiency and reduced human error, because protection is not about what a product can do but about what it actually delivers. 

Latest Stories

  • SonicWall、新しいNSv XS仮想ファイアウォールでGen 8プラットフォームをクラウドに拡張し、ワークロードが実行されるあらゆる場所でMSPとMSSPがマネージドセキュリティを提供できるように支援
    カリフォルニア州ミルピタス — 2026年5月12日 — SonicWallは本日、Gen 8 NSv XSの提供を発表しました。Gen 8 NSv XSは、小規模環境や分散環境にマネージドセキュリティを提供するMSPやMSSP専用に設計されたサブスクリプションベースの仮想ファイアウォールです。パートナーは、これまで物理的な境界に提供してきたGen 8による保護を、継続的収益を考慮した価格帯で仮想...
    Read More
  • SonicWall、年次調査を中小企業の保護の成果を軸に再構築――2026年版サイバー保護レポートで「七つの大罪」を明らかに
    カリフォルニア州ミルピタス —2026年3月31日 — SonicWallは本日、2026年版SonicWallサイバー保護レポートのリリースを発表しました。本レポートは、従来の脅威レポートから、ビジネスリーダーにとって非常に重要な事項である保護の成果を重視する内容へと大きく転換するものです。レポートの中心となっているのは、真剣な対応が求められる調査結果です。ほとんど...
    Read More
  • SonicWall、SecureFirstパートナープログラムを更新し、パートナーの成長と収益性を促進する新たなイネーブルメント施策を提供
    カリフォルニア州ミルピタス — 2026年3月12日 — SonicWallは本日、SecureFirstパートナープログラムに対する重要な更新を発表しました。この更新は、新たなイネーブメント施策を導入し、パートナーが運用の複雑さや人員の増加を伴うことなく、予測可能な成長を促進し、継続的な収益を拡大し、より強力なサイバーセキュリティの成果を顧客に提供できるよ...
    Read More