India, Aug. 31 -- Ransomware attacks against education institutions are increasingly beginning with compromised identities rather than attacks directly targeting network infrastructure, highlighting a security gap that becomes more difficult to address as attackers use phishing, stolen credentials and other identity-based techniques.

Sophos' State of Ransomware in Education 2026 report found that identity-based attack techniques were involved in 85% of ransomware incidents reported by education institutions. This was higher than the 79% recorded across sectors.

The findings suggest that the traditional focus on protecting networks and endpoints needs to be matched by stronger controls around user identities, particularly as education in...