Ransomware data breaches soar in the U.S., affecting K12 and higher ed privacy

Date:

Share post:

Ransomware attacks on K12 districts, colleges and other educational institutions across the globe reached 251 in 2025, a slight uptick over the year prior. The vast majority of the incidents occurred in the U.S., according to an analysis by Comparitech.

The U.K.-based technology research company tallied 130 attacks on U.S. schools, which accounts for over half of all ransomware activity logged on the global education sector. The U.K. ranked second with 12, followed by France, Brazil and Japan, each with nine.

Attacks on American schools fell slightly over the last year, yet ransomware gangs infiltrated 3.89 million records from the U.S. That’s more than 98% of all reported stolen data, including personal identifying information and financial information. The number of global data records breached increased by 27%.

More individuals may have been affected than this report suggests. Comparitech only reported data provided by government websites.


Cybersecurity risk: Hidden vulnerabilities in student data collection


Eight of the 10 largest ransomware data breaches in education last year occurred in the U.S. The biggest was at the University of Phoenix in August, where nearly 3.5 million people were affected. Dartmouth College (99,596) and the University of Pennsylvania (46,491) round out the top three.

Universities could do little to defend themselves in these attacks. Russian ransomware syndicate Cl0p exploited a vulnerability in Oracle’s E-Business Suite platform, which allowed the gang to access critical information from business customers without authentication.

Harvard University was also reportedly breached in October, which exposed 1.3 terabytes of archive files, SecurityWeek reports.

Cl0p’s five confirmed attacks—including Wits University in South Africa—breached over 3.6 million records, more than 90% of all Comparitech’s confirmed reports.

In 2023, Cl0p successfully compromised nearly 900 colleges after gaining access to a third-party service used by the National Student Clearinghouse and TIAA, a retirement financial service used by faculty.

The fourth-most impactful ransomware attack globally was at Cherokee County School District in Georgia, where over 46,000 people were affected. Nearly 624 gigabytes of data were allegedly stolen.

Four other U.S. schools, K12 districts and colleges were in the top 10, including:

  • Madison Elementary School District 38 (Az.): 35,000 affected
  • Clackamas Community College (Ore.): 33,381 affected
  • Institute of Culinary Education: 33,342 affected
  • School District Five of Lexington and Richland Counties (S.C.): 31,475 affected
Alcino Donadel
Alcino Donadel
Alcino Donadel is editor at University Business covering college leadership, enrollment, and career readiness since 2023. He is a first-generation journalism graduate from the University of Florida with triple citizenship from the U.S., Ecuador, and Brazil. Find Alcino on LinkedIn or email him at [email protected].

The Always-On Insight and Networking Platform for Superintendents and Their Teams

AI-driven insights peer-to-peer collaboration and more build exclusively fot K-12 Superintendents and thier leaders
Built for the uniqueness of the superintendent role and their supporting team.Most platforms treat all K–12 leaders the same. DA+ recognizes that superintendents face a unique level of pressure, complexity, visibility, and responsibility—and gives them a space designed specifically for the demands of the top job.
A community where you don’t have to explain the context.Skip the backstory. DA+ understands the job, the politics, the stakes, and the pace.
Your decisions shape communities.Find the tools and peer insight to make them with confidence here.
Leadership tailored to the realities of running a district.From board relations to budgets, crisis response to community trust—DA+ focuses on the challenges only superintendents navigate each day.
Built for superintendents.Powered by superintendents. Trusted by superintendents. If you run a district, you belong here.

Related Articles