EDUCATION
Overview
Over the last couple of years, the educational sector underwent a shift from physical classes to remote online learning, due to which it faced an unprecedented number of cyberattacks.
According to Microsoft, education is the sector most exposed to malware threats globally, accounting for about 62% (over 5 million) of total reported malware contacts in the last 30 days. The average number of attacks on US-based education organizations grew by 30% in August 2020, compared to 6.5% across all sectors. Between 2019 and 2020, the number of ransomware attacks against higher education institutions in the world doubled.
Educational institutions deal with a lot of data and have access to personal, financial, and health-related information of both students and employees. They are, therefore, exposed to cybersecurity concerns. Students and professors are frequently targeted by cybercriminals, who send fraudulent emails from the institution’s legitimate domain, requesting login access, sensitive personal information, and money transfers.
250ok conducted an analysis of 3,614 top-level domains controlled by authorized US colleges and universities in February 2018. The study’s focus was on DMARC adoption, which is an email authentication, policy, and reporting system that helps enterprises prevent domain spoofing. It is worth mentioning that a significant proportion of organizations use a subdomain for some of their communication. Leaving the root domain unprotected, on the other hand, invites spoofing, phishing, and mail forging.
Educational institutions that are entrusted with the safety of their students should have a solid cybersecurity infrastructure that eliminates all risks and possibilities of a breach. These institutions must recognize that cybersecurity is critical not only to protect from financial loss but also to safeguard their students from danger.

Recent cyberattacks on the educational sector
- In February 2021, the cyberattack on Simon Fraser University in British Columbia provided the hacker with access to a server storing sensitive information such as student and staff ID numbers, admissions information, and other academic records. The cyberattack impacted around 200,000 individuals in total.
- In March 2021, the Harris Federation in London suffered a ransomware attack that forced it to temporarily shut the gadgets and email systems of all 50 secondary and primary schools under its supervision.
- According to Forbes, a cyber attack hit Oxford University’s Division of Structural Biology in February 2021.
- According to BBC, after the NetWalker ransomware shut down many systems at the University of California, San Francisco’s School of Medicine, in June 2020, the university paid a $1.14 million ransom to get its systems back and running.
- Quebec’s Minister of Education acknowledged in February 2020 that hackers had stolen personal information of 360,000 teachers and ex-teachers.
- According to a report published in July 2020, 54 % of the UK’s universities disclosed a data breach to a regulator. Despite the fact that the country’s post-secondary institutions are home to over 2.3 million students and 430,000 employees, research states that 46% of university employees did not obtain security training in the year leading up to the publication.
- Blackbaud hack, a ransomware attack that was first revealed in the summer of 2020, is a serious data breach that crossed international borders.
- After hackers hacked a cloud computing provider, data regarding students and/or alumni were stolen from at least ten universities in the United Kingdom, the United States, and Canada.

Educational Industry DMARC Adoption
- Only six of the top 200 U.S. institutions in the 2020 WSJ/THE College Rankings had DMARC enabled and configured to reject suspicious emails, according to a report.
- Domains owned by almost 90% of top-level educational institutions lack even the most basic DMARC policy, putting students, parents, alumni, and workers in danger of phishing attempts.
- A DMARC policy was found on 11.2% of all ‘.edu’ domains examined.
- Only.4% of the ‘.edu’ domains examined had a reject policy, which is the gold standard of DMARC.
- 58% of the 200 colleges and universities surveyed did not have a DMARC record in place.
- According to validity.com, while only 0.4% of ‘.edu’ domains that were analyzed have a reject policy, 250ok is collaborating with numerous schools and universities, including the University of Kentucky, to further secure their domains and safeguard their stakeholders.
- According to a 2018 survey, only 11% of 3,600 domains belonging to prominent US colleges had a published DMARC policy, let alone enforcement.

How Can EmailAuth Help?
EmailAuth, through DMARC’s implementation, gives companies and organizations guaranteed security and complete control of their email domains. However, it has other advantages too. Read more about them in detail here.
EmailAuth also provides a free DMARC Record Checker to display your record, test it, and verify its validity. For a DMARC record check, all you need to do is provide your domain name. The tool will then analyze and display your record along with other important information on your domain’s usage.
Similarly, you can verify your DKIM and SPF records using EmailAuth’s free and automated tools: DKIM Record Checker and SPF Record Checker.
In case you don’t have a DMARC record published for your domain, you can use EmailAuth’s DMARC Record Generator to generate a record instantly.