![]()
SonicWall Research Issues Education Cybersecurity Report Card as Attackers Exploit the Industry’s Most Open Networks
PR Newswire
MILPITAS, Calif., Sept. 2, 2026
New Education Protect Brief reveals 81,879 IPS hits per device, the highest attack intensity of any tracked industry
MILPITAS, Calif., Sept. 2, 2026 /PRNewswire/ — SonicWall today released its 2026 Education Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report. The report found that education recorded the highest per-device attack intensity of any tracked vertical in the first half of 2026, with a single VoIP exploitation signature accounting for more than half of all intrusion prevention events across the sector.
Every year, attacks look more sophisticated. AI has made them faster and more difficult to spot. But the fundamental methods have not changed, and in education, the doors are uniquely difficult to close. University campuses and school districts run networks that are, by function, open: student devices, faculty research systems, public-facing portals, third-party learning platforms, and administrative databases sharing the same infrastructure. Bring your own device (BYOD) isn’t an opt-in security policy for higher education; it’s the fundamental baseline of their network architecture.
“Education has the most exposed attack surface of any industry we track, and the data shows attackers know it,” said Michael Crean, SonicWall SVP of Managed Services. “Education endpoints endure the heaviest per-device attack pressure in our entire dataset. Unlocked network doors remain the operating reality, and threat actors are actively taking advantage.”
Key Findings from the 2026 SonicWall Education Protect Brief
- Education recorded 81,879 IPS hits per device in the first half of 2026, the highest per-device attack intensity of any tracked vertical.
- SIPVicious VoIP exploitation generated 90 million combined hits, claiming both the #1 and #2 spots on education’s attack signature list and accounting for 50.5% of all IPS events in the sector, a concentration no other vertical approaches.
- Education recorded 16,242 malware hits per device, nearly 3.5 times the rate seen in retail.
- The Hikvision IP camera command injection vulnerability, disclosed in 2021, was detected on 605 devices, spanning 28% of all education networks in the dataset.
- Apache Log4j2 generated 6.7 million hits, indicating learning management and administrative middleware still running vulnerable software in 2026.
- Forty-four education organizations detected active ransomware campaigns in the first half of 2026, including the enterprise-grade Ryuk family operating alongside more opportunistic threats.
Half the Class Is Failing the Same Subject
The 90 million SIPVicious hits are not a collection of isolated, minor incidents—they represent the systematic exploitation of a massive, unhardened attack surface. Legacy Voice over Internet Protocol (VoIP) systems deployed across thousands of campus endpoints offer attackers an easy foothold. And a compromised Session Initiation Protocol (SIP) line isn’t just a toll-fraud issue: these systems sit on the exact same networks that house student health records, financial aid data and proprietary research.
“Half of all attacks against education are going after one thing, and it isn’t the thing most districts are budgeting to defend,” continued Crean. “Firewalls are essential perimeter security, but they can’t defend what they aren’t configured to inspect. Leaving legacy SIP endpoints unhardened inside the network negates the investment at the perimeter.”
An Old Vulnerability Still Passes Every Test
Education’s exposure extends far beyond VoIP. Five years after its disclosure, the 2021 Hikvision command injection vulnerability still sits unpatched on more than a quarter of education networks. Because campus cameras share network access with administrative, financial, and research environments, a compromised device offers a direct pivot into core systems.
Combined with 2.5 million MongoBleed hits against research and LMS backends, the data highlights years of unaddressed technical debt. Ransomware actors have priced this reality in: while overall volume remains low, 75.7% of hits stem from concentrated, targeted intrusions against regulated student records and irreplaceable, grant-funded research.
The Architecture Problem Has a Known Solution
Zero Trust addresses the structural issue directly: verification is applied continuously rather than once at the perimeter, so a credential from a student who graduated two years ago does not quietly retain network access, and a compromised login reaches only the application it was issued for, not the research database or the camera management interface.
“The highest per-device attack intensity of any vertical we track requires a security model built for it, not a patched-together version of what worked for a smaller, less open network,” said Crean. “Education doesn’t need to close its doors to be secure. It needs to know who’s walking through them.”
To learn more, visit SonicWall at www.sonicwall.com.
About SonicWall
SonicWall is a partner-first unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments. For more than 30 years, SonicWall has championed a partner-first model that combines purpose-built technology, cloud-delivered security services and real-time threat intelligence to help businesses prevent breaches, reduce risk and stay operational in the face of evolving modern threats. We are committed to deliver the best security outcomes for our customers where others deliver features and functions. Through its unified cybersecurity portfolio and global community of over 17,000 partners, SonicWall enables managed service providers to actively manage, continuously optimize and measurably protect networks, cloud environments, endpoints and applications. The company is redefining cybersecurity around outcomes that matter to business leaders, including breach prevention, compliance achievement, cost efficiency and reduced human error, because protection is not about what a product can do but about what it actually delivers.
View original content to download multimedia:https://www.prnewswire.com/news-releases/sonicwall-research-issues-education-cybersecurity-report-card-as-attackers-exploit-the-industrys-most-open-networks-302867053.html
SOURCE SonicWall
