Education Accounts for 7.3% of Cybersecurity Incidents Across Industries in 2022, Up from 2.8% in 2021

IBM Security, releasing its annual X-Force Threat Intelligence Index for 2023, noted that education, sixth on the list of 10 industries analyzed, jumped from 2.8% of all incidents in 2021 to 7.3% in 2022. The company noted it changed how it examined some of its data to give a more insightful and helpful picture of cybersecurity threats. Key threat highlights in the report include backdoor activity, extortion, phishing, and hacktivism/malware.

Across industries in 2022, extortion attacks accounted for 27% of incidents, deployment of backdoor access 21%, and ransomware attacks 17%. Although there was a 52% drop in phishing seeking credit card data, overall 41% of initial access incidents involved phishing, IBM said, with 62% of those using spear fishing attachment tactics.

In education alone, IBM Security X-Force responded to the following attacks:

  • Exploitation of public-facing applications on initial access (42% of incidents);
  • Spear fishing attachments (25%);
  • Data theft, extortion, and reconnaissance impacts (25% each);
  • Backdoor attacks (20%);
  • Ransomware, adware, and spam (13% each); and
  • Phishing (through service, link, and valid cloud and local account abuse) (8% each).

The company noted that the highest number of attacks were directed at Asia-Pacific areas (67%), followed by North America (27%) and Latin America (6%).

IBM Security gave several recommendations: Manage critical data assets to reduce exposure to attack; include source code, credentials, and other data that could already be out on the web in asset management programs; immediately act on threat intelligence; be prepared for attacks with flexible incident response plans; and have a reputable and competent IR vendor on retainer to help plan, test, and enact incident responses.

"Attacks are inevitable; failure doesn't have to be," the report concluded. "Organizations should develop incident response plans customized for their environment."

To read keynotes of the report, watch video discussions of specific insights, and register to download the report, visit the Threat Intelligence Index 2023 page.

IBM Security X-Force is a team of hackers, responders, researchers, and analysts who provide cybersecurity services. To learn more, visit the X-Force page.

About the Author

Kate Lucariello is a former newspaper editor, EAST Lab high school teacher and college English teacher.

Featured

  • open laptop in a college classroom with holographic AI icons like a brain and data charts rising from the screen

    4 Ways Universities Are Using Google AI Tools for Learning and Administration

    In a recent blog post, Google shared an array of education customer stories, showcasing ways institutions are using AI tools like Gemini and NotebookLM to transform both learning and administrative tasks.

  • illustration of a human head with a glowing neural network in the brain, connected to tech icons on a cool blue-gray background

    Meta Launches Stand-Alone AI App

    Meta Platforms has introduced a stand-alone artificial intelligence app built on its proprietary Llama 4 model, intensifying the competitive race in generative AI alongside OpenAI, Google, Anthropic, and xAI.

  • three main icons—a cloud, a user profile, and a padlock—connected by circuit lines on a blue abstract background

    Report: Identity Has Become a Critical Security Perimeter for Cloud Services

    A new threat landscape report points to new cloud vulnerabilities. According to the 2025 Global Threat Landscape Report from Fortinet, while misconfigured cloud storage buckets were once a prime vector for cybersecurity exploits, other cloud missteps are gaining focus.

  • Stylized illustration showing cybersecurity elements like shields, padlocks, and secure cloud icons on a neutral, minimalist digital background

    Microsoft Announces Security Advancements

    Microsoft has announced major security advancements across its product portfolio and practices. The work is part of its Secure Future Initiative (SFI), a multiyear cybersecurity transformation the company calls the largest engineering project in company history.