Education Accounts for 7.3% of Cybersecurity Incidents Across Industries in 2022, Up from 2.8% in 2021

IBM Security, releasing its annual X-Force Threat Intelligence Index for 2023, noted that education, sixth on the list of 10 industries analyzed, jumped from 2.8% of all incidents in 2021 to 7.3% in 2022. The company noted it changed how it examined some of its data to give a more insightful and helpful picture of cybersecurity threats. Key threat highlights in the report include backdoor activity, extortion, phishing, and hacktivism/malware.

Across industries in 2022, extortion attacks accounted for 27% of incidents, deployment of backdoor access 21%, and ransomware attacks 17%. Although there was a 52% drop in phishing seeking credit card data, overall 41% of initial access incidents involved phishing, IBM said, with 62% of those using spear fishing attachment tactics.

In education alone, IBM Security X-Force responded to the following attacks:

  • Exploitation of public-facing applications on initial access (42% of incidents);
  • Spear fishing attachments (25%);
  • Data theft, extortion, and reconnaissance impacts (25% each);
  • Backdoor attacks (20%);
  • Ransomware, adware, and spam (13% each); and
  • Phishing (through service, link, and valid cloud and local account abuse) (8% each).

The company noted that the highest number of attacks were directed at Asia-Pacific areas (67%), followed by North America (27%) and Latin America (6%).

IBM Security gave several recommendations: Manage critical data assets to reduce exposure to attack; include source code, credentials, and other data that could already be out on the web in asset management programs; immediately act on threat intelligence; be prepared for attacks with flexible incident response plans; and have a reputable and competent IR vendor on retainer to help plan, test, and enact incident responses.

"Attacks are inevitable; failure doesn't have to be," the report concluded. "Organizations should develop incident response plans customized for their environment."

To read keynotes of the report, watch video discussions of specific insights, and register to download the report, visit the Threat Intelligence Index 2023 page.

IBM Security X-Force is a team of hackers, responders, researchers, and analysts who provide cybersecurity services. To learn more, visit the X-Force page.

About the Author

Kate Lucariello is a former newspaper editor, EAST Lab high school teacher and college English teacher.

Featured

  • Blue Cloud Floating on Top of Circuit Board

    Survey: Organizations Moving AI Workloads Away from Public Cloud

    A new Cloudera survey of 1,500 enterprise technology leaders found widespread AI-driven architecture changes, with governance problems, rising infrastructure costs, and workload placement pushing organizations toward more hybrid approaches.

  • Minimalist binary data fragmentation

    Fragmented Data Is Quietly Undermining Student Success and Cybersecurity Hygiene

    Siloed tools, teams, budgets, and resources spread across departments and campuses generate massive amounts of data. However, fragmentation creates unnecessary exposure to security threats and inadvertently reduces student support because no one can see the whole picture.

  • Abstract background with digital shield made of data particles glowing blue blocking against cyber attacks

    Report: AI Attacks Push Organizations Toward Autonomous Cybersecurity Defense

    Artificial intelligence is raising the stakes of cyber conflict as attackers use the technology to accelerate reconnaissance, uncover vulnerabilities, and launch attacks faster than many security teams can respond.

  • circuit patterns

    Anthropic Launches Lower-Cost Claude Sonnet 5

    Anthropic has released Claude Sonnet 5, positioning the model as its most autonomous mid-tier offering to date and a lower-cost alternative to its flagship Opus 4.8 system. The company said the model can plan multi-step tasks, operate tools such as browsers and terminals, and complete agentic work at a level that previously required larger and more expensive models.