logo

Schools in Session: Surge in Phishing Attacks Targeting the Education Sector

ID: e9a560fa-94c7-5de7-9533-6019ea1f6958

STIX ID: report--e9a560fa-94c7-5de7-9533-6019ea1f6958

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2025-03-04

Date Updated: 2026-04-28

Author: Martin Kraemer

...
...

KnowBe4 Threat Lab observed a large-scale phishing campaign against the education sector that used QR codes, embedded links, and Google Forms to harvest credentials; over a 30-day period 4,361 threats were reported from 40 sender domains (26 compromised educational institution IDs), many of which bypassed Exchange Online Protection. The report details delivery vectors (plain links, attachments with embedded links, PDFs with QR codes), campaign characteristics, impact risks (credential compromise and subsequent phishing/data loss), and recommends security awareness training, email security enhancements, and ongoing monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.