The education sector remains a primary target for ransomware and credential theft, driven by a combination of high-value data and chronically underfunded IT infrastructure. While human error, such as password reuse, remains a persistent issue, the threat landscape has shifted with the rise of AI. Phishing attempts now mirror legitimate communications from university leadership, and deepfake technology is increasingly used to impersonate staff. Research indicates that 41% of institutions have already been targeted by AI-generated misinformation campaigns.
Beyond human accounts, a growing security gap exists in Non-Human Identities (NHIs). These include service accounts, API keys, and automated agents that bridge various learning management systems. These digital identities often lack oversight, with many institutions failing to maintain an inventory of active credentials. To mitigate these risks, Keeper Security recommends that IT teams enforce multi-factor authentication, conduct audits of privileged access, and establish automated rotation policies for machine credentials before the academic term begins.

Comments (0)
No comments yet. Be the first!