Report: Ransomware Costs Schools Nearly $550,000 per Day of Downtime

New data from cybersecurity research firm Comparitech quantifies the damage caused by ransomware attacks on K-12 and higher education institutions.

Since 2018, the company has clocked nearly 500 separate ransomware attacks aimed at schools and universities in the United States, affecting the data of over 6.7 million individuals.

It found the average ransomware demand is $1.4 million, though the average ransomware payment is leagues smaller, less than $170,000. 

On average, each of these ransomware attacks caused nearly 11 days of downtime, with each missed day costing schools nearly $550,000.

All told, according to Comparitech's data, ransomware has cost the U.S. education system over $2.5 billion since 2018.

The ransomware landscape was particularly rough in 2023, which had a record-breaking 121 attacks. However, 2024 — at least, so far — has provided a slight reprieve. The rate of attacks this year has considerably slowed, and both the duration and cost of downtime have seen a noticeable decline.  

"Hackers often target schools in the latter part of the year, so it's possible we will see an uptick in ransomware attacks on educational institutions for 2024, but it's unlikely the figures will reach 2023's high," Comparitech said in a post detailing its findings.

However, the company warned that attackers seem to be more discerning, increasingly going for institutions with bigger budgets and larger troves of student data. With attacks becoming more sophisticated and targeted, Comparitech urged readiness.

"With the threat of ransomware attacks across the U.S. and worldwide remaining high across all industries, it's never been more important to ensure employees are clued up, systems are updated, and frequent backups are being carried out," the company said.

About the Author

Gladys Rama (@GladysRama3) is the editorial director of Converge360.

Featured

  • digital lock

    CoSN: Cybersecurity and Data Privacy Remain Top AI Concerns in Education

    A leading concern for education technology leaders across the United States is the potential for AI to enable new forms of cyber attacks, according to the latest State of Ed Tech report from CoSN.

  • lock symbol with quantum bits in dynamic motion

    Microsoft Accelerates Quantum-Safe Security Timeline

    Microsoft is speeding up its quantum-safe security timeline, noting that advances in quantum computing and new federal requirements have pushed post-quantum cryptography from a future planning issue into an immediate engineering priority.

  • large cloud icon on the right in an abstract world above a polygon with a dark blue background

    Cloud Security Alliance Expands Agentic AI Governance Work

    The Cloud Security Alliance (CSA) has announced a series of CSAI Foundation milestones aimed at securing what it calls the agentic control plane, including a new catastrophic risk initiative, CVE Numbering Authority authorization, and the acquisition of two agentic AI specifications.

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.