Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Intensify Against Universities Worldwide

University building with locked computer screens and concerned students in background.
"This H1 report yet again emphasizes the impact one group can have on the threat landscape," said Rebecca Moody, head of data research at Comparitech.

The Gentlemen’s outsized impact on higher education

Comparitech’s Education Ransomware Roundup for the first half of 2026 identifies a single group — The Gentlemen — as a principal driver of rising ransomware activity against universities. The gang’s attacks on education rose 275% in H1 2026 compared with the second half of 2025, and 80% of The Gentlemen’s attacks against the education sector were directed at colleges and universities. That concentration, the report argues, explains why attacks against higher education increased even as overall recorded incidents across the broader education sector declined.

Scope and scale: numbers and geographic spread

Comparitech counted 104 ransomware attacks on the global education sector during the first half of 2026. Of those incidents, 36 were confirmed as ransomware by the victim organizations. While the total number of recorded incidents across education fell — driven by a one-quarter decrease in attacks against primary and secondary schools — higher education experienced an 8% rise in attacks in H1 2026 compared with the previous six months.

The report shows the problem is international: establishments in the United States were the largest single group of confirmed victims, with 34; the United Kingdom and Brazil accounted for 13 and 8 confirmed victims respectively. Universities in 17 additional countries also reported at least one confirmed ransomware incident during the period.

Who is claiming responsibility

Comparitech’s data lists the most prolific perpetrators claiming attacks against education in H1 2026. The Gentlemen and Qilin each claimed 15 attacks; LockBit claimed 9; and Interlock and Nova claimed 6 apiece. That distribution places both large, named operations and smaller gangs in the picture, but The Gentlemen’s recent focus on colleges and universities stands out in the dataset.

Ransom demands, data theft, and the Mount Royal case

Attack economics shifted upward in the first half of 2026. The median ransom demand issued to victim organizations in the education sector was $420,620 — a 53% increase from the median of $275,000 recorded in the second half of 2025. The largest single demand in H1 2026 was $1.9 million, issued following an attack on Mount Royal University in Canada.

That incident remained disruptive a month after the attack: the university’s systems were still impacted, attackers claimed to have stolen over 10TB of data, and, according to Comparitech, "The hackers also deleted entire drives of data, which hasn't just impeded the college's ability to recover from the attack but means some data may be completely unrecoverable, too," Moody said. The Mount Royal example underscores that ransomware incidents can involve not only encryption and extortion but also large-scale data theft and destructive deletion.

How technologists, policymakers, and university leaders will respond

  • Technologists and security teams: The rise in median demands and the reported deletion of entire drives at Mount Royal highlight two pressure points — the financial scale of extortion and the risk of irrevocable data loss. Security teams will watch the concentration of The Gentlemen’s targeting of higher education and the mix of claims from other groups (Qilin, LockBit, Interlock, Nova) as they prioritize detection, backup integrity, and incident recovery capabilities.
  • Policymakers and regulators: With U.S. institutions the most frequently confirmed victims in the dataset (34 confirmed victims), regulators and oversight bodies may focus on reporting requirements, incident disclosure timelines, and guidance related to ransom payments — especially in light of rising median demands and high-profile, high-value claims like the $1.9m demand at Mount Royal.
  • University leaders and administrators: The data points to a sector-specific shift: higher education saw an increase even while primary and secondary schools registered fewer incidents. University decision-makers will need to account for concentrated adversary interest, the elevated size of ransom demands, and the operational consequences of long-lasting system impacts and potential irreversible data deletion.

Comparitech’s H1 2026 roundup identifies a simple but consequential fact: a single gang’s targeting choices can change the appearance of a threat landscape. Whether The Gentlemen’s focus continues to drive higher education’s risk profile — and whether median demands and destructive tactics will keep rising — are the immediate questions university leaders, security teams, and regulators must confront as they plan responses and allocate resources.

Original story