Analysis finds that nearly three dozen ransomware attacks have targeted US school districts educating 700,000+ students since the pandemic began in March
Districts around the U.S. are fighting a wave of increasingly aggressive hackers, who are publicly posting sensitive student information
Context & Ripple Effects
Schools were already a proven target before COVID: Armor counted over 500 US schools and colleges hit by ransomware in 2019, including 100 schools across fifteen districts in a single two-week span. What changed by November 2020 is scale and tactics — the pandemic pushed instruction onto district networks, and this analysis finds nearly three dozen districts serving 700,000+ students attacked since March, with hackers now publicly posting sensitive student information rather than just locking systems.
First-order effects
- Districts educating 700,000+ students face simultaneous recovery costs and exposure of student records, since attackers are publishing sensitive data as leverage when ransoms go unpaid.
- Remote-learning-era IT teams must now defend both availability (classes running) and confidentiality (student PII), a dual burden most district budgets were never sized for.
Second-order effects
- The leak-first tactic raises the cost of refusing payment, pressuring other districts toward capitulation and pushing cyber-insurance and security vendors to reprice K-12 as a distinct risk category.
- Later tallies confirm the wave compounded rather than receded: Comparitech counted 77 attacks affecting over 1,740 schools in 2020 alone, and 67 attacks hitting 954 schools in 2021 with billions in downtime costs.
Third-order effects
- If the pattern holds, ransomware becomes a standing operating cost of public education rather than an incident — pushing states and the federal government toward mandated baseline security and dedicated K-12 cyber funding.
- K12 SIX's finding that attacks on K-12 rose from 14 in 2016 to 69 in 2022 suggests schools consolidate around shared security services and consortia, because individual districts cannot staff against a national-scale adversary.
The trend: Ransomware is shifting from opportunistic encryption to data-extortion campaigns against under-resourced public institutions, with US schools as one of its most persistent targets.