Ransomware against schools is down. Against universities, it is up.
*New H1 2026 data shows attacks on education falling overall while higher education rises, and the attackers who hit a Canadian university deleted the files after stealing them.*
Mount Royal University told its community something in July that most ransomware victims never have to say. The attackers had not only taken data from employee and student file storage — they had deleted it on the way out.
"The actor then deleted our H drive data to impede our recovery," the university wrote on July 7. A second departmental drive was wiped too, with no evidence it had been copied first. On that one, the university was candid: "a full recovery may not be possible."
More than a month after the June 17 intrusion, systems were still disrupted.
## What happened
Comparitech's H1 2026 education ransomware analysis, published July 22, contains a number that reads well at first glance and badly on inspection. Total attacks on education fell 13 percent, from 120 to 104. K-12 dropped 26 percent.
Higher education rose more than eight percent.
The rise traces largely to one group. The Gentlemen, a ransomware-as-a-service operation that spun out of Qilin in mid-2025, claimed 15 education victims in the first half of 2026 against four in the previous six months — a 275 percent increase, 80 percent of it in higher education. Comparitech's Rebecca Moody made the analytical point: "While initially the dip in attacks makes for positive reading, further investigations reveal that this is largely due to one gang and its choice of target."
Their primary way in is not exotic: CVE-2024-55591, the FortiOS authentication bypass. Halcyon reports the operators maintain an inventory of roughly 14,700 already-compromised FortiGate devices plus nearly a thousand brute-forced VPN credentials. From there they favor hijacking Active Directory Group Policy to detonate on every domain-joined host at once.
Mount Royal was a different group — the $1.9 million demand and the drive deletions belong to CMD Organization, which auctions stolen data to the highest bidder rather than negotiating. Worth separating the two, because secondary coverage has repeatedly merged them.
Across education the median ransom demand was $420,620, up 53 percent, roughly 2.8 times the all-sector median. No institution was confirmed to have paid.
## Why it matters for Texas institutions
Two of the four US higher-education institutions with confirmed attacks in H1 2026 were community colleges, both in Pennsylvania, and both lost weeks rather than days. The Community College of Beaver County closed its campus outright; its communications VP described the scope: "We have currently locked down all IT resources. No one is to be using their computers, logging into VPN, even from home." In-person classes did not fully resume for three weeks.
That pattern — total shutdown rather than partial degradation — is what flat networks without segmentation produce. And the compliance clock does not scale with staffing: any Title IV institution must report to Federal Student Aid within 24 hours of a known breach and satisfy the FTC Safeguards Rule whether it employs one generalist or a full SOC. EDUCAUSE polling found smaller institutions expecting a median 8 to 10 percent IT budget cut for 2025–26, with roughly half under hiring freezes.
No Texas college or university suffered a confirmed ransomware attack in H1 2026. Texas exposure came through the shared-vendor path instead. May's compromise of Instructure, parent of the Canvas LMS, reached nearly 9,000 institutions and roughly 275 million records, with a second wave defacing login portals at some 330 institutions during finals. UTSA disabled Canvas logins and rescheduled assessments; Alamo Colleges District, Texas State, Baylor and the University of the Incarnate Word were all affected. Instructure paid — one of only two organizations in all of H1 2026 confirmed to have done so.
## What your institution should do
**Patch and then hunt your edge devices.** Fortinet first, then Cisco appliances and any internet-facing RDP. With thousands of FortiGate devices already in attacker inventories, Halcyon's posture is the right one: any appliance left unpatched during the vulnerability window should be treated as potentially breached. Patching does not undo prior access.
**Back up file shares like they are a destruction target, not just an exfiltration target.** Mount Royal is the case study. Immutable, offline backups isolated from domain-joined systems, and tested restores — because as Halcyon puts it, "Knowing a backup exists is not the same as knowing it works."
**Harden Active Directory and Group Policy,** where the damage multiplies. Implement tiering, restrict write access to SYSVOL and NETLOGON, and alert on unauthorized GPO modification and new domain admin accounts. One free, high-fidelity detection: any scheduled task matching `gentlemen*`.
**Get security terms into your vendor contracts.** Post-Canvas this is not optional — breach notification obligations and periodic assessment for LMS, SIS and payment vendors are an explicit Safeguards Rule expectation.
**Pre-decide the ransom question** with counsel and your insurer, including the sanctions check. Delano Public Schools was legally barred from negotiating because LockBit is sanctioned. Discover that on day one, not day ten.
## RSOC is here to help
RSOC provides monitoring, vulnerability scanning, threat intelligence and incident response support to Texas higher education institutions and state agencies — including those without the staff to run these programs alone. If you want help assessing edge exposure or Active Directory resilience, reach out at [rsoc.utexas.edu](https://rsoc.utexas.edu).