VYPR
breachPublished Aug 3, 2026· 1 source

Brazilian Educational Institutions Face Surge in Ransomware and Data Theft

A Securelist report reveals Brazilian educational institutions, particularly in São Paulo, are increasingly targeted by ransomware and data theft, with private entities most affected.

Educational institutions, both public and private, are prime targets for cybercriminals due to the vast amounts of sensitive personal data they manage and the potential for high impact from successful attacks. These organizations often rely on software with inadequate security testing, and complex network environments supporting diverse user groups amplify risks. A breach can expose Personally Identifiable Information (PII) such as social security numbers, addresses, and phone numbers, which attackers can then leverage for phishing or SIM swapping attacks prevalent in Brazil.

According to a report by Securelist's Global Emergency Response Team (GERT), incidents affecting Brazilian educational institutions between January 2025 and June 2026 primarily concentrated in São Paulo. The data indicates that 60% of the targeted institutions were private, while 40% were public. The most common reasons for incident response requests included suspicious endpoint activity, file encryption, and the presence of malicious files. Notably, 40% of these incidents were classified as high-severity, largely driven by ransomware attacks.

Ransomware families such as DragonForce and LockBit 3 were frequently observed, with private institutions being the primary victims. Attackers often gained initial access through valid accounts, exploitation of public-facing applications, or insider threats. For privilege escalation, variants of the Potato exploit (GodPotato, SweetPotato, BadPotato) were commonly used. Tools like AnyDesk for remote access, PsExec for lateral movement, and AV-killer malware to disable defenses were also prevalent, particularly in ransomware-related incidents.

The analysis highlights that many attacks did not rely on sophisticated techniques but rather exploited common weaknesses like compromised credentials, exposed applications, and poor patch management. The higher prevalence of ransomware in private institutions suggests a financial motivation, as attackers likely believe these organizations have a greater capacity to pay ransoms. While many attacks were detected and contained within a few hours, the technical incident response and recovery process averaged 9.6 hours, indicating the extended impact of breaches.

An interesting observation from the report is the continued use of outdated operating systems within these institutions. Many were found to be running Windows 10 beyond its official end-of-support date (October 2025) and unpatched versions of Windows Server 2016. The use of unsupported and unpatched systems significantly increases the attack surface, providing attackers with known vulnerabilities to exploit for initial access and network expansion.

One case study detailed the use of a custom LockBit variant generated from a leaked builder. This ransomware was delivered via a compromised valid account, encrypting internal systems including file servers and databases containing student profiles. While no data exfiltration was evident in this specific instance, it underscores the threat posed by readily available tools and compromised credentials.

Securelist recommends that educational institutions strengthen their security posture by implementing robust access controls, ensuring timely patching of all systems, and conducting regular security awareness training for staff and students. Addressing the use of legacy systems and securing valid accounts are critical steps in mitigating the risks posed by ransomware and data theft campaigns targeting the education sector.

Synthesized by Vypr AI