Ransomware Attacks on Universities Surge in H1 2026, Driven by 'The Gentlemen' Variant
Ransomware attacks targeting higher education institutions saw an 8% increase in the first half of 2026, with the 'The Gentlemen' ransomware group being a primary driver of this trend.

Universities have become a prime target for cybercriminals, with ransomware attacks against higher education institutions experiencing a notable surge in the first half of 2026. Analysis from Comparitech's Education Ransomware Roundup reveals an 8% increase in attacks on these providers compared to the preceding six months, highlighting a growing threat to the sector.
The emergence and aggressive activity of the 'The Gentlemen' ransomware operation are identified as key factors behind this alarming trend. This specific group's attacks on the education sector escalated by a staggering 275% in the first half of 2026 when measured against the latter half of 2025. Alarmingly, 80% of 'The Gentlemen's' attacks within the education domain were directed specifically at colleges and universities.
Overall, Comparitech recorded 104 ransomware attacks against the global education sector during the first six months of 2026, with 36 of these incidents being confirmed as ransomware by the affected institutions. While the number of attacks on higher education rose, the report also indicated a decrease in overall recorded incidents against the broader education sector. This reduction is attributed to a significant drop in attacks targeting primary and secondary schools, which fell by a quarter. However, this does not signify an abatement of the ransomware problem, but rather a shift in focus.
"This H1 report yet again emphasizes the impact one group can have on the threat landscape. While initially the dip in attacks makes for positive reading, further investigations reveal that this is largely due to one gang and its choice of target,” stated Rebecca Moody, head of data research at Comparitech. She further elaborated, “The Gentlemen has gained immense notoriety in recent months and, as our data shows, has focused on higher education institutions.”
The data underscores that ransomware attacks on the education sector are a global concern. Institutions in the United States were the most frequent targets, with 34 confirmed victims. The United Kingdom and Brazil followed, accounting for 13 and 8 victims, respectively. Universities in 17 other countries also experienced at least one confirmed ransomware attack during this period.
Among the most prolific ransomware perpetrators targeting education were 'The Gentlemen' and 'Qilin,' each claiming responsibility for 15 attacks. 'LockBit' was close behind with 9 claimed attacks, followed by 'Interlock' and 'Nova,' each with 6. The median ransom demand issued to victim organizations in the education sector during this period reached $420,620, a substantial 53% increase from the $275,000 median demand in the second half of 2025.
The largest ransom demand recorded was $1.9 million, issued after an attack on Mount Royal University in Canada. Even a month after the incident, the university's systems remained impacted, and attackers claimed to have exfiltrated over 10 terabytes of data. Moody highlighted the far-reaching consequences, noting, “Last month's attack on Mount Royal University also serves as a stark reminder of the drastic and far-reaching consequences attacks on education continue to have and that system encryption and data theft aren't the only things to worry about.” The attackers also deleted entire drives of data, potentially rendering some information irrecoverable.
This trend highlights the critical need for enhanced cybersecurity measures within educational institutions, which often hold vast amounts of sensitive student and research data. The increasing sophistication and targeted nature of ransomware groups like 'The Gentlemen' necessitate a proactive and robust defense strategy to protect academic operations and data integrity.