Ransomware headlines tend to focus on big retailers, hospitals, and government agencies. But schools and colleges are an escalating, and in some ways more vulnerable, target, and a recent case shows exactly how indiscriminate the threat is.
A real example: Shottermill Junior School
In May 2026, Shottermill Junior School, a primary school in Haslemere, Surrey, was hit by a LockBit 5.0 ransomware attack. The attackers gained initial access on 20 May and weren't publicly detected until the following day, but they didn't strike immediately. They sat inside the school's systems for roughly three weeks, moving laterally across connected systems and network shares, exfiltrating data, disabling backups, and staging the ransomware payload, before the group claimed responsibility on 9 June.
This is double extortion: encrypting data while simultaneously stealing it beforehand, creating two separate harms: operational disruption from the encryption itself, and reputational and legal risk from the threat to publish stolen personal data, which in a school often includes medical information, SEND records, mental health data, and safeguarding notes.
The point isn't the size of the school. As our original coverage of this attack put it: "A junior school in a quiet Surrey market town is as viable a target as any large secondary or multi-academy trust." If anything, smaller schools with fewer dedicated IT resources can look like easier targets.
Shottermill isn't an isolated case either, we've covered similar attacks at St Anne's Catholic School and Higham Lane School, where the campus itself had to close.
A second example: one supplier, 87 schools
Shottermill shows what happens when attackers get inside a single school. A more recent incident in Bristol shows something different: what happens when they get inside a service that many schools share.
In late September 2026, Trading With Schools, a Bristol City Council service that provides internet access to 87 schools across the city, was compromised. According to Bristol Live’s reporting, council staff first noticed suspicious activity on the system on 21 September, but it wasn’t shut down until 25 September. The council then disconnected the affected schools from the internet to stop the malicious software spreading. The regional cyber crime unit is investigating it as a potentially serious cyber crime.
None of those 87 schools had to make a mistake to be affected. They were affected because they all depended on the same system.
What it looked like inside the schools
- No internet in lessons for weeks. Computing, music and other technology-dependent lessons had to be rethought.
- Routine jobs became slow and manual. Registers, lesson planning and printing all took longer, and staff fell back on paper or found ways to work around the council system.
- Communication with families was cut back. One headteacher told parents that newsletters were paused, reports might be delayed, some after-school meetings could be cancelled, and email replies would be slower.
- Parents and councillors were left with questions. Their biggest worry was whether children’s personal details had been taken, and they said clear answers were hard to get.
At the time of writing (9 October 2026), it has not been publicly confirmed what kind of malware was involved, or whether any personal data was accessed.
This isn’t the first time it has happened in the area. In 2021, a ransomware attack on IT infrastructure shared by the Castle School Education Trust affected more than 20 schools in South Gloucestershire, including local authority schools that relied on the trust’s systems.
What every school can take from it
- Your cyber risk includes your suppliers’ cyber risk. Ask your key providers (internet, MIS, IT support, cloud services) how they detect and contain an incident, how quickly they would tell you, and what your contract says about it. Our Cyber Risk Register includes third-party IT provider risks for exactly this reason.
- Hours matter, not days. Four days passed between suspicious activity being spotted and the system being shut down. As we covered on Normalising Immediate Incident Reporting | October 9, the faster something unusual is reported and escalated, the less time an attacker has to work with.
- Plan for a day without the internet. Could you take a register, reach parents in an emergency, and teach a full timetable if your connection went down tomorrow? Printed emergency contact lists, offline register procedures and a backup connection (even a 4G router for the office) belong in your business continuity plan.
- Communication is part of the response, not something that comes after it. Parents’ first question was whether their children’s data was safe. Even “we don’t know yet, and here’s what we’re doing to find out” is better than silence.
- You’re still the data controller, even when the incident happens at your supplier. If personal data has been affected, your provider should tell you without undue delay. Your school is responsible for assessing the breach and, where there is a risk to individuals, reporting it to the ICO within 72 hours. Involve your DPO from the start.
What a ransomware attack actually looks like
Imagine arriving at work to find every system locked, with an on-screen message demanding payment in cryptocurrency. Teachers can't access lesson plans. Attendance records are gone. Administrative systems are completely down.
The cascading effects spread fast:
- Academic disruption: classes stop, online platforms become inaccessible, students can't submit work, exams may be postponed
- Operational paralysis: payroll, student information systems, financial records, and facilities management all freeze; even phone and door entry systems can go offline
- Data loss and exposure: sensitive student data (medical records, behavioural notes) and staff data (HR files, payroll) can be permanently lost or exposed if backups aren't robust
- Financial strain: recovery requires cyber security experts, new hardware, and often legal fees
- Reputational damage: parent trust erodes, and community reputation suffers
- Long recovery: systems restoration can take weeks or months, pulling resources away from education itself; sometimes with the school closed for a long period of time
The scale of the problem
The Cyber Security Breaches Survey 2025/2026, shows the picture has got noticeably worse since last year's figures:
| 2024/25 | 2025/26 | |
|---|---|---|
| Primary schools reporting a breach or attack | 44% | 49% |
| Secondary schools | 60% | 73% |
| Further education colleges | 85% | 88% |
| Higher education institutions | 91% | 98% |
For context, only 43% of UK businesses overall reported a cyber incident; education is being hit harder than the general business population, across every level.
Ransomware specifically remains relatively rare for schools directly (0% of primary schools, 6% of secondary schools reported it), but affects 14% of further/higher education institutions, against just 3% of businesses generally. Phishing remains by far the dominant route in: 90% of primary schools and 96% of secondary schools that experienced a breach said it involved phishing, and the survey specifically flags that AI-enhanced phishing emails are increasingly harder to detect, a point this series covered in detail in Days 6–8.
Among schools that experienced a breach, 13% of primary and 20% of secondary schools reported a negative system impact (compromised accounts, disrupted services, lost access), rising to 49% across further and higher education.
Where schools are falling short
The survey highlights patch management as the weakest technical control in education: only 45% of primary schools and 62% of secondary schools have a formal patching policy. That gap used to be a weakness. As of this year, it's a compliance failure.
What the DfE Digital Standards Require
On 24 June 2026, the DfE tightened its Cyber Security Standard to align with the updated Cyber Essentials 2026 question set.
The DfE's Cyber Security standard is recommended guidance rather than a mandatory, certified requirement; there's currently no pass/fail assessment attached to it directly. That said, within the guidance itself, the language on two specific points is deliberately strong:
- MFA "must" be enabled for all staff accounts with access to cloud services or remote access to on-site systems, and for all IT administrative accounts. For other accounts, it "should" be considered based on risk.
- Critical and high-risk vulnerabilities (CVSS 7.0+) must be patched within 14 days of the fix being released, and occasionally DfE may issue instructions requiring a security update within just 5 working days.
Given that patch management is already the weakest technical control in the sector (only 45% of primary and 62% of secondary schools have a formal patching policy) and MFA gaps are common precisely where this series has flagged risk, these two "musts" are worth checking against your own setup now, regardless of whether a formal assessment is involved. If you're separately working toward Cyber Essentials certification, that scheme does carry its own pass/fail assessment — but that's a distinct, voluntary scheme from the DfE standard itself.
💡Your Daily Cyber Tip
Maintain regular backups on external hard drives or a reputable cloud service, and keep them separate from your primary systems. As Shottermill shows, attackers specifically target and disable connected backups before deploying ransomware — a backup that's reachable from your main network isn't a backup, it's just another target.
If it happens to you
Understanding the threat is one half of this. Knowing what to do when it happens is the other. We've covered that in detail separately:
- What to do in the event of a Cyber Attack: containment, reporting, and evidence preservation, written for schools without in-house IT expertise
- Cyber Incident Review: The Benefits: why reviewing after the fact matters as much as responding in the moment
- Effectively Communicating During a Cyber Incident: keeping staff, parents, and governors informed without making things worse
- The Cyber Security Breaches Survey 2025/2026: Key Advice for Schools: our full analysis, including supply chain security, governor engagement, and AI governance gaps
Where this sits in the DfE Digital & Technology Standards
This sits squarely under the Cyber Security standard, now with considerably less margin for error following the June 2026 update, and reinforces why Digital Leadership & Governance expects schools to have cyber strategy ownership at board level, as covered on Day 10.
