For cybercriminals, the start of the school year is a particularly attractive window. With students, teachers, and administrators returning to work all at once, IT teams are stretched across competing priorities. Inboxes are full of legitimate-looking communications that staff are too distracted to strictly peruse and are more likely to respond to quickly, and attackers know this.
At a rushed time like this, there is another incentive cybercriminals are looking to exploit. A successful attack can be particularly disruptive at this point and potentially more lucrative with schools scrambling to restore systems before a new academic year. Attackers are known to use the quiet summer months to compromise accounts and systems and then execute the attack when the pressure to get operations running is at its peak.
More than 52% of U.S. school districts have experienced a cybersecurity incident in 2025, according to the 2026 Cybersecure report. That is a 16-percentage-point increase from 2024. Over time, third-party incidents have also risen sharply, from 4% of reported breaches in 2023 to a staggering 32% in 2025.
This seasonal pattern is visible in threat data, with DDoS attacks against educational systems doubling in August and September as compared to the preceding two months.
With AI in their arsenal, attackers can now create highly convincing social-engineering messages that imitate superintendents, IT administrators, and other staff, helping them develop malicious campaigns easily and quickly. As a result, AI phishing in schools has become more effective, and the time to detect and respond to it keeps shrinking.
So as students are settling back into their classes, officially closing the 2026 summer vacations across the country, what can schools do to keep themselves safe?
Start With the Accounts, Not the Hardware
As you prepare for students and school employees to return, focus on three things: account configurations, account activity, and lateral phishing.
First, a critical review of accounts, organizational units, and groups must be conducted with particular attention to users who have elevated access to sensitive information and systems. This is an area where problems often exist, and school districts happen to miss it.
Most schools rely heavily on firewalls and native administrative tools provided by cloud vendors to secure data, and this leaves glaring gaps in visibility and control. It is vitally important to include cloud security and account-level visibility in all schools’ baseline security strategy.
As a step two, schools must examine account activity over the summer and ask important questions. Which accounts are more active than expected? Are users logging in from countries they would not normally travel to? Are there any instances of “impossible travel,” where an account user appears to have been logging in from geographically distant locations within an unrealistic timeframe?
The final check should delve into lateral phishing. Once an account has been compromised, cybercriminals often use it to send convincing messages to others inside the system, effectively turning the compromised account into a tool to spread the attack.
Schools also need to review their most important cybersecurity policies and automated controls before a new academic year kicks off. Automation can only help if it has been configured correctly to suit the environment it is protecting.
Don’t Forget the Cloud, or the Vendors
A school’s security perimeter no longer ends at the network. Most of what schools do on the regular happens on cloud applications like Gmail, Google Drive, Google Docs, Microsoft Outlook, Word, Excel, and hundreds of other SaaS platforms that are used for academics and administration. If IT teams only monitor devices and the school’s Wi-Fi network, a significant part of the district’s information environment is being ignored.
Third-party applications need to be particularly scrutinized. School administrators should know which applications are connected to school accounts, what permissions they have, and review if these remain appropriate.
OAuth permissions give applications access to school accounts without necessarily being on top of the list of IT administrators’ minds. Schools need to limit school-account connections to legitimate education-related applications and review when access is granted.
Vendor risk is another growing concern. Third-party incidents accounted for 32% of reported K-12 breaches in 2025, up from 4% in 2023. Now, schools cannot completely control vendors’ security practices. But for companies handling particularly sensitive information like student records or financial data, schools should review the security response protocols and data-handling procedures of the vendors. This is a part of a layered approach to cybersecurity in K-12 where no single security layer can wholly protect a modern school.
What Happens After a Password Is Stolen?
The most important question is not whether every phishing email can be blocked. It is what happens when one gets through.
Credential theft gives attackers a foothold within the system from which they can move quickly. That makes visibility and response speed critical.
A school needs to know who is logging into its systems, where those logins are coming from, and whether the activity is consistent with normal behavior. And this visibility needs to extend into Google Workspace, Microsoft 365, and all other cloud environments, not just school-issued devices and the network.
While traditional email security remains important, no filter is perfect. Modern phishing attacks are specifically designed to circumvent those defenses.
Detection at the cloud level and response provide another layer of protection. When a malicious email gets through the first filter but is identified, quarantined, and flagged, an administrator can quickly determine who received it, whether anyone interacted with it, and whether associated accounts need to be secured.
Without that capability, an administrator may not learn about the attack until someone reports a suspicious email. The investigation then begins manually, and by then, the damage is usually done. Simply detecting suspicious emails is no longer adequate; schools need to identify and respond to threats quickly.
Five red zones to focus on
With the initial checks in place, IT teams must work on finding weaknesses before they become operational problems.
1. Audit accounts and access: Review accounts, organizational units, and groups, particularly users with elevated privileges or access to sensitive information.
2. Investigate unusual activity: Look for unexpected account activity, unusual login locations, and impossible-travel patterns.
3. Check for lateral phishing: Determine whether compromised accounts may be sending suspicious emails internally or externally.
4. Review applications and vendor permissions: Audit third-party applications connected to school accounts, review OAuth permissions, and reassess access granted to critical vendors.
5. Test detection and response: Review the school’s security policies and automated controls. Then test the incident response plan. If an attack happened tomorrow, who would know first, who would investigate it, and how quickly can the school contain it?
AI should also be a part of this review. Four in five schools surveyed for the 2026 Cybersecure report believe AI is increasing their cybersecurity risk, yet only 11% have formal processes for vetting AI use in edtech tools.
Don’t Let a Cyberattack Derail Your Back-to-School Success
Cyberattacks do not respect the academic calendar. In fact, they are here to sabotage it. No cybersecurity strategy can guarantee that a school will never be attacked. The objective is to make sure that when an attacker gets through, you can see what is happening, contain the threat, and respond before a security incident becomes an operational crisis.
And while you have a hundred fires to put out already, the beginning of the school year is exactly the time you need to make sure your district is ready.
Charlie Sander is CEO of ManagedMethods, a Boulder, Colorado-based cybersecurity and student safety platform that protects K-12 school districts.
