Key points:
- Paying a ransom usually results in longer recovery times
- The most common root cause of a ransomware attack is an exposed vulnerability
- See related article: Growing ransomware threats require maximum data protection
The education sector reported the highest level of ransomware attacks in 2022, with 79 percent of higher education organizations surveyed and 80 percent of lower education organizations surveyed reporting that they were victims of ransomware, according to research from cybersecurity provider Sophos.
The “State of Ransomware 2023” report found that in 76 percent of ransomware attacks against surveyed organizations, adversaries succeeded in encrypting data. This is the highest rate of data encryption from ransomware since Sophos started issuing the report in 2020.
The survey also shows that when organizations paid a ransom to get their data decrypted, they ended up additionally doubling their recovery costs ($750,000 in recovery costs versus $375,000 for organizations that used backups to get data back). Moreover, paying the ransom usually meant longer recovery times, with 45 percent of those organizations that used backups recovering within a week, compared to 39 percent of those that paid the ransom.
Overall, 66 percent of the organizations surveyed were attacked by ransomware—the same percentage as the previous year. This suggests that the rate of ransomware attacks has remained steady, despite any perceived reduction in attacks.
- Weak tech could push students, faculty to other institutions - April 13, 2026
- 13 predictions about edtech, innovation, and–yes–AI in 2026 - January 1, 2026
- 5 essential dimensions of AI literacy - December 12, 2025
