Educational institutions in Brazil are increasingly targeted by cybercriminals using ransomware and insider threats, often exploiting weak security practices, outdated software, and compromised user credentials to gain access.
Key Points
- Incident response data from January 2025 to June 2026 shows 60% of attacks targeted private institutions, with São Paulo being the most affected region.
- Ransomware families like LockBit 3 and DragonForce are primary threats, frequently deployed via valid accounts and remote access tools like AnyDesk.
- Attackers commonly use "Potato" variants for privilege escalation and PsExec for lateral movement within compromised academic networks.
- Many institutions remain vulnerable due to the continued use of unsupported operating systems, including Windows 10 and Windows Server 2016.
- Insider threats involve simple Python-based keyloggers used to harvest credentials from shared machines, often bypassing basic security controls.