A Third of UK Unis Hit By Ransomware in Last 10 Years

Leo Daniels • August 14, 2020

This is a subtitle for your new post

Around a third (33%) of UK universities have been targeted with ransomware, freedom of information (FOI) requests submitted by the agency TopLine Comms have revealed.

Of the 134 universities the requests were sent to, 105 responded. Of these, 35 (33%) revealed they had been subjected to attack while 25 (24%) said they hadn’t. The remaining 43 (45%) refused to answer, with the main concern being that admission of attack could lead to further targeting.

Those that refused to answer the FOI added that no inference should be drawn from the refusal as to whether they’d been attacked or not.

Of the 35 universities that admitted to having faced ransomware attack, 34 confirmed they did not pay ransoms, with just one, Liverpool John Moores, refusing to disclose whether they had paid a ransom or not.

Whilst most attacks were isolated incidents, Sheffield Hallam University stood out as it had reported 42 ransomware attacks since 2013. It was followed by City, University of London, which has been targeted seven times since 2014.

The years in which the greatest total number of incidents occurred were in 2015 (31%), 2016 (34%) and 2017 (23%).

Ransomware attacks on universities has been brought into sharper focus recently following the admission by University of California San Francisco in June that it had paid over $1.14m to criminals after discovering that critical academic data related to its COVID-19 research had been encrypted.

Luke Budka, head of digital PR and SEO at TopLine Comms, said: “The recent revelation that hackers extorted $1.14m from the University of California prompted us to submit requests to UK universities asking for details on ransomware attacks and ransom amounts paid. We were naturally most interested in Russell Group universities as their research focus suggests they’ve got the most valuable intellectual property.

“Of the 18 Russell Group universities that responded, all but three refused to answer the questions submitted. The University of Manchester admitted it had been attacked but said it didn’t record when; The University of Sheffield was attacked in 2015 and The University of Edinburgh stated it had not been attacked in the last ten years.”

Speaking to Infosecurity about the findings, Steven Furnell, professor of cybersecurity at the University of Nottingham, commented: “The fact that a third indicated that they had been ‘subject to an attack’ really just serves to confirm the prevalence of the threat – which in itself is not a surprise, as we know ransomware has been a significant element of the threat landscape for the last few years.”

He noted that universities are potentially particularly vulnerable to ransomware attack because of the varied mix of users connecting into the networks across a wide range of devices, including students’ personal devices.

Furnell added: “In terms of what they ought to doing to protect themselves, it is essentially the same as other large organizations – ensuring an effective combination of technical safeguards to detect and prevent the incidents, alongside awareness-raising for staff and students in order to reduce the chances of them inadvertently assisting the threat or losing their own data if a breach was to occur.”

 

We’re 1-fix, we can help you secure your business

At 1-fix, we take a realistic approach to technology – ensuring our client’s systems are best protected.

If you have any concerns, questions or simply want to explore how to better secure your business, please do get in touch with the team for a FREE demonstration, consultation to explore how exposed your business might be and identify actions to take.

Join Our Mailing List

All sign-ups are handled inline with our privacy policy and can unsubscribe at any time.

IT Support Services
Cybersecurity Deep-Dive
IT Cloud Migration Service

Recent Blogs

Cyber Essentials Logo on a dark background
By Craig Atkins April 17, 2025
Cyber Essentials 101: what every business needs to know. Thursday 8th May, 2pm
The words 'Comms Business Awards' in large letters with blue and black background
By Jess Dugdale April 16, 2025
We’re absolutely delighted to share that our Client Manager, Lee , has been shortlisted for the Hidden Hero Award at the Comms Business Awards – and we couldn’t be prouder!
Photo of the 1-Fix team stood in a line smiling at the camera
By Jess Dugdale April 8, 2025
We've moved! 1-Fix is now based in Bracknell, Berkshire - Your trusted IT support partner in the Thames Valley
Image of a gravestone with the writing 'Windows 10 2015-2025'
By Craig Atkins April 1, 2025
As we approach October 2025, the end of life for Windows 10 is just around the corner. For many businesses, this coincides with the start of a new budget cycle in April, making it the perfect time to consider upgrading to Windows 11. In this blog post, we'll explore the benefits of making the switch early and how it can positively impact your business.
By Craig Atkins February 25, 2025
Multi-Factor Authentication (also known as 2-Factor authentication, 2FA and MFA) has become a widely adopted seucirty measure to protect business' data. However, it's becoming more apparent just how easy it may be for hackers to get around it.
Image of a keyboard with a padlock on top
By Lee Dugdale-Shutts February 10, 2025
Data loss can occur due to various reasons, including hardware failures, cyberattacks, natural disasters, and human error. To protect your business from these risks, it's crucial to implement a strong data backup and security strategy.
Show More