Back-to-School Cybersecurity Threats: What Education IT Teams Should Watch This Fall
Share this post
Author
The start of a new school year brings more than new students, new schedules, and a flood of help desk tickets. It also creates a predictable window of opportunity for cybercriminals.
For K–12 school districts, colleges, universities, and public-sector organizations supporting education, the weeks surrounding the start of the academic year bring a massive increase in account activity.
Dormant accounts come back online. Thousands of new users are provisioned. Faculty and staff return from summer. Students connect new devices. Password resets pile up. And IT teams are expected to make everything work on day one.
Attackers know this, too.
At Forsyte, our security operations team monitors these environments around the clock. Throughout the spring and summer, we’ve continued to see phishing, credential theft, account compromise, and identity-based attacks targeting education organizations.
The good news? The biggest risks aren’t mysterious. And there are practical steps education IT teams can take now to reduce their exposure before the first day of class.
Here are four threats our SOC is watching—and what your team can do about them.
1. Phishing Emails That Really Are From Microsoft
One of the most effective phishing techniques we’re seeing involves something that looks completely legitimate: a Microsoft file-sharing notification.
Attackers host a malicious document on a SharePoint tenant they control and then share that document with targeted users. The resulting notification can arrive from a legitimate Microsoft address, such as no-reply@sharepointonline.com.
That means the message isn’t necessarily spoofed.
It can pass traditional email authentication checks, including SPF, DKIM, and DMARC.
And that’s exactly what makes this technique effective.
A Microsoft-branded notification from a legitimate Microsoft domain feels trustworthy to the recipient—and reputation-based email filtering may not have enough information to block it.
The campaigns are also tailored to the education calendar.
We’ve seen lures built around employee benefits, staff programs, financial information, and other topics that make sense in an education environment. During one campaign, a university and community college were targeted on the same day. In another campaign involving loan disbursement, six education customers were targeted within a 24-hour period.
What education IT teams should do
Strengthen your Microsoft 365 email security controls.
Forsyte recommends reviewing:
- Microsoft Defender for Office 365 Safe Links and Safe Attachments across your environment.
- Tenant Allow/Block List configurations for known malicious senders and campaigns.
- Zero-hour Auto Purge (ZAP) to remove malicious messages that are identified after delivery.
- Similar File and Similar URL detection to identify threats that may not match previously known indicators.
- User awareness training for HR, finance, payroll, and administrative teams—especially around legitimate-looking Microsoft sharing notifications.
The key message for users is simple:
A message coming from Microsoft does not automatically mean the content is safe.
Forsyte has also developed proprietary Exchange transport-rule-based blocking mechanisms to help address this specific campaign pattern.
2. Phishing Kits That Can Steal MFA Sessions
MFA remains one of the most important identity security controls an organization can deploy.
But MFA alone isn’t enough.
Modern adversary-in-the-middle phishing attacks are designed to capture an authenticated session after the user successfully completes MFA.
Here’s how it can happen:
A user receives a convincing phishing link and signs in.
They enter their username and password.
They complete their MFA challenge.
Everything appears normal.
But behind the scenes, the attacker captures the authenticated session token and replays it from their own device.
The attacker doesn’t necessarily need to defeat MFA. They can use the session created after MFA succeeds.
We’ve responded to confirmed token-theft compromises at multiple higher education institutions, including situations where resetting the user’s password was not enough to remove the attacker because the compromised session remained active.
What education IT teams should do
Microsoft Entra ID provides several controls that can help reduce the risk and impact of token theft.
Review your use of:
- Conditional Access Token Protection to help bind authentication tokens to the device that obtained them.
- Continuous Access Evaluation (CAE) to enable near-real-time enforcement of certain changes in user and session risk.
- Conditional Access policies that restrict device code authentication where the flow isn’t required.
- Phishing-resistant MFA, including passkeys and Windows Hello for Business, for administrators and other high-value accounts.
- Risk-based Conditional Access policies to identify and respond to suspicious authentication activity.
And if you suspect an account has been compromised:
Don’t stop at a password reset.
Revoke active sessions and refresh tokens, review recent sign-in activity, investigate newly registered MFA methods, and look for suspicious inbox rules or other persistence mechanisms.
Identity security has become one of the most important parts of an effective education cybersecurity strategy.
3. Compromised Accounts Can Become Payroll Fraud
A compromised faculty or staff account can create problems that go far beyond email.
Attackers increasingly use stolen credentials and authenticated sessions to move into other systems connected through single sign-on—including HR, payroll, and financial applications.
One common objective is payroll diversion.
An attacker compromises an employee’s account, accesses the legitimate payroll workflow, and changes the employee’s direct deposit information.
From the application’s perspective, the request may look completely normal.
It’s coming from the employee’s legitimate account.
There may be no obviously malicious attachment, no ransomware, and no suspicious email for an administrator to investigate.
The financial impact can be significant—and the attack can happen before anyone realizes the account has been compromised.
What education IT teams should do
Add an identity verification step to financial changes.
For direct-deposit and other high-risk account changes:
- Require out-of-band verification before changes are approved.
- Monitor for suspicious sign-ins and unusual geographic activity.
- Review newly registered authentication methods.
- Monitor changes to mailbox rules and forwarding settings.
- Apply stronger Conditional Access controls to users with access to financial and HR systems.
- Prioritize phishing-resistant MFA for administrators and other high-value users.
Security controls should make it harder for a compromised identity to become a financial incident.
4. Back-to-School Password Spraying and Account Compromise
Every fall, education organizations experience a predictable identity challenge: a massive number of accounts become active at the same time.
New students are provisioned.
Returning students regain access.
New faculty and staff accounts are created.
Temporary and seasonal accounts may be reactivated.
And some organizations still rely on predictable initial passwords or have gaps in MFA coverage.
That creates an attractive environment for password spraying.
Instead of repeatedly trying hundreds of passwords against one account, attackers can try a small number of commonly used passwords across thousands of accounts.
The goal is to stay below account lockout thresholds while finding the one account that works.
And a student account isn’t necessarily low value.
A compromised identity may provide access to email, Microsoft 365 applications, third-party integrations, sensitive data, and other systems connected through the organization’s identity environment.
What education IT teams should do
Before students and staff return, review your identity security baseline.
- Require MFA across the environment—including student accounts wherever practical.
- Block legacy authentication such as IMAP, POP, and SMTP AUTH where it isn’t required.
- Use Microsoft Entra ID Protection to identify risky users and risky sign-ins.
- Eliminate predictable initial passwords and use strong, randomized credentials for newly provisioned accounts.
- Require users to change temporary credentials during initial sign-in where appropriate.
- Review dormant, disabled, and unnecessary accounts before reactivating them.
- Monitor for password-spray indicators and unusual authentication patterns.
Back-to-school identity management isn’t just an administrative task.
It’s a cybersecurity control.
Why Back-to-School Cybersecurity Matters
The increase in cyber activity around the academic calendar isn’t a new phenomenon.
A 2020 joint advisory from the FBI, CISA, and MS-ISAC documented a significant increase in reported ransomware incidents involving K–12 organizations at the beginning of the school year. According to the advisory, K–12 organizations accounted for 57% of ransomware incidents reported to MS-ISAC in August and September 2020, compared with 28% from January through July of that year.
That statistic is historical—not a representation of today’s threat volume—but it illustrates a pattern that education IT and security teams should continue to take seriously:
Cybercriminals pay attention to the education calendar.
The start of the school year creates more users, more devices, more authentication activity, and more pressure on already-stretched IT teams.
That combination creates opportunity.
Back-to-School Cybersecurity Checklist
Before the first day of class, education IT leaders should ask:
Identity
- Is MFA enabled for students, faculty, staff, and administrators?
- Are privileged accounts using phishing-resistant authentication?
- Are legacy authentication protocols blocked?
- Are Conditional Access policies enforcing appropriate risk controls?
- Have dormant and unnecessary accounts been reviewed?
- Is Microsoft Defender for Office 365 configured and enforced?
- Are Safe Links and Safe Attachments enabled?
- Is Zero-hour Auto Purge configured?
- Are users trained to recognize legitimate-looking Microsoft phishing notifications?
Monitoring & Response
- Who is watching your environment after hours?
- Are identity, endpoint, email, and cloud activity being monitored continuously?
- Who investigates suspicious activity when your internal team is unavailable?
- How quickly can compromised accounts be contained?
Data Protection
- Where is sensitive student, faculty, financial, and research data stored?
- Who has access to it?
- Are excessive permissions creating unnecessary exposure?
- Are Microsoft Purview capabilities being used to identify and protect sensitive information?
These questions don’t require another security tool for the sake of having another security tool.
They require the tools you already own to be properly configured, monitored, and used.
Security Shouldn’t Get in the Way of the School Year
Back-to-school season is demanding enough without adding a security incident to the list.
Your IT team already has enough to manage: onboarding users, supporting classrooms, keeping systems running, answering password-reset requests, and making sure everything works when students walk through the door.
Cybersecurity shouldn’t require your team to be everywhere, all the time.
That’s where managed security can help.
Guardian 365 provides 24×7×365 managed security operations across identity, endpoints, email, cloud workloads, and data. Our human-led SOC monitors your Microsoft environment continuously, investigates threats, hunts for activity that automated tools may miss, and responds when something needs attention. Forsyte is also a Microsoft MXDR Verified provider, with Guardian 365 built around the Microsoft security technologies many education organizations already own.
The goal isn’t to replace your IT team.
It’s to extend it.
You get dedicated security expertise without having to build and staff a 24×7 security operation yourself.
Because your team should be focused on supporting students, faculty, staff, and your community—not watching security alerts at 2 a.m.
Ready for the first day of class?
Start with a clear picture of where your organization stands.
Forsyte’s Free Security Assessment helps identify gaps across Microsoft 365 security, identity and access, email security, and sensitive data—and gives your team a prioritized roadmap for what to address next.
We make security easy—so your team can focus on what matters most.
Request a Free Security Assessment or contact the Forsyte team at sales@forsyteit.com to talk through your environment.
Ready to make security easy?
Find out where your organization stands. Our free security assessment gives you a clear picture of your current posture and a roadmap for what comes next.