Leksjon 6 av 6 · 9 min
The extortion economy: ransomware groups against universities and public bodies
From encryption to data theft and public shaming: how modern extortion groups make money, what the 2026 numbers say about education, and why paying rarely buys what victims hope for.
Denne siden er foreløpig på engelsk.
Ransomware began as a simple crime: encrypt a victim’s files, sell back the key. Today it is an economy, with groups that recruit affiliates, run leak sites, publish victim lists and negotiate like businesses. Universities and public bodies sit at the centre of it, because they hold sensitive data, run services people depend on and often have limited security budgets.
From encryption to extortion
CISA’s Ransomware 101 notes that ransomware actors often threaten to sell or leak exfiltrated data if the ransom is not paid. This is known as double extortion: steal the data first, then encrypt the systems, and demand payment for both the decryption key and silence. Good backups defeat the first threat (you can restore your files) but not the second (your data is already in someone else’s hands).
Some groups skip encryption entirely and extort on stolen data alone. ShinyHunters, which appears in two earlier lessons of this course, is an example: in the Canvas case, the leverage was the threat to leak student data by a deadline, together with defaced pages and an offline platform. The FBI’s May public service announcement, quoted by the Guardian, described the group as specialising in large-scale data breaches and extortion, and warned that such actors use “real or exaggerated claims” of access to prompt payment.
What the 2026 numbers say about education
Infosecurity Magazine reported on Comparitech’s education ransomware roundup for the first half of 2026. It counted 104 ransomware attacks on the education sector worldwide, 36 of them confirmed by the victim. Attacks on higher education rose 8% compared with the previous six months, even as attacks on primary and secondary schools fell by about a quarter. A newer operation, The Gentlemen, increased its attacks on education by 275%, with 80% of them aimed at colleges and universities.
| Group (H1 2026) | Claimed attacks on education |
|---|---|
| The Gentlemen | 15 |
| Qilin | 15 |
| LockBit | 9 |
| Interlock | 6 |
| Nova | 6 |
The median ransom demand to education victims was $420,620, up 53% from $275,000 in the previous half-year. The largest demand, $1.9 million, followed an attack on Mount Royal University in Canada, where attackers claimed to have stolen more than 10TB of data. Comparitech’s Rebecca Moody noted that the attackers had also deleted entire drives, so some data might be unrecoverable.
Qilin and the public sector
The Record describes Qilin as one of the most destructive ransomware operations of 2025: it previously damaged dozens of hospitals and clinics in London, targeted several US municipalities, and launched significant attacks on the governments of Malaysia and Palau. The Record reported that Qilin claimed an attack on the US healthcare provider Covenant Health that exposed the data of 478,188 people, and that Comparitech tracked more than 700 Qilin attacks in 2025, 118 of them confirmed.
Why paying is a poor bet
- No enforcement: a deletion promise or “shred log” is the criminal’s word. Data may be kept, resold or used again.
- Funding the next attack: every payment finances the group’s tools, affiliates and future victims.
- Legal exposure: payments to sanctioned groups can break the law; take legal advice and involve law enforcement.
- It doesn’t restore trust: students, patients and staff still need to be notified and protected.
Whatever an organisation’s position on paying, it should decide in advance, with leadership, legal counsel and law enforcement contacts, not for the first time at 3 a.m. with a countdown on a leak site.
Defences that change the economics
The #StopRansomware Guide is a practical checklist. The measures that matter most for universities and public bodies:
- Offline, tested backups: keep copies attackers can’t reach, and practise restoring them.
- Data minimisation: data you delete on schedule can’t be used to extort you.
- Phishing-resistant multi-factor authentication, especially for remote access, email and administrator accounts.
- Fast patching of internet-facing systems and third-party platforms such as HR and learning systems.
- Network segmentation, so a compromised student lab can’t reach finance or research data.
- Watch for large or unusual outbound transfers: data theft has to leave the network before it can be leaked.
- An incident response plan with named contacts, including your national cyber agency and law enforcement.
On an individual Mac, FireAI contributes at the network layer, not as an antivirus: it shows which app is sending data where, can block an unknown app from reaching the internet, and offers a kill switch to cut the connection at once while you investigate.
Any testing of these defences, from phishing simulations to restore drills that touch production systems, should be done with written authorization from the organisation that owns the systems.
Det viktigste
- Double extortion adds data theft to encryption: backups alone no longer remove the leverage.
- Comparitech counted 104 education ransomware attacks in H1 2026; higher-education attacks rose 8%.
- Leak-site numbers are marketing: treat them as claims until confirmed.
- Offline backups, data minimisation, strong MFA, segmentation and outbound monitoring change the economics.
Test deg selv
1. What is “double extortion”?
- Asking two victims for the same ransom
- Stealing data before encrypting systems, then threatening to publish it — Riktig.
- Encrypting files twice
- Demanding payment in two currencies
CISA notes that actors often threaten to sell or leak exfiltrated data, so restoring from backups does not end the threat.
2. According to Comparitech’s H1 2026 roundup, which groups claimed the most attacks on education?
- LockBit and Nova
- The Gentlemen and Qilin, with 15 each — Riktig.
- ShinyHunters alone
- Interlock and LockBit
The Gentlemen and Qilin claimed 15 attacks each, followed by LockBit with 9 and Interlock and Nova with 6 each.
3. Which defence directly reduces the leverage of data-theft extortion?
- Faster laptops
- Data minimisation: not keeping data you no longer need — Riktig.
- A longer password expiry period
- Turning off backups
Backups address encryption, but only data you no longer hold is safe from being leaked.
Prøv det med FireAI
Sett denne leksjonen ut i praksis på din egen Mac.
- Regler: app, nettsted, domene, IP eller et område, for alltid eller til du starter på nytt — Skriv en regel like presis som én adresse eller like bred som et helt domene.
- Undersøk en tilkobling — Bestem deg med fakta foran deg, ikke en vag advarsel.
- Verdenskartet — Se hvor dataene dine faktisk går, ikke bare et vertsnavn du måtte slå opp selv.
- Kill switch — Kutt Mac-en din fra internett med ett klikk når noe føles galt.
- Trussellister (valgfritt) — Sjekk trafikken din mot offentlige trusseldata uten å sende den noe sted.
- Sikkerhetsmoduser: Hjem, Kaffebar, Paranoid, Under angrep — Match FireAIs strenghet til hvor Mac-en din faktisk er, med ett trykk.
Kilder
- CISA: Ransomware 101
- CISA: #StopRansomware Guide
- Infosecurity Magazine: Ransomware attacks targeting universities on the rise (Comparitech H1 2026 data)
- The Record: Covenant Health breach claimed by Qilin
- The Guardian (23 September 2026): FBI investigates breach of jobs website
Ta det i bruk på din Mac
Prøv alle funksjonene gratis i 17 dager, uten kort.