Education: High exposure to cybercriminals and state-sponsored threats State-sponsored groups frequently target academic research, with at least one Czech educational institution having reported and mitigated a malicious state-backed campaign in 2023. Despite an improvement over last year, this sector faces a larger volume of cyber incidents than any other (Fig. 22). Comparison of the number of cyberattack attempts reported by respondents in the education sector (% of respondents) 2022 2023 11 % 0 15 % 26 % 16 % 6-10 12 % 5% 11-20 9% 11 % 20-30 6% 5% 3% 31-50 42 % 101 and more 29 % 0% Figure 22 The education sector continues to be an attractive target for attackers. 11 % 1-5 10 % 20 % 30 % 40 % 50 % This is most visible at both ends of the scale: the extreme category of over 101 incidents was 13 % higher than the average; instances of no attack at all were approximately 4 % below average (Fig. 23). A notable incident covered in the media involved the cybercriminal group Monti, which executed a ransomware attack on the Czech Republic’s University of Defence (UNOB), detected on September 11. The attackers used double extortion, exfiltrating and encrypting the university’s data and threatening to publish it if a ransom was not paid. When the university refused, the group released documents containing the personal data of teaching staff, meeting minutes and study plans. Information from such institutions can be valuable to malicious state actors. Although the university restored the encrypted data from backups, the theft of sensitive information constitutes a serious incident. 36

Select target paragraph3