---
title: The Weakness of Academic Cybersecurity
description: A penetration test conducted for UK government agency came with a straightforward conclusion - UK academic institutions have shockingly weak cybersecurity
image: https://reflare.com/hubfs/Blog%20image%20in%20post/The%20Weakness%20of%20Academic%20Cyber%20Security%20.png
---

[![Reflare home](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=421&height=150&name=reflare%20logo.png "Reflare home")](https://reflare.com)

[![logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png?width=262&height=82&name=logo.png "logo")](https://reflare.com/act3)

[![reflare logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=168&height=60&name=reflare%20logo.png "reflare logo")](https://reflare.com/act3)

- [Galena](https://reflare.com/galena) 
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training 
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit 
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research) 
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about) 
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Login](https://reflare.com/login)

[Buy Now](https://www.hubspot.com/)

[Login](https://www.hubspot.com/)Login to your Reflare account

- [Galena](https://reflare.com/galena)
  
  
  
  
  
  
  
  
  
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training
  
  
  
  
  
  
  
  
  
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit
  
  
  
  
  
  
  
  
  
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research)
  
  
  
  
  
  
  
  
  
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about)
  
  
  
  
  
  
  
  
  
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Buy Now](https://www.hubspot.com/)

<https://reflare.com/research> Research

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/the-weakness-of-academic-cybersecurity&text=The%20Weakness%20of%20Academic%20Cybersecurity) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/the-weakness-of-academic-cybersecurity&t=The%20Weakness%20of%20Academic%20Cybersecurity) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/the-weakness-of-academic-cybersecurity&t=The%20Weakness%20of%20Academic%20Cybersecurity)

# The Weakness of Academic Cybersecurity

 by [**Reflare Research Team**](https://reflare.com/research/author/reflare-research-team) on Aug 18, 2022 5:21:00 PM

A penetration test conducted for a UK government agency came out with one simple conclusion - 100% of UK universities and academic institutions have shockingly weak cyber security. Just ask the University of Sunderland.

First Published 8th April 2019  |  Latest Refresh 18th August 2022

![The Weakness of Academic Cyber Security ](https://reflare.com/hs-fs/hubfs/Blog%20image%20in%20post/The%20Weakness%20of%20Academic%20Cyber%20Security%20.png?width=672&height=448&name=The%20Weakness%20of%20Academic%20Cyber%20Security%20.png)

*Universities aren't making the grade.*

4 min read  |  Reflare Research Team

## Problems on top of problems

Academic institutions continue to be the focus of exploitative and malicious cyber attacks.

Most recently, a targeted intrusion adversary named Aquatic Panda (believed to be from mainland China) has been seen exploiting the critical flaws in the Apache Log4j logging library. While this allegedly state-sponsored group has primarily focused on communications companies, tech firms, and government departments, it is [reported](https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/) by CrowdStrike that academic institutions are now also being targeted.

We highly recommend that those responsible for the security of academic institution systems and networks make themselves familiar with the vulnerabilities and risks associated with the Apache Log4j exploit, which they can do so by reviewing our research on [Log4j and the Open-Source Rebellion](https://reflare.com/research/log4j-and-the-open-source-rebellion).

## Can academia defend what's coming?

As academic institutions clearly become a more attractive target for hackers, the cyber resilience of universities still leaves much to be desired.

In the not-so-distant past, the BBC [reported](https://www.bbc.com/news/education-47805451) on a penetration test performed against UK universities that quickly resulted in severe breaches. In this research report, we will take a look at the techniques used, why universities are relatively unprepared and what attackers seek when hacking into university networks.

A penetration test ordered by Jisc - the government agency providing internet access to UK universities - showed that 100% of tested universities were successfully hacked with most of them only fending off attackers for 1-2 hours. According to their [published report](https://www.hepi.ac.uk/wp-content/uploads/2019/03/Policy-Note-12-Paper-April-2019-How-safe-is-your-data.pdf), most breaches were achieved using Spear Phishing attacks.

## What is Spear Phishing?

Most of our readers will have heard of Phishing attacks. Here, attackers send fake emails to victims in order to trick them into revealing login credentials or other critical information. Spear phishing attacks take this approach further by tailoring the emails to the victim.

Imagine for a moment that your name is John and that you are working as a non-technical administrator at a UK university. You know Sally, the head of IT, personally.

A general phishing attack may look like this:

*Dear User,*

*Your account is about to expire!*

*Please log in here to prevent expiry.*

*hxxp://evil.com/login*

*Thanks*

While even such basic attacks are frighteningly successful, a spear phishing version of the same email may look something like this

*Hi John,*

*As you may have heard during Monday’s staff meeting, we are upgrading the security of our systems. For technical reasons that I won’t bore you with, this requires that you log into the staff panel before 5pm today. In case you forgot the link, it’s at hxxp://evil.com/login.*

*Sorry to bother you with this, but it is to keep us all safe.*

*Best,*

*Sally*

The spear phishing attack is significantly harder to detect. Reflare’s own penetration testing experience shows that up to 3 out of every 5 victims fall for well-crafted spear phishing emails the first time they are encountered.

If the victim has access to confidential files, this can have catastrophic consequences.

## Why are universities being attacked?

Universities present a target that is relatively weakly secured and offers relatively high rewards. While undergraduate assignments and exam scores are of little interest to external attackers, research data can be highly valuable to companies in the private sector and foreign governments. The ease with which UK universities were hacked during this penetration test combined with the high value of information stored on university systems makes it highly likely that actual successful attacks by criminals against universities are a regular occurrence.

## Case in point

Hackers who conduct these sorts of attacks understand that 'right timing' can hugely increase the value and impact of their work. The University of Sunderland was hit by an attack at what can be argued as the worst possible time; the start of the first in-person academic year after the COVID-19 pandemic.

As you could imagine, being hacked as thousands of students return to campus would be incredibly disruptive, which is exactly what a hacker would want. The university's vice-chancellor, Sir David Bell, said this "frustrating" attack had disabled the institution's entire IT system. Although the University did not say who was behind the attack or what type of hack had taken place, it is believed to be ransomware which has encrypted and locked the IT system until a ransom payment is made.

Another recent example is Ottawa’s French-language public school board Conseil des écoles publiques de l'Est de l'Ontario (CEPEO), which fell [victim](https://cepeo.on.ca/cyberincident) to a breach where 75 gigabytes of files were seized from a server in their main offices. Even though the Law enforcement and the Information and Privacy Commissioner of Ontario were advised of the attack, the data of employees, students and alumni were critical enough that CEPEO [paid](https://ottawa.ctvnews.ca/ottawa-s-french-public-school-board-paid-hackers-a-ransom-following-cyberattack-1.5687578) the hacker’s ransom. 

## Summary

One of the most common ways of delivering ransomware into a system is through (surprise) spear phishing attacks, which are extremely hard to detect. Please never trust an email simply because it appears to come from someone you know. Always check the recipient’s email address before answering and confirm the authenticity of any websites you visit.

Universities are relatively soft targets that own relatively valuable data. In combination with the apparent ease of attack, this indicates that successful hacks against universities will remain somewhat common until there is firm action taken to address their vulnerabilities. Improving the systems and processes within their IT can be complex, expensive, and take time to implement.

However, [upskilling](https://reflare.com/rcse/) the cyber security capabilities and threat awareness of the staff and students can be cost-effective, quick to implement, and make a significant impact on mitigating the risks of this happening to other universities. 

Additionally, it is important to understand that there are many other types of cyber threats that universities are exposed to. Staying on top of the latest emerging cyber security trends can give academic institutions the opportunity to proactively reduce the risks to their IT systems and networks. Subscribe to our Reflare Research Newsletter to stay up-to-date, and check out some of the related stories below to learn more.

Topics: [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/the-weakness-of-academic-cybersecurity&text=The%20Weakness%20of%20Academic%20Cybersecurity) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/the-weakness-of-academic-cybersecurity&t=The%20Weakness%20of%20Academic%20Cybersecurity) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/the-weakness-of-academic-cybersecurity&t=The%20Weakness%20of%20Academic%20Cybersecurity)

- Recent
- Topics
- Archive

Recent

Topics

- [Infosec Culture (113)](https://reflare.com/research/tag/infosec-culture)
- [Anatomy of a Breach (60)](https://reflare.com/research/tag/anatomy-of-a-breach)
- [Normal People and Infosec (42)](https://reflare.com/research/tag/normal-people-and-infosec)
- [High Tech (31)](https://reflare.com/research/tag/high-tech)
- [Infrastructure (21)](https://reflare.com/research/tag/infrastructure)
- [Capture the Flag (8)](https://reflare.com/research/tag/capture-the-flag)

See all

Archive

- [June 2026 (1)](https://reflare.com/research/archive/2026/06)
- [May 2026 (1)](https://reflare.com/research/archive/2026/05)
- [April 2026 (1)](https://reflare.com/research/archive/2026/04)
- [March 2026 (1)](https://reflare.com/research/archive/2026/03)
- [February 2026 (1)](https://reflare.com/research/archive/2026/02)
- [January 2026 (1)](https://reflare.com/research/archive/2026/01)
- [December 2025 (1)](https://reflare.com/research/archive/2025/12)
- [November 2025 (1)](https://reflare.com/research/archive/2025/11)
- [October 2025 (1)](https://reflare.com/research/archive/2025/10)
- [September 2025 (1)](https://reflare.com/research/archive/2025/09)
- [August 2025 (1)](https://reflare.com/research/archive/2025/08)
- [July 2025 (1)](https://reflare.com/research/archive/2025/07)
- [June 2025 (1)](https://reflare.com/research/archive/2025/06)
- [May 2025 (1)](https://reflare.com/research/archive/2025/05)
- [April 2025 (1)](https://reflare.com/research/archive/2025/04)
- [March 2025 (1)](https://reflare.com/research/archive/2025/03)
- [February 2025 (1)](https://reflare.com/research/archive/2025/02)
- [January 2025 (1)](https://reflare.com/research/archive/2025/01)
- [December 2024 (1)](https://reflare.com/research/archive/2024/12)
- [November 2024 (1)](https://reflare.com/research/archive/2024/11)
- [October 2024 (1)](https://reflare.com/research/archive/2024/10)
- [September 2024 (1)](https://reflare.com/research/archive/2024/09)
- [August 2024 (1)](https://reflare.com/research/archive/2024/08)
- [July 2024 (1)](https://reflare.com/research/archive/2024/07)
- [June 2024 (1)](https://reflare.com/research/archive/2024/06)
- [April 2024 (2)](https://reflare.com/research/archive/2024/04)
- [February 2024 (1)](https://reflare.com/research/archive/2024/02)
- [January 2024 (1)](https://reflare.com/research/archive/2024/01)
- [December 2023 (1)](https://reflare.com/research/archive/2023/12)
- [November 2023 (1)](https://reflare.com/research/archive/2023/11)
- [October 2023 (1)](https://reflare.com/research/archive/2023/10)
- [September 2023 (1)](https://reflare.com/research/archive/2023/09)
- [August 2023 (1)](https://reflare.com/research/archive/2023/08)
- [July 2023 (1)](https://reflare.com/research/archive/2023/07)
- [June 2023 (2)](https://reflare.com/research/archive/2023/06)
- [May 2023 (2)](https://reflare.com/research/archive/2023/05)
- [April 2023 (3)](https://reflare.com/research/archive/2023/04)
- [March 2023 (4)](https://reflare.com/research/archive/2023/03)
- [February 2023 (3)](https://reflare.com/research/archive/2023/02)
- [January 2023 (5)](https://reflare.com/research/archive/2023/01)
- [December 2022 (1)](https://reflare.com/research/archive/2022/12)
- [November 2022 (2)](https://reflare.com/research/archive/2022/11)
- [October 2022 (1)](https://reflare.com/research/archive/2022/10)
- [September 2022 (11)](https://reflare.com/research/archive/2022/09)
- [August 2022 (5)](https://reflare.com/research/archive/2022/08)
- [July 2022 (1)](https://reflare.com/research/archive/2022/07)
- [May 2022 (3)](https://reflare.com/research/archive/2022/05)
- [April 2022 (1)](https://reflare.com/research/archive/2022/04)
- [February 2022 (4)](https://reflare.com/research/archive/2022/02)
- [January 2022 (3)](https://reflare.com/research/archive/2022/01)
- [December 2021 (2)](https://reflare.com/research/archive/2021/12)
- [November 2021 (3)](https://reflare.com/research/archive/2021/11)
- [October 2021 (2)](https://reflare.com/research/archive/2021/10)
- [September 2021 (1)](https://reflare.com/research/archive/2021/09)
- [August 2021 (1)](https://reflare.com/research/archive/2021/08)
- [June 2021 (1)](https://reflare.com/research/archive/2021/06)
- [May 2021 (14)](https://reflare.com/research/archive/2021/05)
- [February 2021 (1)](https://reflare.com/research/archive/2021/02)
- [October 2020 (1)](https://reflare.com/research/archive/2020/10)
- [September 2020 (1)](https://reflare.com/research/archive/2020/09)
- [July 2020 (1)](https://reflare.com/research/archive/2020/07)
- [June 2020 (1)](https://reflare.com/research/archive/2020/06)
- [May 2020 (1)](https://reflare.com/research/archive/2020/05)
- [April 2020 (2)](https://reflare.com/research/archive/2020/04)
- [March 2020 (1)](https://reflare.com/research/archive/2020/03)
- [February 2020 (1)](https://reflare.com/research/archive/2020/02)
- [January 2020 (3)](https://reflare.com/research/archive/2020/01)
- [December 2019 (1)](https://reflare.com/research/archive/2019/12)
- [November 2019 (2)](https://reflare.com/research/archive/2019/11)
- [October 2019 (3)](https://reflare.com/research/archive/2019/10)
- [September 2019 (5)](https://reflare.com/research/archive/2019/09)
- [August 2019 (2)](https://reflare.com/research/archive/2019/08)
- [July 2019 (3)](https://reflare.com/research/archive/2019/07)
- [June 2019 (3)](https://reflare.com/research/archive/2019/06)
- [May 2019 (2)](https://reflare.com/research/archive/2019/05)
- [April 2019 (3)](https://reflare.com/research/archive/2019/04)
- [March 2019 (2)](https://reflare.com/research/archive/2019/03)
- [February 2019 (3)](https://reflare.com/research/archive/2019/02)
- [January 2019 (1)](https://reflare.com/research/archive/2019/01)
- [December 2018 (3)](https://reflare.com/research/archive/2018/12)
- [November 2018 (5)](https://reflare.com/research/archive/2018/11)
- [October 2018 (4)](https://reflare.com/research/archive/2018/10)
- [September 2018 (3)](https://reflare.com/research/archive/2018/09)
- [August 2018 (3)](https://reflare.com/research/archive/2018/08)
- [July 2018 (4)](https://reflare.com/research/archive/2018/07)
- [June 2018 (4)](https://reflare.com/research/archive/2018/06)
- [May 2018 (2)](https://reflare.com/research/archive/2018/05)
- [April 2018 (4)](https://reflare.com/research/archive/2018/04)
- [March 2018 (5)](https://reflare.com/research/archive/2018/03)
- [February 2018 (3)](https://reflare.com/research/archive/2018/02)
- [January 2018 (3)](https://reflare.com/research/archive/2018/01)
- [December 2017 (2)](https://reflare.com/research/archive/2017/12)
- [November 2017 (4)](https://reflare.com/research/archive/2017/11)
- [October 2017 (3)](https://reflare.com/research/archive/2017/10)
- [September 2017 (5)](https://reflare.com/research/archive/2017/09)
- [August 2017 (3)](https://reflare.com/research/archive/2017/08)
- [July 2017 (3)](https://reflare.com/research/archive/2017/07)
- [June 2017 (4)](https://reflare.com/research/archive/2017/06)
- [May 2017 (4)](https://reflare.com/research/archive/2017/05)
- [April 2017 (2)](https://reflare.com/research/archive/2017/04)
- [March 2017 (4)](https://reflare.com/research/archive/2017/03)
- [February 2017 (2)](https://reflare.com/research/archive/2017/02)
- [January 2017 (1)](https://reflare.com/research/archive/2017/01)
- [December 2016 (1)](https://reflare.com/research/archive/2016/12)
- [November 2016 (4)](https://reflare.com/research/archive/2016/11)
- [October 2016 (2)](https://reflare.com/research/archive/2016/10)
- [September 2016 (4)](https://reflare.com/research/archive/2016/09)
- [August 2016 (5)](https://reflare.com/research/archive/2016/08)
- [July 2016 (3)](https://reflare.com/research/archive/2016/07)
- [June 2016 (5)](https://reflare.com/research/archive/2016/06)
- [May 2016 (3)](https://reflare.com/research/archive/2016/05)
- [April 2016 (4)](https://reflare.com/research/archive/2016/04)
- [March 2016 (5)](https://reflare.com/research/archive/2016/03)
- [February 2016 (4)](https://reflare.com/research/archive/2016/02)

See all

### Subscribe by email

#### About Reflare

We help customers increase cyber resilience with the #1 hands-on IT security training platform.

Our developer, administrator, and non-technical user training programs enhance user skills, fulfil your compliance needs, and contribute to developing more secure technologies.

<https://x.com/reflarehq><https://www.linkedin.com/company/reflare-ltd.>

Legal

- [Terms of Service](https://reflare.com/terms)
- [Privacy Statement](https://reflare.com/privacy)
- [Cookie Info](https://reflare.com/cookies)
- [Copyright and Citation Enquiries](https://reflare.com/citation)
- [Contact](https://reflare.com/contact)

 © 2026 Reflare Ltd, and/or its affiliates.   /   In business since 2009.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Reflare Research Team",
    "url" : "https://reflare.com/research/author/reflare-research-team"
  },
  "dateModified" : "2023-11-21T13:08:23.104Z",
  "datePublished" : "2022-08-18T16:21:00.000Z",
  "headline" : "The Weakness of Academic Cybersecurity",
  "image" : [ "https://reflare.com/hubfs/Blog%20image%20in%20post/The%20Weakness%20of%20Academic%20Cyber%20Security%20.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://reflare.com/research/the-weakness-of-academic-cybersecurity",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://reflare.com/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png"
    },
    "name" : "Reflare"
  }
}
```