In June 2023, the University of Manchester told students and staff that an unauthorised party had accessed a network holding personal data, including some linked to a regional genetics service. The university did not pay a ransom. In June 2020, the University of California San Francisco made a different calculation: it paid $1.14 million to unlock servers encrypted by NetWalker ransomware in the School of Medicine. Both decisions were defensible. They weren't the same decision.
Ransomware attacks on universities stopped being an occasional freak event years ago. They are a recurring operational hazard for public systems, private colleges, research-intensive institutions, and small liberal-arts campuses alike. The pattern behind the headlines is less about malicious software and more about institutional design. Universities run networks that are open and old, and they are packed with valuable data.
The anatomy of a campus ransomware attack
Most campus ransomware begins the same way it begins in other sectors: a stolen password, an unpatched service, or a phishing message that persuades one employee to enter credentials. From that single foothold, attackers move across the network and look for the systems a university cannot afford to lose for long. They encrypt files, change passwords, and post a demand. Increasingly, they also steal data first and threaten to publish it if the institution refuses to pay, a tactic known as double extortion. A university that restores from backups may still face a leak of student records, personnel files, or unpublished grant submissions waiting on a federal deadline.
Maastricht University experienced a full version of this in December 2019, when ransomware encrypted email and research servers, including library systems. The institution paid about €200,000 in Bitcoin to recover access, and Dutch authorities later seized part of the ransom during a money-laundering investigation. The payment was not an abstract policy debate. It was the price of restoring exams, payroll, and laboratory work before the term collapsed.
Why universities are softer targets than they look
The same qualities that make universities productive make them hard to defend: thousands of students arriving each year with their own devices, faculty who need remote access to grant systems, research labs running bespoke software older than some of their users, and a governance structure that spreads authority across departments rather than concentrating it in a single IT office. A single reused password from a compromised consumer service can become the key to a biology lab's instrument controller or a registrar's file share.
Attackers also understand the academic calendar. A ransomware demand that lands in the final week before exams, or during enrolment renewal, arrives when pressure to restore access is highest. That timing isn't accidental, and it changes the negotiating position of a provost or chief financial officer who is being told that students cannot submit work or receive financial aid until systems return.
The cases that changed the conversation
Some cases are cited for the amount paid, others for what they revealed about the gap between public confidence and internal preparedness. In July 2020, the University of Utah paid $457,059 after ransomware hit its College of Social and Behavioral Science. The university said the payment was made to prevent the publication of student information. A month earlier, the University of California San Francisco had paid $1.14 million in the NetWalker attack; the university described the decision as difficult but necessary and limited to data important to academic work.
Not every incident ends with payment. When the Cl0p ransomware group exploited a flaw in the MOVEit file-transfer tool in 2023, universities worldwide were pulled into a campaign that hit third-party vendors rather than campus systems directly. The lesson wasn't that university IT departments had done everything right. It was that a university's attack surface now includes every vendor, research partner, and application it does not control.
The costs that never appear in the incident report
The ransom itself is often the smallest number. Even when no payment is made, cost arrives through forensic investigation, legal review, breach notification, credit monitoring, insurance excesses, and months of staff overtime. Faculty lose access to grant submission portals. Students lose access to housing and financial-aid systems. Research groups rebuild instruments and datasets from scratch. A university's next application cycle, donor appeal, or research proposal can be slowed by an event that never shows up as a budget line named ransomware. Federal agencies recommend that victim institutions report through the FBI Internet Crime Complaint Center, although the decision is not automatic when insurers and counsel are already at the table.
These costs land at an increasingly difficult time for public institutions. The kind of unbudgeted expense that sits alongside tuition-dependent budget gaps, which public universities are already managing in annual operating plans, can force a choice between recovery work and other campus services. At smaller institutions, the choice is often sharper: pay for a forensic firm or retain a mental-health counsellor; add an incident responder or replace a science lab instructor.
What actually reduces risk on a campus
Security guidance for universities is not mysterious. It is also not cheap. The measures below are repeated precisely because the evidence points in one direction.
- Require multi-factor authentication for email, learning platforms, payroll, and research systems. The greatest early gain comes from protecting accounts, not buying another appliance.
- Segment networks so that a compromise in one department does not reach student records, finance systems, or research infrastructure elsewhere. The practical rule is that one researcher's workstation should not be on the same path to the registrar's database.
- Maintain offline backups that an attacker cannot delete. Backups only matter if the restoration process has been rehearsed during normal operations, not discovered during an incident.
- Run tabletop exercises that include the general counsel, the communications office, the registrar, and a faculty senate representative. An incident response plan written by IT alone will fail at the first decision that needs a signature outside IT.
Federal and sector guidance is broadly aligned. CISA's StopRansomware resource points organisations toward the same core practices, with an emphasis on planning before an attack. Universities are also adding AI tools to admissions and research systems, along with the administrative tools that manage pay and enrolment. The data-privacy tensions that run through university AI rollouts, documented in earlier reporting on this site, do not disappear simply because an incident team is standing.
The year-two question
For the institutions that have absorbed an attack or watched one nearby, the first-year response is usually funded: a hired security lead, a mandated MFA rollout, a boardroom briefing. The harder test comes in year two, when the immediate fear has faded and the same budget committee must decide whether to renew the monitoring contract or protect teaching assistant lines. The question for a regional public university with twelve IT staff and no dedicated security architect is simpler: which happens first, the next attack or the next budget line?
Photo by Joshua Jen on Unsplash
