Forget the movie version of a hacker breaking through a firewall like it's a bank vault. That's not how most school districts actually get hit.
A new industry survey of 226 education IT leaders whose districts had been hit by ransomware in the past year found that 85% of those attacks started the same simple way: a phishing email, a stolen password, or a login guessed through brute force. Not a software flaw. Not some exotic exploit. A person's credentials.
That's higher than the average across every other sector surveyed, and it should change how districts think about where their security dollars go.
Identity is the front door, not a side door
Here's the part that's easy to miss: the credential theft usually isn't a separate problem from the ransomware. It IS the ransomware, start to finish. Nearly three out of four education ransomware victims in the survey said the attack that took down their systems was also the most significant identity compromise they'd dealt with all year. Once an attacker has someone's login, they don't need to break anything else. They just walk in as that person.
Malicious email was the single most common way in, responsible for roughly three in ten attacks in both K-12 and higher ed. That tracks with what most district IT staff already sense but don't always say out loud: the weak point isn't the network. It's the inbox.
And here's the number that should really get a board's attention. In cases where a district's firewall actually flagged the attack before it fully hit, meaning the tool worked exactly as intended, the attacker still succeeded in encrypting data about half the time anyway. The tools are seeing the threat. They're just not stopping it fast enough once a stolen login is already inside.
Montana isn't exempt from this pattern
Montana has its own history here. Districts around the state have dealt with malware and network disruptions serious enough to bring in insurance carriers and outside investigators, and cybersecurity has become enough of a concern that Montana's congressional delegation and the Department of Homeland Security have held public roundtables on the topic with district leaders.
The common thread across most of these incidents, in Montana and nationally, is the same one the survey data points to: someone's credentials got compromised first, and everything after that was just the attacker moving through the door they'd already opened.
Why this hits rural districts especially hard
National survey data from the Consortium for School Networking found that rural and town districts are the least likely of any district type to have a dedicated cybersecurity staff member, at just 15%, compared to 41% in urban districts. The same research found that 65% of districts report being understaffed specifically for cybersecurity, even when their general IT functions are staffed fine.
That gap matters more for identity-based attacks than almost any other kind of threat. A network exploit takes some technical sophistication to pull off. A phishing email doesn't. It just takes one staff member, on one busy morning, clicking one convincing link. The fewer eyes a district has watching for that, the longer it takes to catch.
CISA seems to agree on where the priority sits. The agency's K-12 Cybersecurity Foundations Resource Package, released in August 2026 specifically for resource-constrained districts, puts credential protection at the very top of its list of core objectives, ahead of device security, backup testing, and everything else. When federal guidance built for districts with no security budget leads with "protect your logins first," that's worth listening to.
What this means for the next budget cycle
If you're a superintendent or business official deciding where security dollars go this year, the identity data gives you a clean way to rank the requests in front of you. The highest-return investment isn't another firewall refresh or a bigger antivirus contract. It's the work that closes the identity gap directly:
- Enforce multi-factor authentication on every account, not just admin logins. In the survey, almost all credential-attack victims already had MFA enabled somewhere in their environment. The gap was coverage, not the tool itself. MFA has to reach every account, including the ones nobody remembers to protect: shared logins, vendor portals, older systems.
- Run phishing simulation training on a real schedule, with follow-up for staff who click, not a once-a-year slideshow nobody remembers by October.
- Monitor privileged accounts for unusual activity, so an odd login gets flagged and acted on in minutes, not discovered during a forensic review weeks later.
- Make your existing tools talk to each other. The firewall-caught-it-anyway-got-encrypted problem above is the argument for this. Most districts don't need more security tools. They need the ones they already have working together instead of logging alerts nobody sees in time.
How K12 Montana helps close this gap
This is the exact kind of work K12 Montana builds for districts our size. We run staff phishing simulation programs designed around how small district teams actually operate, not enterprise assumptions that don't fit a 400-student district with one and a half IT staff. We deploy and enforce MFA across every district account, including the ones that tend to get skipped. And through K12 Panel, our device and asset management platform, district leadership gets visibility into what's actually happening across the network, so an unusual login doesn't sit unnoticed the way it did in about half the cases in this year's survey.
If your district is budgeting for next year and trying to figure out where security spending should go first, that's a conversation worth having before the budget locks in. Reach out to K12 Montana to talk through what a phishing simulation and MFA rollout would look like for your team.
FAQ
What is an "identity-based attack" in this context? It means the attacker got in using a person's credentials rather than exploiting a software vulnerability. That covers phishing emails, stolen passwords, credential stuffing (trying leaked passwords from other breaches), and brute-force login guessing.
Does having MFA guarantee protection? No. Nearly all education ransomware victims in the survey already had MFA enabled somewhere in their environment. The gap is usually coverage (accounts or systems MFA wasn't extended to) and how fast a suspicious login gets acted on once it's flagged.
Is this a bigger risk for small districts than large ones? The survey didn't break results out by district size, but separate national data shows rural and town districts are far less likely to have dedicated cybersecurity staff than urban districts. Fewer dedicated eyes on the network generally means slower detection, which is exactly where recovery times suffer most.
Where can districts get free federal guidance on this? CISA's K-12 Cybersecurity Foundations Resource Package, released in August 2026, is free and built around eight objectives, starting with credential protection. It's a solid starting checklist for districts without a dedicated security budget yet.
Sources
- Industry survey of 226 education IT and cybersecurity leaders on ransomware causes and identity attacks, as reported by Sophos
- CISA, K-12 Cybersecurity Foundations Resource Package, as reported by K-12 Dive
- Consortium for School Networking (CoSN), IT staffing and cybersecurity survey data, as reported by SolarWinds and K-12 Dive
- Montana Public Radio, "Panel Discusses Cyber Security For Montana Public Schools"
-1.png?width=798&height=406&name=k12-4%20(2)-1.png)