Connect with us

NEWS

The 24 Percent Education Cyber Claim Does Not Add Up

Seqrite ranks Indian education first for cyber detections, yet its 24 percent share and 4.92 million count do not sit on the same 265.52 million base.

Published

on

Seqrite Labs logged 265.52 million threat detections in India in the year to September 2025, and ranked education as the top industry. A later Seqrite briefing put schools, colleges, training centres and edtech platforms at nearly 24 percent of detections, or 4.92 million hits. Those two figures do not share a base.

Education is a noisy, open, heavily hit surface. That part holds across more than one firm’s telemetry. The poster percentage now circulating does not sit on Seqrite’s own full-year tally, and the bill that will stick is student identity under the Digital Personal Data Protection Act, not worm counts on lab PCs.

24 Percent on a Tally That Will Not Reconcile

Seqrite, the enterprise arm of Quick Heal Technologies, released the India Cyber Threat Report 2026 on 4 December 2025. Researchers at Seqrite Labs, which the company calls India’s largest malware analysis facility, recorded 265.52 million detections on 8 million endpoints between October 2024 and September 2025, averaging 505 detections every minute, or more than 727,000 a day.

The report page lists Education and Training as the top industry impact. The same page, and the 4 December newsroom note, say education, healthcare and manufacturing together made up nearly 47 percent of all detections. Neither document prints 24 percent. That share, and the 4.92 million education count, arrive in a later sector readout that also sells Seqrite Data Privacy and Digital Risk Protection tools.

Four point nine two million is 1.85 percent of 265.52 million. Twenty-four percent of the same tally would be 63.7 million. Both cannot describe the same pile of alerts.

SEQRITE FIGURES ON TWO DIFFERENT BASES

Item Figure Where it appears
Full-year detections 265.52 million December 2025 report and newsroom
Named top industry Education and Training Report “Top Impacts”
Education, healthcare, manufacturing Nearly 47 percent December 2025 newsroom
Education briefing count 4.92 million Later education readout
Education briefing share Nearly 24 percent Later education readout
4.92 million as a share of 265.52 million 1.85 percent Arithmetic on the full tally
24 percent of 265.52 million 63.7 million Arithmetic on the full tally

A March 2026 healthcare note drawn from the same report said hospitals and pharma logged 3.79 million detections, called 14.24 percent of attacks, and described healthcare as receiving the highest number. An engineering note put manufacturing at 3.79 million, or 14.22 percent of industry volume. Add those two counts to 4.92 million and the three sectors sum to 12.5 million, which is not 47 percent of 265.52 million. Seqrite is measuring something real. It is not publishing one share, on one base, for one sector.

WHERE SEQRITE’S OWN BRIEFINGS DIVERGE

  • December report: Education and Training is the top industry, and the three sectors together are nearly 47 percent of detections.
  • Education readout: The sector is the most heavily targeted industry at nearly 24 percent, with 4.92 million detections.
  • Healthcare note: Hospitals received the highest number, at 3.79 million detections and 14.24 percent.

Dr. Sanjay Katkar, joint managing director of Quick Heal Technologies, said the 2026 report was meant to give policymakers, enterprises and citizens intelligence to understand evolving threats. The education readout then turned a top-industry line into a 24 percent poster. Readers should treat the poster as a briefing claim, not as 24 percent of 265.52 million.

Old Malware on Shared Campus Networks

The mix inside the tally is not novel, targeted code. The report page’s “troublesome trio” is Trojans at 88.44 million detections, file infectors at 71.09 million, and worms at 13.81 million. On-premises environments absorbed 91 percent of detections. Network exploit scans exceeded 9.2 million, often aimed at WordPress plugins, Apache Tomcat and SysAid. Cryptojacking reached 6.5 million. Ransomware peaked in January 2025 at 185 incidents and 113,000 detections, driven by families Seqrite names as Xelera and Weaxor.

In education, Seqrite Labs tied repeated compromise attempts to older families such as Trojan.Pioneer.CZ1 and W32.Expiro.R3. Attackers used unpatched systems, shared Wi-Fi and weak research kit for credential theft, data theft and cryptomining. That is what a detection lead looks like when thousands of unmanaged lab PCs, faculty laptops and student devices share a network that was built to stay open.

WHAT THE EDUCATION SURFACE STILL LEAVES OPEN

  • Shared Wi-Fi: Campus wireless is built for guests, students and staff on the same pipes, so one infected laptop can scan sideways.
  • Unpatched labs: Teaching machines and research boxes often run old images because a lock-down breaks the class.
  • Remote learning tools: Third-party apps and OAuth logins sit beside on-site servers, so a stolen password can move without a malware alert.
  • Research stores: Grant data and unpublished work live next to student records on networks that still trust internal traffic.

Seqrite has put education at the top of its India tables before. In the July to September 2019 quarter the company assigned the sector more than 30 percent of the enterprise threats it recorded. The 2026 ranking is a loud year on a familiar surface, not a new class of foe.

Check Point Puts Indian Campuses at 7,095 Weekly Hits

Independent telemetry still puts Indian education near the front of the queue. It just does not use Seqrite’s 24 percent. Check Point Software’s India threat readout, covering about six months into September 2025, said the education and research sector faced 7,095 weekly attacks per organization. Government followed at 5,140, and consumer goods and services at 3,889. Indian organizations overall saw 3,233 weekly attacks, against a global average of 2,002.

Sundar Balasubramanian, managing director for Check Point in India and South Asia, said infostealers and remote access Trojans are exploiting hybrid learning and connected campuses, and that institutions need to protect intellectual capital as well as uptime. That is a different unit from Seqrite’s detections: weekly attacks per organization, not antivirus alerts on a vendor’s installed base. The direction of travel is the same. The percentages are not interchangeable.

SonicWall’s Education Protect Brief, published 3 September 2026 and covering the first half of 2026, measured global education, not India alone, and still describes the same open-door problem. Education logged the highest per-device attack intensity SonicWall tracks, at 81,879 IPS hits per device. SIPVicious VoIP exploitation generated 90 million combined hits and 50.5 percent of intrusion-prevention events in the sector. Education saw 16,242 malware hits per device. A 2021 Hikvision camera bug still showed up on 605 devices, spanning 28 percent of education networks in the set. Apache Log4j2 generated 6.7 million hits. Forty-four education organizations detected ransomware campaigns in that half-year, including the Ryuk family.

Education has the most exposed attack surface of any industry we track, and the data shows attackers know it.

Michael Crean, SVP of Managed Services, SonicWall, 2026 Education Protect Brief

Crean’s point is architectural. Campus VoIP, cameras and learning software sit on the same networks as health records, fees and grant data. A scanner that looks like a nuisance on a lab phone line is a foothold next to the registrar.

THREE FIRMS, THREE YARDSTICKS

Firm Window Education metric
Seqrite Labs October 2024 to September 2025, India Top industry; later briefing 4.92 million detections, nearly 24 percent
Check Point About six months to September 2025, India 7,095 weekly attacks per organization
SonicWall First half of 2026, global education 81,879 IPS hits per device

None of those rows is a 24 percent slice of 265.52 million. All three say the doors are open.

What a Stolen Student Record Is Worth?

Seqrite’s education readout is clearer when it leaves the percentage and talks about bait. Fake institution websites, fraudulent scholarship offers and fake job postings now sit beside malware. The trusted campus name is the lure. The catch is identity documents, marksheets, bank details and parent contacts. A spoofed admissions portal or a fake scholarship microsite can harvest that file before any endpoint product fires.

Cloud-connected learning makes the first stolen password more useful than a worm. Seqrite says on-premises kit still takes 91 percent of detections, while cloud traffic shows identity abuse, OAuth misuse and API exploitation. Compromise can start with one login and move into student records, faculty mail, exams and research stores. That is a different job from spreading W32.Expiro across a computer lab.

HOW THE HARVEST RUNS OUTSIDE THE FIREWALL

  • Fake scholarship pages: Applicants upload Aadhaar copies, income proofs and account numbers to sites that borrow a college’s colours and name.
  • Fake hiring boards: Campus-placement lookalikes collect résumés, ID scans and bank details from students who think a recruiter asked.
  • Spoofed portals: Lookalike fee and admission domains sit one typo away from the real registrar.
  • Leaked logins: Student and staff passwords recirculate on dark-web dumps and get reused on exam and mail systems.

Schools already hold names, addresses, phones, Aadhaar numbers, attendance, parent finances, health notes, photos and CCTV. Under the Digital Personal Data Protection Act, 2023, the institution that decides why that file is processed is a Data Fiduciary. Anyone under 18 is a child. Processing a child’s data needs verifiable parental consent, not a tick-box on an admission form, and the Act bars behavioural tracking and targeted ads aimed at children.

IIT Roorkee’s Read-Only Cloud Slip in June

The gap between a detection count and a student-data event showed up in public in June 2026, on the machinery for JEE Advanced. IIT Roorkee, the organising institute, said that on 2 June 2026, hurried technical work to help candidates reach admit-card data produced a short misconfiguration in a cloud storage component. An ethical hacker the institute named as Rylen Anil reported that he could reach the database. IIT said the issue was fixed at once.

Claims of a data breach and privacy violation affecting lakhs of JEE (Advanced) aspirants are misleading and factually incorrect.

IIT Roorkee, official statement, 5 June 2026

The institute said the affected storage was read-only, so nothing could be edited or deleted. Cloud access logs, it said, showed no bulk download, with read-only access limited to less than 0.05 percent of the data, and no effect on marks, ranks or category. A researcher’s public claim of about 179,600 result records and 187,300 admit-card PDFs is not a figure IIT adopted. On 10 June 2026 the institute separately said fabricated rank-and-marks lists circulating online did not match any official record, and that 56,880 candidates had qualified.

The same result season, CBSE said its post-result portal took about 1.5 million access requests in two minutes and blocked more than 100,000 unauthorised attempts, with no breach detected. Exam platforms are now part of the education attack surface Seqrite is counting, and they fail in public even when the malware dashboard is quiet. After a cloud slip, fake result lists still travel. That is how student-data panic moves when the official file is only partly open and the rumour file is fully open.

DPDP Will Fine a School up to 250 Crore

The legal clock is no longer theoretical. Parliament enacted the Digital Personal Data Protection Act on 11 August 2023. MeitY notified the Digital Personal Data Protection Rules, 2025 and, in the 13 November 2025 commencement gazette, brought the Data Protection Board into force the same day. Core fiduciary duties, including security safeguards, breach notice, children’s data rules and principal rights, come into force 18 months after that gazette, on 13 May 2027.

THE DPDP CLOCK FOR A CAMPUS

  1. 11 August 2023: The Act receives presidential assent and is published.
  2. 13 November 2025: Rules are notified and the Data Protection Board of India is established.
  3. 13 May 2027: Sections covering notice, consent, fiduciary duties, children’s data and principal rights apply to schools, colleges and edtech firms.

The Schedule to the Act sets a cap of 250 crore rupees for a failure of reasonable security safeguards under Section 8(5) that leads to a personal data breach. A breach of the extra duties for children’s data under Section 9 can run to 200 crore rupees. Those are maxima, not automatic fines, and the Board has to hear the fiduciary. They are still large enough to dwarf a college IT budget, and they attach to student and parent records, not to a worm alert on a lab image.

DPDP CAPS THAT HIT A SCHOOL FILE

  • Security failure: Up to 250 crore rupees under Section 8(5) when safeguards fail and personal data is breached.
  • Children’s data: Up to 200 crore rupees under Section 9, including verifiable parental consent and the ban on tracking children.
  • Age line: Anyone under 18 is a child, so most school and many undergraduate files sit in that bucket.

Seqrite’s own preparedness survey, published with the December report, gave Indian organizations an average maturity score of 6.37 out of 10. Advanced malware protection sat at 86.7 percent and backup readiness at 78.5 percent, with weaker incident response, configuration and asset hygiene. That is the profile of a sector that can raise a 4.92 million detection count and still lose a cloud bucket because a flag was left open during a rush to serve admit cards.

IIT Roorkee’s 5 June 2026 statement said the affected storage was read-only and that cloud logs showed no bulk download. That is the standard a campus will have to meet, in public, once DPDP duties apply on 13 May 2027.

Disclaimer: This article is news reporting and analysis of vendor telemetry, public institute statements and Indian data-protection law. It is informational only and is not legal advice, compliance advice, or a determination that any school, college, board or company has breached the Digital Personal Data Protection Act, 2023 or the 2025 Rules. Readers who run an institution, process student data, or face a suspected incident should consult a qualified data-protection lawyer or certified privacy professional before changing systems, signing vendor contracts, or notifying regulators. Detection counts, penalty caps and enforcement dates reflect the Seqrite report, Check Point and SonicWall briefings, IIT Roorkee’s June 2026 statements, and MeitY gazette notifications cited above, and those figures can change with later reports or official corrections.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending