This is a university. I expect they have a higher than normal proportion of attackers who know the system and exactly how they'd escalate having gained some access, and have the free time to prepare a customized attack.
On the other hand, those attackers are probably less malicious than the average Russian ransomware group.
On the other hand, those attackers are probably less malicious than the average Russian ransomware group.