- What: Attackers are targeting software suppliers of EdTech companies.
- Impact: Educational institutions and their partners may be at risk.
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security Apple's MacOS Gap Lets Users Disable Security Tools Apple's MacOS Gap Lets Users Disable Security Tools by Jai Vijayan Jun 24, 2026 4 Min Read Cyberattacks & Data Breaches Scope of Salesforce Attacks Expands as Icarus Leaks Data Scope of Salesforce Attacks Expands as Icarus Leaks Data by Rob Wright Jun 23, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyberattacks & Data Breaches Cyber Risk News Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. EdTech Attackers Shift From Schools to Their Software Suppliers Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series. Arielle Waldman , Features Writer , Dark Reading June 25, 2026 Source: Dark Reading Threats against the education sector have mounted over the past five years and are becoming even more widespread, as attackers set their sights on educational technology (edtech) vendors. Rather than conducting ransomware or other attacks against an individual school or district, cyberattackers now target learning management systems (LMS) and other educational applications to victimize hundreds, if not thousands, of institutions in one fell swoop. The attack by Shiny Hunters against Instructure's LMS Canvas earlier this year — forcing the Canvas platform offline during a time when many students had final examinations — is a prime example of how disruptive these attacks can be. The gang also claimed responsibility for not one but two attacks against Instructure in one month. This was not the first attack against edtech. Two years prior, Powerschool, an edtech cloud-based platform for K-12, gave into ransom demands following a data breach where threat actors took off with students' names, Social Security numbers, medical information, and academic records. Related: Processes & Culture Top Reasons Behind Data Breaches It's that kind of high-value information, combined with the institution's often limited security resources, that makes targeting edtech so appealing to cyberattackers. That doesn't mean higher education institutions with more resources escape scrutiny. The innovative research data at those institutions is attractive to attackers, too. Three reporters — Dark Reading's Arielle Waldman , TechTarget SearchSecurity's Sharon Shea , and Cybersecurity Dive's Eric Geller — share what they've learned while speaking to industry experts on how the edtech ecosystem and the relationship between vendors and educational organizations will evolve. Companies and organizations could start pushing to add specific cybersecurity requirements into their contracts with the vendors. Learn more in the video transcript below, and check out other episodes in the Reporters' Notebook series for insights and coverage from across Informa TechTarget's three cybersecurity publications. Arielle Waldman, Eric Geller & Sharon Shea: Full Video Transcript This transcript has been edited for clarity and length by Informa TechTarget's internal AI assistant. For the full experience, please watch the video. Dark Reading's Arielle Waldman : Hi, everyone, welcome to another edition of the Reporters' Notebook. Today we're going to be discussing the education sector and all the issues that they've been facing. My name is Arielle Waldman and I'm a features writer for Dark Reading. I have Sharon Shea and Eric Geller with me. Would you like to introduce yourselves? Related: Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Cybersecurity Dive's Eric Geller : Yes, I'm Eric Geller, senior reporter at Cybersecurity Dive. TechTarget SearchSecurity's Sharon Shea : Hi, I'm Sharon Shea, executive editor on TechTarget SearchSecurity. Thank you all for joining us today. We're excited to chat about ed tech and the educational sector and cybersecurity. So, we're kind of coming off at the heels of the what folks are calling the biggest attack on education in history. In late April and early May, edtech company Instructure confirmed a cyberattack on its Canvas Learning Management System . Threat group Shiny Hunters claimed responsibility for the attack and said that they stole 3.65TB of data, including information from 275 million users across almost 9,000 schools. As of May 11, Instructure said it had reached an agreement with the attackers and that the software is safe to use. I don't think we know if they paid a ransom or not, but whatever "reached an agreement" means. And then again, just last week, Shiny Hunters also claimed responsibility for further attacks on higher ed, reportedly exploiting the Oracle PeopleSoft software suites, [the vendors] for ERP, CRM, [and] HCM, and they have campus applications to help higher ed manage student records , admissions, financial aid. Google noted that while some organizations were able to block or remediate the vulnerabilities before this latest round of attacks, others are compromised and have had their data published on data leak sites. So, education is unique. It's up against a lot of threats and this just kind of touches on the supply chain side, the software supply chain, and you know organizations getting hit because of their software suppliers, as in through Canvas and the PeopleSoft software. Related: Scope of Salesforce Attacks Expands as Icarus Leaks Data And also a bit of the ransomware in there too, right? Because they spoke with the attackers and reached an agreement. So, Arielle, I didn't know if you want to talk a little bit more about other attacks that you've seen and written about and what you have experienced. Well, not experienced, but … DR's Arielle Waldman : Sure. Yeah. Yeah, this seems to just be the latest supply chain attack. I think one issue is kind of the concentrated area of schools only use certain platforms and software. And they've just experienced so many attacks in the last five years alone. In 2023, there was a big one with Progress Software's MOVEit . It's a file transfer that schools use, and that was also a ransomware attack, and that affected a lot of schools as well, another supply chain ransomware situation, which is so common against the sector. And then the PowerSchool data breach that happened a couple of years ago. PowerSchool is an ed tech cloud-based platform. It's used in K through 12 schools . And in that case, it was a data breach and attackers made off with names, addresses, birth dates, academic records, and even medical information. And in that case, I think it was confirmed that they paid a ransom to have the files deleted, which does seem common, maybe in the education sector . I don't know if it's always confirmed, but like you said, it seems like they talked with the attackers, which maybe insinuates that they did pay a ransom since the data is so valuable and sensitive when it comes to students. And with the most recent with Canvas, it happened during finals week, which put another kind of hurdle, kind of disrupted school even more so. Though I don't think the students were that upset. I saw a lot of things on social media with students kind of thanking Shiny Hunters for disrupting their finals and things like that, which, you know, I think kids are so immune to it nowadays that their schools are just being attacked and they receive data breaches, as [does] everyone, and these attacks just continue to show that. Eric, do you wanna kind of dig into why schools are such a big target? CD's Eric Geller : Yeah, it’s a kind of a toxic combination of a bunch of factors. First, they, you know, have a lot of data. Second, they have a lot of data about people who are at the very beginning of their lives. So Social Security numbers and personal information is gonna be usable for a lot longer because these people are so young. If you steal that information, you have in some cases 80 more years of usefulness from it if the person doesn't change some of that information and you can't, you know, change the Social Security number. So that there's the lifespan of the data is so much longer and when you combine that with the fact that these are not well protected organizations, they're funded by local governments. They have dire needs outside of cybersecurity that receive a lot more of the funding, teacher pay infrastructure. They’re not only valuable targets because of the data that they hold, but they're easy targets because of the networks that they run. There's also another security issue for them because you know, a lot of them will give out tablets, and it's not always easy to manage the security of the tablets . Same with laptops, but also students are bringing their own devices to school. If you think about a business environment where you're trying to enforce a managed device policy because of the security risks of BYOD , it's so much harder in a school enviro