The education sector has become one of the fastest-growing targets for cybercriminals due to the enormous volume of sensitive student, staff and financial information it holds.
Hacking groups including ShinyHunters and FulcrumSec are increasingly targeting not only schools and universities, but also the third-party platforms they depend upon. Recent attacks this year include:
- Canvas — April 2026 — millions of student records affected globally
- Infinite Campus Salesforce data theft attack — March 2026 — 137,000 school staff accounts
- Global Schools Foundation — June 2026 — large-scale data exfiltration from critical systems across its schools in multiple countries
- Victorian Department of Education — January 2026 — data breach impacting all 1,700 government schools
- Reynella East College — June 2026 — ransomware disclosure involving 600 GB of school data
- Glendale Community College — June 2026 — 62 GB of data exposed
- Moody Bible Institute — June 2026 — personal data of more than 2.3 million individuals
- Illinois Central College — June 2026 — 28 GB of sensitive records compromised
- Houston City College — June 2026 — sensitive records of 832,000 individuals exposed
These incidents are a worrying trend, reminding us that even organisations with strong internal security can be affected both directly and through a supply chain compromise.
As education continues its digital transformation, managing third-party cyber risk is becoming just as important as protecting the school's own network.

