On April 30, 2026, the extortion group ShinyHunters pulled roughly 3.65 terabytes of data out of Instructure’s cloud environment. By the time anyone outside Instructure knew about it, approximately 8,800 schools and universities were affected, and student records belonging to as many as 275 million people were in criminal hands. Names, email addresses, student IDs, and the contents of private Canvas messages had already been exfiltrated. Less than a week later, ShinyHunters defaced Canvas login pages at multiple institutions to prove they still had access, hours after Instructure had publicly declared the incident “resolved.”
If you’re a business leader at a school district, university, or an edtech vendor, the Canvas breach is not a story about Instructure. It’s a story about you. The students whose data was stolen are your students. The notification obligations under FERPA, COPPA, and state law fall to the institution, not the vendor. And the next supply chain attack that will impact the education industry will almost certainly involve a different vendor in a similar position.
This guide covers what business leaders in education should do about that, both now and in the long run.
Why Education Has Become a Primary Supply Chain Attack Target
TL;DR: Education has become a primary target for supply chain attacks because student data is uniquely valuable, the sector is consolidated around a few cloud platforms, and modern attacks exploit vendor APIs rather than school networks.
Three large edtech breaches in 18 months tell the story. PowerSchool was breached in early 2025, exposing data on approximately 62 million students. Infinite Campus followed in March 2026 with around 11 million records. Then Instructure in May 2026, with Canvas reaching roughly 41% of North American higher education institutions and a large share of K-12 districts. Three platforms, three breaches, hundreds of millions of student records, and the same threat actor (ShinyHunters) behind each incident.
This pattern isn’t an accident. Education is an appealing supply chain target for three reasons that aren’t going away.
- The data is uniquely valuable, since minors’ identities can be exploited for years before anyone notices.
- The sector is consolidated around a small number of cloud platforms, which means one successful breach yields data on millions of students.
- The attack technique used in these breaches doesn’t depend on breaking your firewall. It depends on compromising a vendor’s cloud environment, then using legitimate APIs to extract data that already had permission to be there.
That’s what makes this a supply chain problem. The attackers didn’t pick locks at 8,800 schools. They picked one lock at one vendor.
What Educational Institutions Should Do in Response to a Vendor Breach
TL;DR: Educational institutions responding to a vendor breach should take six immediate actions: demand institution-specific disclosure from the vendor, rotate all related credentials and active sessions, preserve logs before making changes, notify their cyber insurance carrier, communicate through channels other than the breached platform, and brief their help desk before issuing public notifications.
The action steps in this playbook apply to any edtech vendor breach. Whether you’ve been impacted by the Canvas breach or want to create an incident response plan in case of a future breach, these steps are applicable to both scenarios.
Get written, institution-specific disclosure from your vendors
Aggregate breach numbers don’t help your incident response. You need to know which of your records were accessed, when, and how. If your vendor contracts don’t already require this on a defined timeline, that’s a gap to close at your next renewal.
Rotate everything that touches the vendor
Rotate API keys, OAuth grants, SSO tokens, LTI integration secrets, SIS sync credentials, and active user sessions. If a credential was valid at any point during the vendor’s incident window, treat it as compromised. Force-terminate active sessions rather than just rotating passwords, since session tokens can be harvested separately and remain valid after a password change.
Preserve logs before you change anything
Once credentials are rotated, the evidence you’d need for a regulatory inquiry, an insurance claim, or your own forensic review may be unrecoverable. Capture admin audit logs, access logs, and SSO authentication logs before they roll off.
Notify your cyber insurance carrier
Many policies have notification windows measured in days, and the contractual liability cap on your vendor agreement is almost certainly far below your actual response costs.
Communicate through channels that aren’t the breached vendor.
If your LMS is compromised, don’t use it to deliver breach notifications. Use institutional email, SMS, or another form of communication that will reach your community.
Brief your help desk before students and families hear about it elsewhere
A simple FAQ on your institutional website, paired with a script for the people answering the phones, reduces call volume and keeps messaging consistent.
What Schools Should Tell Students, Parents, and the Community if a Breach Occurs: A Communication Checklist
TL;DR: After a breach, schools and universities should communicate the facts, the protective actions affected individuals should take, and the institution’s response, using channels other than the breached platform.
Effective post-breach communication balances transparency with accuracy. Affected individuals need enough information to protect themselves, without speculation or unnecessary alarm. The lists below cover the principles of breach communication, then provide audience-specific messaging you can adapt for your own notifications.
Principles for Every Breach Communication
- Lead with confirmed facts, not speculation.
- State clearly what data was exposed, what was not, and what’s still under investigation.
- Acknowledge the institution’s responsibility (depending on what systems were affected).
- Include specific, immediate protective actions the recipient can take.
- Tell recipients how to verify that breach-related communications are legitimate (direct them to your official website, not to links in emails).
- Date and version every communication so updates can be tracked.
Action Steps For Adult Students (Higher Education)
- Change institutional email password immediately.
- If that same password was reused on any other account, change those passwords as well.
- Enable multi-factor authentication on email, financial accounts, and Federal Student Aid account at studentaid.gov.
- Be alert to phishing emails that reference courses, instructors, or the specific breach. Do not click links in those emails. Go directly to official website(s).
Action Steps For Parents and Guardians of K-12 Students
- Change your child’s password and any other accounts where the same password was reused.
- If your child’s school-issued email account is tied to other systems (Google Workspace, Microsoft 365), secure those as well.
- Talk to your child about not clicking links in unfamiliar emails or messages, especially any that reference their school or teachers.
- For children under 13, additional protections under COPPA may apply.
- Consider placing a free credit freeze on your child’s credit file at Equifax, Experian, and TransUnion. The FTC’s identitytheft.gov has step-by-step instructions.
Action Steps For Faculty and Staff
- Change institutional credentials and any reused passwords immediately.
- If you have administrative or API access, rotate credentials.
- If you maintain LTI integrations, third-party tool connections, or API keys connected the incident, review and confirm which integrations are still required.
- Be alert to phishing campaigns that may impersonate institutional IT or other vendors.
What Edtech Vendors Should Do to Protect Schools and Universities
TL;DR: Edtech vendors should adopt an assume-breach posture for cloud integrations, apply aggressive data minimization, take third-party risk management seriously in their own supply chain, treat customer communication as part of the security product, and re-examine contractual liability caps that no longer match real breach response costs.
Vendors hold the data, which means vendors carry the burden of proving they’re worth the trust institutions extend. Here’s what that looks like in practice.
Adopt an assume-breach posture for cloud integrations
The Canvas incident didn’t involve endpoint malware or ransomware. It involved exploiting a cloud application, registering connected applications inside a SaaS environment, and extracting data through legitimate APIs. If your security model assumes attackers will arrive through a phishing email or a vulnerable workstation, you need to rethink your attack surface. Cloud-native attacks look like normal traffic to traditional tools.
Apply data minimization aggressively
The reason the Canvas breach exposed years of private messages is that years of private messages were still sitting in the platform. Every record retained is a record at risk, and your customers can’t control this; you can.
Take third-party risk management seriously in your own supply chain
Most edtech vendors integrate with dozens of upstream services, and many headline breaches in this sector started with a vendor of a vendor. If you can’t say where your customer data flows and who else has access to it, neither can your customers when their auditors ask.
Treat customer communication as part of the security product
The most damaging move Instructure made in the Canvas incident wasn’t the breach itself. It was declaring the incident “resolved” on May 6, then having attackers prove otherwise less than 24 hours later. Customers can absorb bad news, they can’t absorb being misled, even unintentionally. Be slow to claim resolution, fast to share what you know, and direct about what you don’t.
Re-examine your contractual liability caps
Standard edtech contracts often cap vendor liability at the annual subscription fee, a number now wildly out of proportion to the breach response costs institutions actually bear. The vendors that lead on this will be the ones that win enterprise contracts in 2026 and beyond.
How to Build Long-Term Resilience Against Supply Chain Attacks in Education
TL;DR: Long-term resilience against supply chain attacks requires a continuous security program rather than one-time assessments. That means continuous third-party risk management, data minimization, stronger contract terms, and a living integration map. In the long run, it means a Continuous Threat and Exposure Management (CTEM) posture that replaces the annual pentest with ongoing discovery, validation, and remediation.
The temptation after an incident like the Canvas breach is to file a memo, run a tabletop, and move on. That cycle hasn’t worked. The same threat actor breached three major edtech platforms in 18 months, and each incident was bigger than the last. The institutions and vendors that come out of this period in better shape will be the ones that build security as a continuous practice rather than an event.
That means including every vendor that touches student data in your third-party risk program, not just the ones whose contracts came up for review this year. It means assessing what data lives in each platform and purging what doesn’t need to be there. It means insisting on contract terms that require timely, institution-specific breach disclosure, meaningful liability allocation, and the right to audit. And it means treating your integration map, the catalog of every system connected to every other system, as a living security asset rather than a one-time compliance artifact.
For long-term proactive security, it means moving toward a Continuous Threat and Exposure Management (CTEM) posture: scoping what you protect, discovering what’s actually exposed, prioritizing by real exploitability, validating with adversary-style testing, and mobilizing remediation in a measurable way. An annual penetration test isn’t enough when your attack surface changes every sprint and the threat actors targeting your sector run automated reconnaissance continuously.
The institutions and vendors that take this seriously now will be in a different conversation a year from now. The ones that don’t will be writing the next breach advisory.
Where to Go From Here
For business leaders in education and the edtech vendors who serve them, the question isn’t whether something like this will happen again. It’s whether you’ll be ready. The actions in this guide (vendor disclosure, credential rotation, log preservation, data minimization, contract review, continuous exposure management) don’t depend on any one incident. They’re the foundation of a security program that holds up when your supply chain doesn’t.
If you’d like to talk through what continuous exposure management looks like for your institution or your edtech product, or you’d like a copy of the full SafeHill advisory on the Canvas incident, reach out to SafeHill. The next breach is already being planned. Your response shouldn’t be.