Education Sector Faces Rising Threats from Third-Party Software Breaches
Schools and universities are running out of ways to protect themselves when the software vendors they depend on get breached.

Key points
- 1,252 education sector data breaches reported in 2025, per Verizon's 2026 DBIR.
- 71% of those breaches entered through web application flaws.
- More than 100 organizations, many of them schools, were hit via a zero-day in Oracle's E-Business Suite in late summer 2025.
- Canvas, used by more than 8,000 institutions, was knocked offline mid-finals week by a ransomware group.
Cybercriminals have found a reliable angle on schools: don't attack the school, attack the software every school depends on. One breach of a shared platform can ripple through thousands of institutions at once, and there's often nothing the schools themselves could have done.
Verizon's 2026 Data Breach Investigations Report put 1,252 data breaches in the education sector last year. More than half involved malware (software designed to damage or disrupt systems), and 65% of those involved ransomware, where attackers encrypt files and demand payment for the key.
How did the hackers get in?
Web applications were the door. They accounted for 71% of education-sector breaches in the DBIR. In late summer 2025, a ransomware gang exploited a zero-day flaw, one with no patch yet available, in Oracle's E-Business Suite and hit more than 100 organizations, with a heavy concentration of educational institutions among them.
In May, a pair of attacks forced Instructure to take Canvas offline during final examinations. The group claiming responsibility negotiated directly with Instructure, promising not to extort individual schools further. Our earlier story on that attack traced an eight-month attack arc against Instructure. "Platforms like Canvas are critical infrastructure and should be protected as such," CEO Steve Daly said in a statement to media at the time.
Adversaries pick their timing deliberately. "I think the timing was not coincidental, that they looked at the end of the school year as when they would have maximum use," Adam Marrè, CISO at Arctic Wolf, told Dark Reading.
Should you worry?
Schools can't prevent a vendor breach, but they can shrink the damage. Marrè, speaking to Dark Reading, recommended three things: a third-party risk program that holds vendors contractually to breach notification and incident-response standards; identity controls, specifically single sign-on backed by multifactor authentication, kept under the school's own management; and a business-continuity plan built on the assumption that a breach will eventually succeed.
"You can't put the genie back in the bottle," Marrè told Dark Reading. "What you can do is make sure your institution can still run."
The structural problem is money. Schools face the same third-party exposure as large corporations but rarely have the budgets to match. A federal privacy law could shift some accountability to vendors, though KnowBe4 CISO advisor Erich Kron noted, in comments to Dark Reading, that even well-regulated sectors like healthcare keep getting breached.
The realistic near-term bet is AI-assisted detection tools lowering the cost of capabilities that were previously out of reach for under-resourced IT teams. Whether that closes the gap fast enough is the question worth watching.



