Publish date
August 26, 2026
{x} minute read
Written by
Reviewed by
Table of contents

Biggest Data Breaches in Education (Updated August 2026)

Education and edtech are among the most heavily targeted sectors in cybercrime, and the reason is structural. Schools, universities, and, by extension, their software vendors hold dense, long-lived records on minors and young adults; they run on thin security budgets; and they concentrate that data in a handful of platform vendors, each serving thousands of institutions.

When one vendor falls, the blast radius is national or global. The 2024 PowerSchool intrusion and the 2026 Instructure Canvas incident are the clearest illustrations, and they anchor this ranking of the largest and most consequential education data breaches known as of August 2026.

This ranked list covers 30 incidents, ordered primarily by either scale or notability, with several lower-count but high-notability cases included for their regulatory or precedent-setting weight. Where a figure is an attacker claim, a leaked-dataset count, or a press estimate rather than an organization-confirmed number, it is attributed to its source.

A pattern worth noticing before the list starts: in many cases below, the first evidence of a breach didn't come from the affected institution's own systems. It surfaced somewhere else first. A leaked credential dump or a researcher's dark web scan, long before any official notification went out.

Compliance landscape and sector statistics

In the US, a mix of federal and state laws protects student data, but the rules haven't kept pace with how often schools get breached. Education is now one of the most targeted sectors, so it's worth understanding which regulations apply and what they require.

The regulatory regimes that apply

The first thing to understand about student data protection in the United States is that the flagship federal law doesn't require security. No single standard governs litigation and enforcement; instead, state laws and regulators, along with privacy authorities abroad, create a patchwork of requirements.

The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. 1232g) governs education records held by schools and districts that receive US Department of Education funding, restricting disclosure of personally identifiable information without consent. FERPA contains no data security standard. It doesn't require encryption, multi-factor authentication (MFA), logging, incident response, or breach notification, and it carries no private right of action. The Supreme Court settled the latter point in Gonzaga University v. Doe, 536 U.S. 273 (2002). The statute's only sanction is termination of federal funding. Yet, the Department of Education has never imposed that penalty on any institution in FERPA's history, so families litigate breaches under state consumer-protection, negligence, and breach-notification theories instead.

The Children's Online Privacy Protection Act (COPPA) and the COPPA Rule (16 C.F.R. Part 312) apply to online services directed to children under 13. COPPA has real teeth because the Federal Trade Commission (FTC) can seek civil penalties per violation. The amended COPPA Rule finalized in 2025, with full compliance required in 2026, added a written children's information security program requirement, a data retention policy that prohibits indefinite retention, and separate opt-in consent for third-party disclosure and targeted advertising.

Like FERPA, COPPA has no private right of action; enforcement rests with the FTC and state attorneys general (AG). The Protection of Pupil Rights Amendment (20 U.S.C. 1232h) governs surveys probing protected categories. It restricts marketing-purpose collection, but its administrative enforcement mechanism is essentially never used as a breach remedy.

State student privacy laws contain the substantive obligations. California's Student Online Personal Information Protection Act (SOPIPA) prohibits targeted advertising to K-12 students and the sale of student data, and it requires reasonable security and deletion on request.

More than 40 states have enacted analogs since 2014, including New York Education Law 2-d and its Part 121 regulations, which impose security alignment and breach-notification duties on districts and vendors, and Illinois' Student Online Personal Protection Act (SOPPA), which leaves enforcement authority exclusively to the state Attorney General rather than creating a private right of action for parents.

For institutions in Europe, the General Data Protection Regulation (GDPR) and UK GDPR apply in full: Article 32 requires security appropriate to the risk, Articles 33 and 34 require breach notification, and Article 83 allows fines up to 20 million euros or 4% of global annual turnover.

FTC enforcement has built the clearest edtech precedent. The Commission's actions against Chegg (final order 2023), Edmodo (2023), and Blackbaud (final order 2024) targeted data minimization, retention, and misrepresentation rather than the breaches alone. The Securities and Exchange Commission (SEC) separately charged Blackbaud in March 2023 over misleading disclosures, settled for $3 million, and charged Pearson in August 2021 for the same reason, establishing that hedged breach disclosure is itself a securities-enforcement risk.

What the sector statistics show

Education sits mid-table by breach volume but is rising by cost, and the reported figures come with heavy caveats about what they count. The Identity Theft Resource Center reported 3,322 US data compromises in 2025, up 5% on 2024, with the education sector recording 188 compromises, fifth by industry, and PowerSchool topped the report's list at more than 71.9 million victim notices.

Several other measures round out the picture, and each carries an attribution you should preserve when citing it:

  • Cost is below average but climbing: IBM put the global average cost of a data breach at $4.44 million in 2025, down 9% year over year; the education sector average reported in the full IBM report was $3.8 million, below the global figure, yet education was among the minority of sectors whose costs rose.
  • Ransomware and people drive most breaches: The Verizon 2026 Data Breach Investigations Report found ransomware present in 48% of analyzed breaches, up from 44%, and a human element in 62%.
  • Education ransomware claims are mostly unconfirmed: Comparitech counted 104 ransomware attacks on education globally in the first half of 2026, but only 36 were confirmed by the target while 68 remained unconfirmed claims, with a median ransom demand of $420,620.

The two largest incidents on this list, PowerSchool and the Instructure Canvas breach, were both third-party platform compromises rather than attacks on individual schools. Vendor concentration, not district-level negligence, is the dominant driver of scale in education.

Where the first signal usually appears

Look at how the incidents below came to light, and a pattern emerges: schools, districts, and edtech vendors rarely catch a compromise on their own network first. They learn about it from a journalist, a state investigator, a parent who forwarded a ransom note, or a researcher who stumbled across a leaked dataset — often months after the access itself.

That's because the earliest evidence of a breach usually doesn't show up inside the institution at all. It shows up outside it: in stolen credentials harvested by infostealer malware, combolists traded on criminal marketplaces, and the back-and-forth of dark web forums and encrypted channels. Without dedicated threat intelligence built for that scale, the first anyone hears is usually from someone outside the institution.

30 biggest data breaches in education and EdTech

1. Instructure (Canvas LMS)

Records or individuals affected: Approximately 275 million user records and 3.65 TB of data across roughly 8,800 to 9,000 institutions—attacker-claimed figure, attributed to ShinyHunters, not confirmed by Instructure.

Date of breach: Initial access approximately April 25, 2026; second wave detected May 7, 2026

Date disclosed: May 2026

Country: United States (vendor), global victim base

Sub-sector: EdTech vendor (learning management system)

Attack vector: Attackers abused Instructure's "Free for Teacher" self-service account program as a foothold into production infrastructure, then exfiltrated large amounts of data and defaced institutional Canvas login portals with extortion messages.

Data types exposed: Usernames, email addresses, course names and codes, enrollment information, and in-platform messages, per the attackers' claims

Summary: ShinyHunters claimed to have exfiltrated 3.65 TB covering roughly 275 million Canvas users at close to 9,000 institutions worldwide. After defacing about 330 institutional login portals, the group announced a ransom agreement with Instructure on May 11, 2026, reportedly around $ 10 million, in exchange for deleting the data. Instructure hasn't confirmed the scale.

Aftermath: Plaintiffs filed class action litigation in the United States, institutional customers issued their own notifications, and higher education law firms published incident-response guidance.

Source: The Hacker News, Reed Smith client alert, UC Berkeley Law BCLT analysis

2. PowerSchool

Records or individuals affected: 62.4 million students and 9.5 million teachers across 6,505 school districts, per reporting on the criminal case; the Identity Theft Resource Center separately recorded more than 71.9 million victim notices.

Date of breach: December 19 to 28, 2024

Date disclosed: January 7, 2025

Country: United States, Canada, and other markets

Sub-sector: EdTech vendor (student information system)

Attack vector: Stolen credentials belonging to a subcontractor, used to log into PowerSchool's PowerSource customer support portal, which lacked MFA.

Data types exposed: Names, addresses, dates of birth, Social Security numbers for a subset, contact information, medical alert and health information, parent and guardian details, grades, and disciplinary records.

Summary: Federal prosecutors described this as the largest breach of children's data in US history: Matthew D. Lane and a co-conspirator used stolen credentials to pull down databases from 6,505 districts. PowerSchool paid a ransom for deletion, but the data wasn't destroyed, leading to follow-on extortion demands against individual districts in 2025.

Aftermath: Lane pleaded guilty and was sentenced on October 15, 2025, to four years in federal prison and roughly $ 14.1 million in restitution. A court granted preliminary approval to a PowerSchool class action settlement of $17.25 million on February 27, 2026.

Source: BleepingComputer, ITRC 2025 Annual Data Breach Report, CBC News

3. Edmodo

Records or individuals affected: Approximately 77 million records (76.6 million usernames and 43.4 million unique email addresses with bcrypt-hashed passwords, per Have I Been Pwned).

Date of breach: May 2017

Date disclosed: May 2017

Country: United States, global user base

Sub-sector: EdTech vendor (K-12 social learning platform)

Attack vector: Attackers exploited a vulnerability in Edmodo's user database, then exfiltrated and sold the data on the Hansa dark web marketplace.

Data types exposed: Usernames, email addresses, and bcrypt-hashed passwords.

Summary: Edmodo put tens of millions of schoolchildren's account records into criminal hands. The FTC's 2023 action against Edmodo set a major legal template by targeting business data retention models rather than breach security.

Aftermath: On May 22, 2023, the FTC and Department of Justice (DOJ) brought a COPPA Rule and FTC Act action alleging failure to obtain verifiable parental consent and indefinite data retention. The stipulated order imposed a suspended $6 million civil penalty and a permanent advertising injunction. Edmodo shut down US operations in 2022.

Source: FTC, US DOJ press release

4. Chegg

Records or individuals affected: Approximately 40 million users (relating to the April 2018 third-party cloud database incident).

Date of breach: Four incidents between 2017 and 2020.

Date disclosed: September 2018 for the 2018 breach; full picture detailed in FTC's October 2022 complaint.

Country: United States, global user base

Sub-sector: EdTech vendor (homework help, tutoring, textbook rental)

Attack vector: A former contractor's credentials gave access to an unsecured cloud database (2018); attackers phished employees in other incidents.

Data types exposed: Names, email addresses, shipping addresses, passwords weakly hashed with MD5, and scholarship application details (sexual orientation, religion, parents' income).

Summary: Chegg demonstrated the sensitive nature of edtech data by exposing self-reported demographics from scholarship applications alongside standard login credentials.

Aftermath: The FTC finalized an order on January 27, 2023, requiring Chegg to limit data retention, mandate MFA, and undergo independent security assessments.

Source: FTC press release, FTC case page

5. Blackbaud

Records or individuals affected: More than 13,000 customer organizations with millions of downstream constituents.

Date of breach: February to May 2020

Date disclosed: July 2020

Country: United States (vendor), with global institutional victims

Sub-sector: EdTech and non-profit SaaS vendor (fundraising, alumni relations, CRM)

Attack vector: Ransomware with prior data exfiltration against Blackbaud's self-hosted cloud environment.

Data types exposed: Alumni, donor, and student records including names, dates of birth, giving history, unencrypted bank account numbers, and Social Security numbers.

Summary: Hundreds of universities discovered they were breached through a third-party supplier. Blackbaud initially claimed attackers took no sensitive financial or identity numbers, but later revised SEC disclosures after discovering unencrypted SSNs and bank details were exposed.

Aftermath: Blackbaud settled with the SEC for $3 million in March 2023 over misleading disclosures, followed by a $49.5 million settlement with 49 state AGs in October 2023. Total regulatory and litigation exposure exceeds $100 million.

Source: The Record, Blackbaud newsroom statement, HIPAA Journal

6. MOVEit Supply Chain (Education Victims)

Records or individuals affected: Affected students at nearly 900 US colleges (via National Student Clearinghouse); University System of Georgia notified ~800,000 individuals; Colorado Dept of Higher Ed notified several hundred thousand.

Date of breach: Mass exploitation May 27–31, 2023

Date disclosed: June to October 2023

Country: United States, with global spillover

Sub-sector: Higher education, K-12, and education-adjacent vendors

Attack vector: Zero-day SQL injection in Progress Software's MOVEit Transfer (CVE-2023-34362), exploited by Clop ransomware.

Data types exposed: Names, dates of birth, SSNs, student ID numbers, enrollment and academic records.

Summary: Because the National Student Clearinghouse serves as the degree verification hub for US higher ed, a single MOVEit zero-day let Clop harvest data from hundreds of universities at once.

Aftermath: Plaintiffs proceeded with extensive consolidated multidistrict litigation against Progress Software, alongside a separate National Student Clearinghouse class settlement.

Source: Higher Ed Dive, SecurityWeek, National Student Clearinghouse settlement site

7. Illuminate Education

Records or individuals affected: Approximately 1.7 million current and former New York students across roughly 750 schools (per NY AG).

Date of breach: December 2021 and January 2022

Date disclosed: March 2022

Country: United States

Sub-sector: EdTech vendor (student information and special-education management)

Attack vector: Unauthorized access to Illuminate's hosted environment due to absent encryption and monitoring controls.

Data types exposed: Student names, dates of birth, special education status, disability accommodations, English language learner status, and behavioral records.

Summary: Illuminate highlighted the severe risk surrounding special education case management files. The breach compromised unencrypted records detailing delicate student accommodations and behavioral tracking across New York school districts.

Aftermath: In January 2023, Illuminate Education agreed to a $5.1 million settlement with the New York Attorney General following the breach. The settlement required a comprehensive data security program, including full encryption of stored student data.

Source: New York Attorney General, Wilson Sonsini analysis

8. Pearson

Records or individuals affected: 2018 AIMSweb: data connected to over 13,000 school accounts; 2025 GitLab token incident: individual count unpublished.

Date of breach: November 2018 (AIMSweb); January 2025 (GitLab token)

Date disclosed: July 2019 (AIMSweb); May 2025 (2025 incident)

Country: United Kingdom (parent company), United States (affected schools)

Sub-sector: EdTech vendor (assessment and courseware)

Attack vector: Compromise of AIMSweb 1.0 (2018); leaked GitLab Personal Access Token in a public repository giving access to cloud environments (2025).

Data types exposed: Student names, dates of birth, email addresses, source code, and cloud credentials.

Summary: The SEC sanctioned Pearson in 2021 for referring to the 2018 breach as hypothetical in public filings, even though the exfiltration had already occurred. The 2025 incident highlighted ongoing secrets-management risks in software development workflows.

Aftermath: The SEC charged Pearson plc in August 2021 with misleading investors, resulting in a $1 million civil penalty.

Source: SEC settlement order, BleepingComputer, EdScoop

9. Los Angeles Unified School District (LAUSD)

Records or individuals affected: 2022: ~500 GB of data leaked; 2024: threat actor claimed 24–26 million rows/records (unconfirmed by LAUSD).

Date of breach: July–September 2022 (Vice Society); June 2024 (Snowflake-linked)

Date disclosed: September 2022; June 2024

Country: United States

Sub-sector: K-12 school district (second largest in the US)

Attack vector: Vice Society ransomware (2022); compromise of a Snowflake cloud tenant without two-factor authentication (2024).

Data types exposed: Social Security numbers, confidential psychological assessments, payroll records, and medical records.

Summary: LAUSD became a focal point for K-12 cyber threats when Vice Society posted highly sensitive confidential psychological evaluations of students online after the district refused to pay a ransom.

Aftermath: The incident served as a primary catalyst for the White House K-12 Cybersecurity Summit in August 2023.

Source: BleepingComputer, TechCrunch, Cybernews, UpGuard

10. Clark County School District

Records or individuals affected: Attacker group "SingularityMD" claimed 200,000 student records (unconfirmed by district).

Date of breach: October 2023

Date disclosed: October 2023

Country: United States

Sub-sector: K-12 school district (Las Vegas, NV)

Attack vector: Compromised student Google Workspace accounts resulting from default passwords set to student birthdates.

Data types exposed: Student names, addresses, dates of birth, contact details, ID numbers, and internal emails.

Summary: Illustrates basic identity hygiene risks in public education. Default password policies let attackers take over accounts and email stolen records directly to parents to force ransom payments.

Aftermath: Parents filed class action claims, but a Nevada court ruled sovereign/governmental immunity shielded the district.

Source: BleepingComputer, The Nevada Independent

11. Minneapolis Public Schools

Records or individuals affected: Over 100,000 individuals notified by the district; ~300,000 files (143 GB) leaked by attackers.

Date of breach: February 17, 2023

Date disclosed: March 2023

Country: United States

Sub-sector: K-12 school district

Attack vector: Medusa ransomware with data exfiltration.

Data types exposed: Sexual assault allegations, mental health documentation, abuse reports, special education records, and staff SSNs.

Summary: Medusa published 300,000 files after the district refused a $1 million ransom demand. The leak exposed severe, highly confidential safeguarding files detailing student mental health and misconduct investigations.

Aftermath: Spurred federal action, contributing directly to the launch of the Federal Communications Commission Schools and Libraries Cybersecurity Pilot Program.

Source: The Record, The 74

12. University of California System (Accellion FTA)

Records or individuals affected: System-wide notice across 10 campuses; exact individual total unpublished.

Date of breach: December 24, 2020

Date disclosed: March 2021

Country: United States

Sub-sector: Higher education (public university system)

Attack vector: Zero-day vulnerabilities in Accellion's legacy File Transfer Appliance (FTA), exploited by Clop/FIN11.

Data types exposed: SSNs, bank details, dates of birth, driver's licenses, and medical information.

Summary: Clop exploited a single legacy file transfer tool to compromise multiple major universities, setting the precedent for the later MOVEit attacks. Attackers attempted direct extortion by emailing students and staff directly.

Aftermath: Accellion settled a consolidated class action for $8.1 million in 2022 and retired the FTA product.

Source: UC Notice of Data Breach, Inside Higher Ed

13. University of Manchester

Records or individuals affected: Attackers claimed 7 TB of data; press reported potential exposure of 1 million National Health Service patient records held for research (unconfirmed by university).

Date of breach: June 6–9, 2023

Date disclosed: June 2023

Country: United Kingdom

Sub-sector: Higher education

Attack vector: Undisclosed network intrusion.

Data types exposed: Student/staff personal records, proprietary research data, and shared health system datasets.

Summary: This breach demonstrates how university breaches can spill over into public health sectors when research databases are shared with national health services.

Aftermath: Reported to the UK Information Commissioner's Office (ICO) and the National Cyber Security Center.

Source: BleepingComputer, Infosecurity Magazine

14. British Library

Records or individuals affected: ~600 GB published (~490,000 documents), primarily affecting staff and select users.

Date of breach: October 28, 2023

Date disclosed: October 2023 (detailed post-mortem published March 2024)

Country: United Kingdom

Sub-sector: National research library and educational infrastructure

Attack vector: Rhysida ransomware via a compromised terminal services account lacking MFA.

Data types exposed: HR documents, National Insurance numbers, payroll, and internal operational files.

Summary: Highly notable for the British Library's transparent, published post-incident report outlining legacy technology risks, missing MFA, and technical debt.

Aftermath: The Library refused to pay the 20 bitcoin ransom. Recovery costs reached an estimated £7 million, causing multi-month service outages.

Source: Wikipedia overview with primary sources, SecurityWeek, Computer Weekly

15. Michigan State University

Records or individuals affected: Undisclosed count; restricted to Physics and Astronomy Department.

Date of breach: May 2020

Date disclosed: May 2020

Country: United States

Sub-sector: Higher education

Attack vector: NetWalker ransomware.

Data types exposed: Departmental student records and financial data.

Summary: Notable for MSU's public refusal to pay NetWalker's ransom demand despite public countdown timers, contrasting with other universities that quietly paid during the same campaign.

Aftermath: Law enforcement seized NetWalker infrastructure in January 2021.

Source: EdScoop, HIPAA Journal

16. Maastricht University

Records or individuals affected: Availability incident affecting ~25,000 students and 4,500 staff (267 servers encrypted).

Date of breach: December 23, 2019

Date disclosed: December 2019

Country: Netherlands

Sub-sector: Higher education

Attack vector: Phishing led to domain admin compromise; Clop ransomware deployed by TA505.

Data types exposed: Attackers exfiltrated minimal personal data; the incident primarily locked all operational systems.

Summary: The university paid 30 bitcoin (~€200,000) to restore operations before exams, then commissioned Fox-IT to publish a comprehensive technical review.

Aftermath: Dutch prosecutors seized a wallet containing part of the paid ransom in 2020. Because Bitcoin's value appreciated, the returned funds (~€500,000) exceeded the original ransom, and the excess proceeds were transferred to a student hardship fund.

Source: Fox-IT report, BleepingComputer

17. Finalsite

Records or individuals affected: ~5,000 schools and districts had web portals taken offline; no confirmed data theft.

Date of breach: January 4, 2022

Date disclosed: January 4, 2022

Country: United States, international base

Sub-sector: EdTech vendor (website hosting and communications)

Attack vector: Ransomware against Finalsite's hosting environment.

Data types exposed: None confirmed.

Summary: A pure availability breach demonstrating how vendor outages interrupt vital emergency and weather notification channels across thousands of school districts.

Aftermath: Connecticut AG issued a public advisory; Finalsite restored systems without evidence of data exfiltration.

Source: CNN, BleepingComputer, Connecticut Attorney General advisory

18. Western Sydney University

Records or individuals affected: ~10,000 individuals in an early 2025 single sign-on (SSO) compromise; ~7,500 in earlier 2023–2024 incidents.

Date of breach: Repeated incidents, 2023 through August 2025

Date disclosed: Progressive notifications through August 2025

Country: Australia

Sub-sector: Higher education

Attack vector: Compromise of SSO infrastructure, Isilon storage platforms, and Microsoft 365 environments.

Data types exposed: Student identifiers, demographic data, academic history, and health/financial information.

Summary: Demonstrates persistent posture weakness, where attackers repeatedly compromised distinct layers of institutional identity infrastructure over three years.

Aftermath: Reported to the Office of the Australian Information Commissioner (OAIC) and New South Wales Information and Privacy Commission; police charged an individual regarding earlier intrusions.

Source: Western Sydney University notification, Cyber Daily, Campus Review

19. Oracle E-Business Suite Zero-Day Campaign (Higher Ed Victims)

Records or individuals affected: UPenn confirmed 1,488 individuals (attacker claimed 1.2M); Clop claimed 1.3 TB from Harvard.

Date of breach: August–October 2025

Date disclosed: October–December 2025

Country: United States, global reach

Sub-sector: Higher education (Enterprise Resource Planning (ERP) software)

Attack vector: Zero-day exploitation of Oracle E-Business Suite (CVE-2025-61882) by Clop.

Data types exposed: Advancement data, donor databases, financial records, and SSNs.

Summary: Clop targeted enterprise resource planning platforms across major universities. At UPenn, attackers hijacked legitimate email systems to send mass extortion notes directly to donor lists.

Aftermath: Emergency Oracle patching, class action filings, and identity monitoring notifications.

Source: BleepingComputer on Penn, Dark Reading on Harvard, BleepingComputer on University of Phoenix

20. Australian National University (ANU)

Records or individuals affected: Data spanning 19 years of records; unconfirmed estimates place scope near ~200,000 individuals.

Date of breach: November 2018 (detected April 2019)

Date disclosed: June 2019

Country: Australia

Sub-sector: Higher education

Attack vector: Sophisticated spearphishing email campaign bypassing normal interaction controls, targeting Enterprise Systems Domain.

Data types exposed: Personal contact details, tax file numbers, bank account details, passport details, and academic transcripts.

Summary: Highly detailed incident report released by Vice-Chancellor Brian Schmidt in October 2019 provided rare visibility into state-sponsored cyber espionage tradecraft within higher education networks.

Aftermath: Worked with the Australian Cyber Security Center; drove significant national defense investment into Australian university cyber posture.

Source: ANU incident report, The Conversation, BBC News

21. Benesse Holdings

Records or individuals affected: Approximately 48.6 million customer records (company confirmed).

Date of breach: Discovered July 2014 (revised scope published September 2014)

Date disclosed: July 9, 2014

Country: Japan

Sub-sector: EdTech and correspondence education provider

Attack vector: Malicious insider at a subcontractor who copied database records onto a personal device.

Data types exposed: Parent and child names, physical addresses, phone numbers, sex, and birthdates.

Summary: The canonical education insider threat case. A systems contractor systematically copied tens of millions of records regarding children and sold them to external data brokers.

Aftermath: The Benesse president resigned; the Tokyo High Court eventually ordered Benesse and its contractor to pay damages to affected claimants, driving significant updates to Japan's Act on the Protection of Personal Information.

Source: South China Morning Post, Winston & Strawn, DataBreaches.net

22. Toronto District School Board (TDSB)

Records or individuals affected: Approximately 1.49 million past and present students dating back to 1985.

Date of breach: December 2024 (via PowerSchool portal breach)

Date disclosed: January 2025 (updates through November 2025)

Country: Canada

Sub-sector: K-12 school board (via vendor)

Attack vector: Downstream exposure from the PowerSchool PowerSource support portal compromise.

Data types exposed: Student names, dates of birth, Ontario health card numbers, addresses, special education files, and disciplinary records.

Summary: Highlights downstream vendor impact on public school boards, exposing four decades of archived student health and special education records.

Aftermath: Joint findings by privacy commissioners of Ontario and Alberta in November 2025 faulted TDSB for insufficient oversight of vendor security controls.

Source: Global News, CBC News, CP24, The Record

23. Miljödata

Records or individuals affected: Over 1.5 million individuals across Swedish municipal systems (includes a substantial portion of public school staff).

Date of breach: August 23–24, 2025

Date disclosed: August 2025

Country: Sweden

Sub-sector: HR SaaS vendor serving public municipal employers

Attack vector: Ransomware and exfiltration against Miljödata's "Adato" occupational health module by Datacarry group.

Data types exposed: Names, personal identity numbers, sick leave logs, rehabilitation notes, and occupational injury records.

Summary: Showed that supply-chain exposure extends into staff HR and occupational health platforms, affecting working conditions and private medical records of educators nationwide.

Aftermath: Swedish Authority for Privacy Protection initiated GDPR investigations into Miljödata and client municipalities in late 2025.

Source: BleepingComputer, Cybernews, DataBreaches.net

24. New York City Public Schools (MOVEit)

Records or individuals affected: Confirmed roughly 45,000 students and 19,000 employees (~64,000 individuals total) across ~19,000 accessed files, including ~9,000 SSNs.

Date of breach: Late May 2023

Date disclosed: June 23, 2023

Country: United States

Sub-sector: K-12 school district (largest in the US)

Attack vector: Exploitation of MOVEit Transfer zero-day (CVE-2023-34362) on the New York City Department of Education (NYC DOE)'s self-hosted instance.

Data types exposed: Employee IDs, student names, and Social Security numbers.

Summary: The NYC DOE was hit through its self-hosted MOVEit transfer server, just months after the district dealt with the Illuminate Education vendor breach.

Aftermath: Spurred stricter internal software deployment policies under New York State Education Law 2-d guidelines.

Source: Chalkbeat, K-12 Dive, Chalkbeat on cybersecurity rules

25. University of Nottingham

Records or individuals affected: 454,600 records cataloged on Have I Been Pwned; ShinyHunters claimed >40 GB of files.

Date of breach: June 2026

Date disclosed: June 10, 2026

Country: United Kingdom (with international campuses in Malaysia and China)

Sub-sector: Higher education

Attack vector: Unauthorized access to Campus Solutions student records platform.

Data types exposed: Names, addresses, dates of birth, passport numbers, citizenship, ethnicity, disability codes, and payment details.

Summary: ShinyHunters targeted major higher education institutions directly, harvesting sensitive demographic data including citizenship and disability classifications.

Aftermath: Formal report filed with UK ICO and Action Fraud; group litigation claims opened under UK GDPR.

Source: BleepingComputer, The Register, Have I Been Pwned, SecurityWeek

26. Providence Public Schools

Records or individuals affected: ~337,000 individual files (217 GB archive) leaked; district-confirmed individual count unpublished.

Date of breach: September 2024

Date disclosed: Autumn 2024

Country: United States

Sub-sector: K-12 school district (state-run)

Attack vector: Ransomware exfiltration, followed by a leak after non-payment of a $1M demand.

Data types exposed: Names, addresses, student health records, vaccination histories, special education files, and internal investigation records.

Summary: The district initially publicly denied that student files were exposed until independent research revealed sensitive internal child misconduct and health files in the published dump.

Aftermath: Public backlash over delayed notification; credit monitoring offered to affected families.

Source: The 74 on the ransomware attack, The 74 on the initial denial, Boston Globe, WPRI

27. Ohio State University (OSU)

Records or individuals affected: ~760,000 individuals notified.

Date of breach: October 22, 2010

Date disclosed: December 2010

Country: United States

Sub-sector: Higher education

Attack vector: Unauthorized server access used to launch secondary attacks.

Data types exposed: SSNs, names, addresses, and dates of birth.

Summary: Represents one of the largest proactive notifications in university history, as OSU notified 760,000 people out of caution despite finding no forensic proof of actual data exfiltration.

Aftermath: Cost OSU ~$4 million in response measures and drove sweeping policy changes to eliminate Social Security numbers as general system identifiers.

Source: IEEE Spectrum, Dark Reading

28. University of Nebraska

Records or individuals affected: Up to 650,000 current and former students, parents, and employees.

Date of breach: May 23, 2012

Date disclosed: May 2012

Country: United States

Sub-sector: Higher education

Attack vector: Authorized insider account abuse (university student gained elevated access to NeSIS database).

Data types exposed: SSNs, grades, addresses, housing files, and bank details.

Summary: A primary example of internal identity control failures, where an enrolled student bypassed permission boundaries to access millions of administrative identity records.

Aftermath: Internal monitoring detected the access; the university referred it to the FBI and Nebraska State Patrol for prosecution.

Source: SecurityWeek, Comparitech

29. Strategic Education, Inc.

Records or individuals affected: At least 111,706 across state filings (100,845 TX, 8,188 MA, 2,673 ME).

Date of breach: February 23–25, 2026

Date disclosed: June 2026

Country: United States

Sub-sector: Higher education (for-profit operator of Strayer & Capella Universities)

Attack vector: Unauthorized corporate network access and file exfiltration.

Data types exposed: Names, SSNs, driver's license numbers, and passport numbers.

Summary: Highlights the exposure of for-profit university operations holding extensive financial aid and identity verification documentation on adult learners.

Aftermath: Class action lawsuits filed; 12 months of credit monitoring offered to impacted individuals.

Source: Techtimes, ClassAction.org, Wolf Haldenstein alert

30. University of Duisburg-Essen

Records or individuals affected: Undisclosed individual count (1,200 servers encrypted; central identity directory destroyed).

Date of breach: November 27, 2022

Date disclosed: November 2022 (data published January 2023)

Country: Germany

Sub-sector: Higher education

Attack vector: Vice Society ransomware.

Data types exposed: Backup files, financial spreadsheets, academic research, and student lists.

Summary: The compromise of central directory servers forced the university to rebuild its entire IT infrastructure from scratch instead of restoring from compromised backups.

Aftermath: Refused to pay ransom; reported to North Rhine-Westphalia data protection authority.

Source: BleepingComputer, The Record, Times Higher Education

How Breach Risk helps you catch these threats first

Most entries on this list started the same way: a stolen credential, an unpatched server, a support portal without MFA, or a vendor nobody was actively watching. Breach Risk is built to catch that first layer by continuously monitoring your external attack surface alongside the open, deep, and dark web sources where stolen credentials, infostealer logs, and combolists surface long before an attacker gets further.

Explore the platform with a free trial or book a demo to walk through your institution's exposure.

Breach Risk pairs with two other product lines:

Vendor Risk: Assesses and monitors the security posture of student information systems, learning platforms, and other suppliers, giving districts visibility into vendor concentration risks.

User Risk: Discovers workforce risks such as compromised credentials and weak identity hygiene, preventing account takeover vectors.

Frequently asked questions

What is the biggest education data breach?

By claimed scale, the 2026 Instructure Canvas incident is the largest, with ShinyHunters claiming roughly 275 million user records (unconfirmed by Instructure). The largest confirmed breach of children's records is the 2024 PowerSchool intrusion, affecting 62.4 million students and 9.5 million teachers.

What was the PowerSchool data breach?

In December 2024, an attacker used stolen subcontractor credentials to access PowerSchool's un-MFA'd PowerSource support portal and downloaded databases from 6,505 school districts.

What happened in the Canvas data breach?

In 2026, extortion group ShinyHunters claimed to exfiltrate 3.65 TB of Canvas data by abusing a self-service teacher account feature, later defacing login portals across institutions. Instructure has not confirmed the claimed 275 million user record scale.

How common are data breaches in schools?

The Identity Theft Resource Center recorded 188 education-sector compromises in the US in 2025, while Comparitech recorded 104 global ransomware attacks on education during the first half of 2026.

What laws protect student data in the United States?

FERPA governs record disclosures but lacks specific technical security mandates. Practical protection relies on COPPA (for online services targeting children under 13) and state privacy frameworks like California's SOPIPA, New York Education Law 2-d, and Illinois SOPPA.