Publication
Back to School, Back to Resilience: Your Next Cyber Incident May Not Be Yours
Why Your Next Cyber Incident May Not Be Your Own
As students return to classrooms and campuses this fall, technology once again becomes the backbone of education. Learning management systems, student information systems, communication platforms, payroll, transportation, food services, and countless other cloud-based tools help schools operate every day.
That convenience also creates a new reality: a school can experience a major cyber incident without ever being the organization that was hacked.
The recent 2026 Canvas cyberattack serves as one of the clearest examples to date.
What Happened in the Canvas (Instructure) Breach?
Instructure reported detecting unauthorized activity within Canvas on April 29, 2026. According to the company, attackers accessed information including usernames, email addresses, student identification numbers, course and enrollment information, and messages exchanged through the platform. Instructure stated there was no evidence that passwords, government identification numbers, financial information, course submissions, or core course content were compromised.
The group claiming responsibility, ShinyHunters, alleged it had obtained data associated with nearly 9,000 educational institutions. Instructure later confirmed the attackers exploited vulnerabilities involving its Free-for-Teacher environment and data-access mechanisms within the platform.
The incident escalated on May 7 when the attackers leveraged a second vulnerability to alter pages displayed to some Canvas users. Although Instructure detected and disabled the activity within approximately ten minutes, it temporarily took Canvas offline to investigate, contain the incident, and implement additional safeguards.
For schools, the practical consequences were immediate. Students could not retrieve assignments. Faculty members lost access to course materials. Exams and final projects were disrupted. Technology teams suddenly found themselves answering questions about an incident they neither caused nor could independently investigate, often with limited information from the vendor.
That is the anatomy of a modern third-party cyber incident.
What Made the Extortion Strategy Different
The attackers' handling of the stolen information made this incident especially noteworthy.
Traditional ransomware and data extortion campaigns typically focus on the organization whose systems were compromised. The victim organization is pressured to pay in exchange for a decryption key, the return of stolen data, or a promise not to publish it.
In this case, the attackers attempted to broaden the pressure well beyond Instructure.
After claiming the company had not adequately engaged with them, ShinyHunters published a list of approximately 1,400 schools and districts and encouraged those organizations to negotiate directly to prevent their data from being released. Messages displayed through compromised Canvas pages reportedly instructed schools to arrange their own payments regardless of whether Instructure paid. Some institutions reportedly contacted the attackers directly.
While this tactic was not entirely unprecedented, it represented a significant evolution in both scale and leverage.
Rather than viewing Instructure as the only victim, the attackers attempted to monetize the same breach thousands of times by turning every affected customer into a potential extortion target.
It was a divide-and-extort strategy.
By shifting pressure directly to individual schools, the attackers exploited uncertainty. Each institution faced its own concerns about student privacy, legal obligations, public communications, reputation, and operational continuity. Organizations with limited information could easily feel compelled to act independently if they believed their vendor might not resolve the situation quickly enough.
Instructure ultimately announced it had reached an agreement covering all affected customers, stating that the stolen data had been returned, digital destruction records had been provided, and the attackers agreed not to pursue individual institutions. Even so, cybersecurity professionals recognize an important reality: once data has been stolen, no organization can ever be completely certain that every copy has been destroyed.
The Lesson Is Bigger Than Canvas
The lesson is not that schools should avoid cloud services. Modern education depends on trusted technology providers.
The real lesson is that vendor dependency must be treated as an operational resilience issue, not simply a procurement exercise or an annual cybersecurity questionnaire.
Most incident response plans assume the crisis begins inside the school's own network. They explain how to respond when the organization discovers ransomware, unauthorized access, or a data breach within its own environment.
A vendor cyber incident raises a different set of questions that should be discussed and answered long before an actual event occurs, including:
- Who is responsible for contacting and coordinating with the affected vendor?
- Who determines whether the institution's data, systems, or users have been impacted?
- Who is responsible for preserving logs, integration records, and other evidence needed for the investigation?
- Who decides whether critical systems should remain connected or be temporarily isolated?
- Who communicates with teachers, students, parents, trustees, regulators, cyber insurance providers, law enforcement, and the media?
- How will instruction and critical business operations continue if the affected platform is unavailable during exams, enrollment, financial aid processing, payroll, or another mission-critical period?
Most traditional incident response plans were written for attacks against an organization's own network. As educational institutions become increasingly dependent on cloud providers and third-party platforms, those plans must also prepare leaders to respond when the cyber incident starts somewhere else.
What Schools Should Do Now
Fortunately, this is a challenge schools can prepare for. Cyber resilience isn't just about preventing attacks. It's about ensuring the organization can continue teaching, serving students, and making informed decisions when disruptions occur, even when those disruptions begin outside its own network. A few proactive steps can make a significant difference before the next vendor incident occurs.
- Identify your critical technology vendors. Determine which vendors support mission-critical operations and understand how instruction and business functions would continue if those services became unavailable.
- Establish a formal vendor risk management program. Go beyond procurement by conducting security reviews, maintaining current security contacts, defining breach notification requirements, and ensuring contracts clearly outline incident response expectations and responsibilities.
- Expand your incident response and business continuity plans. Develop a dedicated playbook for third-party cyber incidents that addresses leadership decision-making, vendor coordination, communications, legal counsel, cyber insurance, regulatory considerations, and continuity of operations.
- Exercise vendor compromise scenarios. Regularly conduct tabletop exercises that simulate a critical vendor cyberattack so leadership and response teams can practice making coordinated operational and strategic decisions before a real incident occurs.
The Bottom Line for Education Leaders
The Canvas incident should not be remembered simply because a major education platform was compromised. It should be remembered because it exposed a growing reality of modern cybersecurity: your organization doesn't have to be the one that gets hacked to experience a cyber crisis.
As another school year begins, educational leaders should ask themselves one question: If one of our most critical vendors experiences a cyberattack tomorrow, are we prepared to lead through it?
Connect with Our Team
Worried about third-party cyber risk across your vendors? Talk to Ice Miller's Tech, Privacy & Cyber Risk team about vendor risk programs, incident response playbooks, and tabletop exercises built for third-party incidents. Contact us.
This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.
