In May 2026, Instructure — maker of Canvas, one of the world's most widely used learning management systems — confirmed a criminal breach later claimed by the ShinyHunters extortion group, complete with a public "pay or leak" deadline. In Australia, Queensland's education department confirmed tens of thousands of students and staff were affected through its QLearn platform, and TasTAFE reported student data compromised. It followed the PowerSchool breach of 2024, which affected an estimated 62 million students globally.
The pattern is unmistakable: attackers have worked out that breaching one edtech vendor is more efficient than breaching a thousand schools. Your school's security perimeter now includes every company whose software touches your student data — and most schools have never listed them, let alone assessed them.
Why schools are especially exposed
A typical school runs an LMS, a student information system, an attendance app, a canteen system, a library platform, reading apps, a parent portal, a photo service and a dozen classroom tools — each holding some slice of student personal information, each with its own security posture. Research across Australian organisations found the overwhelming majority suffered negative impacts from a third-party or supply-chain breach in the past year, while only a minority run mature third-party risk programs. In education, with thin IT resourcing, the gap is wider still.
The questions to ask every edtech vendor
You don't need a procurement department to do meaningful due diligence. Before signing — and at renewal for the tools you already use — get written answers to:
- What data do you hold about our students, exactly? Then ask for less: data the vendor never receives can't be leaked.
- Where is it stored? Australian data residency should be your default expectation.
- How will you tell us about a breach, and how fast? A contractual notification window (72 hours is a reasonable ask) matters more than a marketing page about security.
- Do you support SSO and enforce MFA for both our users and your own staff and administrators?
- What happens at exit? Certified deletion of student data at contract end should be in writing.
- Have you been independently tested? Recent penetration test or SOC 2 / ISO 27001 evidence separates mature vendors from hopeful ones.
Five controls on your side of the fence
- Build the inventory. One spreadsheet: every system, what student data it holds, who owns the relationship, when the contract renews. This single artefact transforms your risk conversation.
- Least-privilege integrations. When platforms connect to your Microsoft 365 or student information system, scope the API access to the minimum — an attendance app doesn't need write access to your whole directory.
- Separate and monitor vendor accounts. Vendor support logins should be individually identifiable, MFA-protected, and disabled when not in use — not a shared "supplier" account that never expires.
- Include vendors in your incident response plan. The Canvas incident showed the awkward reality: you may learn about a breach of your students' data from the news. Decide in advance who calls whom, what you tell families, and when your OAIC notification obligations trigger.
- Watch the accounts, not just the perimeter. When a vendor is breached, the follow-on attack usually arrives through legitimate-looking logins and password reuse. Identity monitoring — unusual sign-ins, new mail rules, impossible travel — is where 24/7 SOC coverage earns its keep.
A note on ransoms
Australia's Cyber Security Act 2024 now requires organisations above $3 million annual revenue to report any ransomware payment to the Australian Signals Directorate within 72 hours — and paying a sanctioned group can itself breach sanctions law. The practical takeaway for school leadership: the "quietly pay and move on" option effectively no longer exists. Resilience — immutable backups, tested recovery, detection — is the only strategy left standing.
Want a vendor risk snapshot?
Our cybersecurity consulting includes a third-party risk review built for schools: we inventory your edtech stack, flag the risky integrations and hand you the contract clauses to ask for. Get a security assessment.