EdTech Incident Library

A running, sourced record of the major K-12 and EdTech data security incidents that shape how districts think about vendor risk. Each entry covers what happened, what was exposed, and what a district can take away from it. Plain English, sources cited, no spin.

The common thread across every incident below: districts that know which vendors hold which data can tell families what was at risk. Districts that do not, cannot.

  1. ActiveHigher edJune 2026

    University of Nottingham Data Breach

    The same group behind the Canvas/Instructure incident hit a major university six weeks later through a different door. One threat actor, two education-sector victims, two entry points. Education is a named, repeat target.

  2. MonitoringK-12 + Higher edMay 2026

    Canvas / Instructure Security Incident

    Instructure, the Utah maker of Canvas, was hit by a two-wave security incident in late April and early May 2026. What happened, what was exposed, what Utah law requires districts to do, and what to tell families.

  3. ResolvedK-12 SIS vendorDecember 2024

    PowerSchool SIS Breach

    One stolen support credential, no MFA, and the student and teacher records of tens of millions of people walked out the door. Paying the ransom did not stop the attackers from coming back to extort individual districts five months later.

  4. ResolvedK-12 benefits administratorDecember 2024

    Carruth Compliance Consulting Breach

    K-12 vendor risk extends to the back office. A breach at a retirement-plan administrator exposed school-employee data across many districts at once.

  5. ResolvedK-12 safety vendorJanuary 2024

    Raptor Technologies Cloud Exposure

    No hacker required. Three unprotected cloud buckets from a school-safety vendor exposed lockdown plans, camera locations, and at-risk student files. Vendor cloud hygiene is a life-safety issue, not just a privacy one.

  6. ResolvedEducation data clearinghouseMid 2023

    National Student Clearinghouse MOVEit Breach

    The signature supply-chain breach of 2023. One file-transfer flaw cascaded across nearly 900 institutions, the textbook argument for tracking your vendors’ sub-processors.

  7. ResolvedK-12 districtFebruary 2023

    Minneapolis Public Schools Ransomware

    The most graphic illustration of what "student records" can actually contain, and a case study in failed breach notification. The district told families no personal information was compromised. It was wrong.

  8. ResolvedEdTech vendorOrder finalized January 2023

    Chegg FTC Enforcement

    The benchmark FTC EdTech security-enforcement action. Four breaches, plaintext data, no MFA, and a regulator holding a vendor accountable for its practices, not just a single event.

  9. ResolvedK-12 districtSeptember 2022

    LAUSD Vice Society Ransomware

    The marquee K-12 ransomware case of its era. The second-largest US district refused to pay, and the gang published 500GB of stolen data, setting a precedent other districts now weigh.

  10. ResolvedK-12 assessment vendor2021 breach, 2026 FTC order

    Illuminate Education Breach and FTC Settlement

    A former employee’s still-active login exposed the records of more than 10 million students, including special-education status, IEP details, and disciplinary records. The vendor denied it for weeks. The FTC order, finalized June 5, 2026, became the data-minimization benchmark for EdTech.

  11. ResolvedEdTech vendor2018 breach, 2021 SEC fine

    Pearson AIMSweb Breach and SEC Action

    The definitive "downplaying the breach" case. Pearson described an actual breach as a hypothetical risk, and the SEC fined it $1 million. The lesson is about honest disclosure.

Maintained by Ask Before You App. Not legal advice. Spotted an error or a missing incident? [email protected].

EdTech Incident Library | Ask Before You App