EdTech Incident Library
A running, sourced record of the major K-12 and EdTech data security incidents that shape how districts think about vendor risk. Each entry covers what happened, what was exposed, and what a district can take away from it. Plain English, sources cited, no spin.
The common thread across every incident below: districts that know which vendors hold which data can tell families what was at risk. Districts that do not, cannot.
- ActiveHigher edJune 2026
University of Nottingham Data Breach
The same group behind the Canvas/Instructure incident hit a major university six weeks later through a different door. One threat actor, two education-sector victims, two entry points. Education is a named, repeat target.
- MonitoringK-12 + Higher edMay 2026
Canvas / Instructure Security Incident
Instructure, the Utah maker of Canvas, was hit by a two-wave security incident in late April and early May 2026. What happened, what was exposed, what Utah law requires districts to do, and what to tell families.
- ResolvedK-12 SIS vendorDecember 2024
PowerSchool SIS Breach
One stolen support credential, no MFA, and the student and teacher records of tens of millions of people walked out the door. Paying the ransom did not stop the attackers from coming back to extort individual districts five months later.
- ResolvedK-12 benefits administratorDecember 2024
Carruth Compliance Consulting Breach
K-12 vendor risk extends to the back office. A breach at a retirement-plan administrator exposed school-employee data across many districts at once.
- ResolvedK-12 safety vendorJanuary 2024
Raptor Technologies Cloud Exposure
No hacker required. Three unprotected cloud buckets from a school-safety vendor exposed lockdown plans, camera locations, and at-risk student files. Vendor cloud hygiene is a life-safety issue, not just a privacy one.
- ResolvedEducation data clearinghouseMid 2023
National Student Clearinghouse MOVEit Breach
The signature supply-chain breach of 2023. One file-transfer flaw cascaded across nearly 900 institutions, the textbook argument for tracking your vendors’ sub-processors.
- ResolvedK-12 districtFebruary 2023
Minneapolis Public Schools Ransomware
The most graphic illustration of what "student records" can actually contain, and a case study in failed breach notification. The district told families no personal information was compromised. It was wrong.
- ResolvedEdTech vendorOrder finalized January 2023
Chegg FTC Enforcement
The benchmark FTC EdTech security-enforcement action. Four breaches, plaintext data, no MFA, and a regulator holding a vendor accountable for its practices, not just a single event.
- ResolvedK-12 districtSeptember 2022
LAUSD Vice Society Ransomware
The marquee K-12 ransomware case of its era. The second-largest US district refused to pay, and the gang published 500GB of stolen data, setting a precedent other districts now weigh.
- ResolvedK-12 assessment vendor2021 breach, 2026 FTC order
Illuminate Education Breach and FTC Settlement
A former employee’s still-active login exposed the records of more than 10 million students, including special-education status, IEP details, and disciplinary records. The vendor denied it for weeks. The FTC order, finalized June 5, 2026, became the data-minimization benchmark for EdTech.
- ResolvedEdTech vendor2018 breach, 2021 SEC fine
Pearson AIMSweb Breach and SEC Action
The definitive "downplaying the breach" case. Pearson described an actual breach as a hypothetical risk, and the SEC fined it $1 million. The lesson is about honest disclosure.
Maintained by Ask Before You App. Not legal advice. Spotted an error or a missing incident? [email protected].