Student data breaches in edtech

Student Data Breaches in EdTech

Recent Incidents and What They Mean for SEL Procurement

In December 2024, a 20-year-old college student used stolen credentials to access PowerSchool's customer support portal and exfiltrate the personal records of approximately 62 million students and 9.5 million teachers across more than 6,500 school districts. It was the largest breach of children's data in United States history.[1]

PowerSchool paid a $2.85 million ransom. The attacker provided a video purporting to show the data being deleted. The attacker then turned around and extorted individual school districts directly, proving the deletion video was fabricated.[3]

This is the world that districts are procuring SEL curriculum into.

The Breach Landscape

Dec 2024

PowerSchool: 62 Million Student Records

62M

Students

6,500+

Districts

$17.25M

Settlement (CPS)

$2.85M

Ransom paid

Stolen credentials on a support portal. SSNs, dates of birth, addresses, medical alerts. Data going back 20+ years. Attacker extorted districts after being paid. Cybersecurity experts now recommend credit freezes for kindergartners.[1][2][4]

Apr–May 2026

Canvas/Instructure: 275 Million Records Claimed

275M

Records claimed

8,809

Institutions

1,616

K-12 Districts

Breached twice

Same ShinyHunters group as PowerSchool. Breached twice in one month. 3.65 TB of data including private student-teacher messages. Instructure paid an undisclosed ransom. Dept. of Education issued a Technology Security Alert.[10][11][12][14]

Jan 2022

Illuminate Education: 1.7M Students, $5.1M Settlement

Credentials from an employee who left 3.5 years earlier still worked. Failed to encrypt data at rest. Ignored a 2020 security warning. First enforcement under California's KOPIPA. FTC consent order requiring data deletion.[5][6][7]

Feb 2023

Minneapolis: Mental Health Records Published Online

Refused $1M ransom. Medusa group published 300,000 files: sexual misconduct cases, child abuse inquiries, mental health crisis records, suspension reports. Not academic records — records of children's most vulnerable moments.[8]

2025

Gaggle/Vancouver: 3,500 Sensitive Records Exposed

Student poems, essays, and AI chat transcripts collected by a monitoring tool exposed through unprotected links. No password. No encryption. No access controls. Data collected for “safety” was accessible to anyone.[9]

Paying the ransom does not work

PowerSchool paid $2.85M for a deletion video → attacker extorted districts anyway. Instructure paid an undisclosed ransom → received “shred logs.” Independent verification of data destruction is not possible.

Once data is exfiltrated, it is gone. The only protection is not having it stored.

What This Means for SEL

SEL data is uniquely sensitive

When Minneapolis published mental health crisis records, it exposed exactly the kind of information that SEL platforms routinely collect: emotional assessments, behavioral flags, intervention notes, check-in responses. The difference between those records and the data on an SEL vendor's servers is not sensitivity — it is whether the breach has happened yet.

Every vendor is a potential breach vector

PowerSchool: stolen credentials. Illuminate: ex-employee credentials (3.5 years old). Gaggle: unprotected links. Minneapolis: ransomware. Canvas: same group exploiting systems twice. The methods vary. The result is the same. These are not obscure vendors — they are dominant platforms.

The regulatory environment is tightening

All 50 states have breach notification statutes. State AGs are pursuing vendors. FTC consent orders. Settlements in the millions. 59% of districts report higher cyber insurance premiums. The cost of storing student data now includes legal exposure, insurance, notification, and remediation.[8][10]

The SEL Procurement Question

The question is not whether your vendor's security is good enough. PowerSchool's was supposed to be. Illuminate's was supposed to be. The question is whether the curriculum needs to generate the data that creates the risk.

Digital SEL platform stores:

  • • Student names and identifiers
  • • Mood check-in responses
  • • Emotional self-assessment data
  • • Behavioral incident records
  • • Teacher notes on SEL development
  • • Progress monitoring data
  • • Intervention flags

Each point = breach risk you don't control

Device-free, account-free curriculum stores:

Nothing

No student records to breach. No emotional assessments in a database. No mood check-ins on a cloud platform. No data to exfiltrate, extort, or expose.

Zero breach exposure

What Districts Should Do

1

Audit your current SEL vendor's data practices

Request a complete inventory: what data is collected, where stored, who has access, retention period, and what happens if the contract ends or vendor is acquired.

2

Evaluate breach history and security posture

Ask directly whether the vendor has experienced a breach. Review their incident response plan. Ask who bears breach notification costs — vendor or district.

3

Assess whether the data is necessary

For every data point collected, ask: does this improve instruction enough to justify breach risk? If no, the data should not be collected.

4

Consider separating instruction from assessment

Let the curriculum teach. Let a validated screener (DESSA, Panorama) measure. Don't require both from a vendor whose primary competency is content, not data security.

5

Reduce your vendor footprint

Every vendor storing student data is a breach vector. A device-free SEL curriculum removes one vendor from the data governance landscape entirely.

The Calculation

62M

PowerSchool records

275M

Canvas records claimed

$22.35M

In settlements

2

Ransoms paid (neither verified)

1

FTC consent order

18 mo

Timeframe for all of this

The simplest way to protect children's social-emotional data is to choose a curriculum that never collects it.

References

  1. TechPolicy.Press. (2026). Unmasking EdTech's Surveillance Infrastructure in the Age of AI. techpolicy.press
  2. EdCircuit. (2025). PowerSchool Data Breach 2025: What Schools Must Know. edcircuit.com
  3. Cloudskope. (2025). PowerSchool Breach 2025: 60M Student Records. cloudskope.com
  4. Captain Compliance. (2026). The PowerSchool Settlement. captaincompliance.com
  5. The Data Advisor (WilmerHale). (2025). EdTech Provider $5.1M Settlement. wsgrdataadvisor.com
  6. GovTech. (2025). Ed-Tech Company Reaches Settlement Over Data Breach. govtech.com
  7. JD Supra. (2025). FTC's Illuminate Education Order. jdsupra.com
  8. Stingrai. (2026). Education Data Breach Statistics 2026. stingrai.io
  9. University of Washington. (2025). Privacy by Design Framework for LLM Applications for Children. arxiv.org
  10. National Cybersecurity Alliance. (2026). Canvas Data Breach. staysafeonline.org
  11. K-12 Dive. (2026). 2nd Canvas data breach causes major disruptions. k12dive.com
  12. Tech Insider. (2026). Instructure Canvas Breach: 275M Records. tech-insider.org
  13. Reed Smith. (2026). Canvas/Instructure Cyberattack: Key Developments. reedsmith.com
  14. U.S. Dept. of Education, FSA. (2026). Technology Security Alert: Canvas LMS. fsapartners.ed.gov

No Data Stored. No Data to Breach.

Be The Buffalo collects zero student data. No accounts. No logins. No emotional assessments stored on any server. The teacher projects the lesson. The class participates together. Full SEL instruction with zero breach exposure. Because data that doesn't exist can't be stolen.

Sign Up Free

Related Resources