By Liora Ziv, Threat Intelligence Researcher at CyberProof
A Shift in How Education Is Being Compromised
Over the past year, cyberattacks targeting educational institutions have evolved well beyond opportunistic ransomware campaigns. While public reporting continues to emphasize disruption or data leaks, recent incidents reveal a more consistent pattern: attackers are no longer breaking into these environments in the traditional sense. Instead, they are operating within them, leveraging valid identities, SaaS access, and trusted relationships to move laterally without triggering conventional detection mechanisms.
This trend is no longer theoretical. Recent attacks linked to the threat group ShinyHunters against Udemy and Instructure demonstrated how attackers are increasingly targeting the centralized SaaS platforms on which modern education environments depend. Rather than focusing on a single university or school, these campaigns leveraged weaknesses in shared infrastructure and identity layers capable of impacting thousands of institutions simultaneously.
The broader data reflects the same escalation. Recorded cyber incidents in the education sector increased by 63% year-over-year, rising from 260 incidents between November 2023 and October 2024 to 425 incidents between November 2024 and October 2025. Across 67 countries, education-related data breaches increased by 73%, while hacktivist activity rose by 75%. This trend is further reinforced by findings from the UK Government’s Cyber Security Breaches Survey 2025/2026, which showed that 98% of universities and 88% of further education colleges identified a breach or attack within the previous 12 months — significantly higher than the broader business average.[1][2]
These numbers reinforce a growing reality: education institutions are not simply being targeted more often, but are increasingly being targeted through the platforms, trust relationships, and identity systems that underpin modern academic operations.
Identity Persistence as an Inherited Weakness
At the core of these intrusions is a structural issue: the way identities are created, maintained, and forgotten within education environments. Educational institutions continuously provision access for students, faculty, researchers, and external collaborators, yet identities are rarely retired with the same rigor.
Over time, this creates a growing pool of valid credentials with unclear ownership — alumni accounts, shared lab access, and temporary research identities that persist beyond their intended use. This accumulated “identity debt” does not need to be exploited in the traditional sense; it can simply be used.
In many education environments, identity expiration lags far behind access revocation — creating an attack surface that adversaries can quietly inherit.
Groups such as ShinyHunters increasingly operate within this model. Rather than relying exclusively on malware deployment or perimeter exploitation, recent campaigns have leaned heavily on credential compromise, social engineering, SaaS abuse, and the compromise of trusted third-party access paths. Reporting surrounding the Udemy incident indicated the exposure of approximately 1.4 million records containing personally identifiable information, instructor payout data, corporate information, and account details after the company allegedly refused extortion demands. The leaked data was later indexed by Have I Been Pwned, significantly increasing downstream phishing and credential-stuffing risks.[3]
How SaaS Becomes the Intrusion Layer After Authentication
Once access is established, attackers rarely pivot to endpoints. Instead, they embed themselves within SaaS platforms where institutional communication, coursework, and operational data reside.
The Canvas breach highlighted this shift clearly. In May 2026, ShinyHunters claimed responsibility for compromising approximately 3.65TB of data tied to nearly 275 million students, faculty members, and staff across roughly 9,000 schools worldwide. Investigations into the incident indicated that the attackers initially exploited weaknesses associated with “Free-for-Teacher” accounts before pivoting deeper into the broader platform environment, ultimately leveraging the shared nature of the SaaS architecture to impact institutions simultaneously.[4]
The significance of the incident was not only the scale of exposed data, but the operational dependency it revealed. By compromising a centralized SaaS platform, attackers gained potential visibility into usernames, institutional email addresses, enrollment information, course structures, and communications spanning thousands of institutions simultaneously.
This reflects a broader evolution in intrusion methodology:
- Mailbox manipulation replaces malware deployment
- OAuth persistence replaces endpoint footholds
- API-driven access replaces interactive sessions
The intrusion layer increasingly exists inside the SaaS environment itself.
Use Case: SaaS Persistence Through OAuth and Mailbox Manipulation
In one recurring pattern, a compromised low-privilege identity is used as an entry point into cloud platforms such as Microsoft 365 or Google Workspace. Rather than escalating privileges immediately, attackers focus on persistence mechanisms that survive password resets and blend into legitimate activity.
This typically involves:
- Granting OAuth permissions such as Mail.Read or Files.Read.All
- Creating forwarding rules to external infrastructure
- Suppressing or deleting security-related notifications
- Leveraging API-based access to reduce visibility
These techniques are particularly effective within education environments due to the large number of unmanaged identities, decentralized administration models, and extensive SaaS adoption.
Indicators associated with these intrusion patterns commonly include:
- OAuth consent granted outside expected administrative workflows
- Sudden spikes in Microsoft Graph or Google API activity
- Mailbox forwarding rules redirecting communications externally
- Access originating from infrastructure not historically associated with the user
IT Impersonation and the Abuse of Operational Trust
Recent campaigns have also demonstrated how attackers increasingly target operational workflows rather than software vulnerabilities alone. Threat actors impersonate IT personnel or support staff to initiate MFA resets, password changes, or device registration processes that appear legitimate to end users.
This reflects a broader shift toward identity-centric intrusion models where operational trust becomes the primary attack surface.
The timing of the Canvas attacks further highlighted how adversaries strategically align operations with academic cycles. Portions of the campaign coincided with examination and enrollment periods, maximizing operational pressure on institutions and increasing the likelihood of user error and delayed response.[5]
Federated Environments and Cross-Institution Exposure
The education sector’s reliance on federated identity systems introduces an additional dimension of risk. Research environments frequently allow access across institutions, enabling collaboration but also expanding the potential blast radius of a single compromised identity.
Unlike enterprise systems, these environments are often less tightly monitored and operate on trust-based access models. As a result, compromise does not remain isolated.
The Canvas incident demonstrated this challenge at scale. Following initial access, attackers reportedly defaced approximately 330 institution-specific login portals while leveraging the shared nature of the platform to create operational disruption across universities and K-12 environments simultaneously. Institutions reportedly impacted included major universities such as Harvard, Stanford, Columbia, and Rutgers.
This reinforces a growing reality for defenders: in education, vendor compromise increasingly becomes institutional compromise.
Ransomware Shifting from Disruption to Data Access
Although ransomware continues to feature in attacks against educational institutions, the operational model used by groups such as ShinyHunters demonstrates that encryption is no longer necessary to create pressure.
Instead, modern extortion campaigns increasingly prioritize:
- Large-scale data theft
- Leak-site pressure
- Direct institutional negotiation
- Public exposure of sensitive records
In both the Udemy and Canvas incidents, operational disruption was amplified through the threat of public exposure rather than widespread encryption activity. In the Canvas case, attackers escalated beyond data theft by defacing institution-specific portals and directly pressuring affected organizations during finals season — maximizing reputational and operational impact simultaneously.
Conclusion
Education institutions are not being targeted simply because they are under-resourced, but because their operating model — open, collaborative, and heavily dependent on identity and trust — creates conditions that can be systematically exploited.
The recent campaigns targeting Udemy and Canvas demonstrate that the primary risk to the sector is no longer confined to individual institutions. Instead, it increasingly resides within the centralized platforms, federated identities, and shared SaaS ecosystems on which modern education environments depend.
As these ecosystems continue to expand, the challenge is no longer limited to preventing unauthorized access. It is increasingly about understanding how legitimate access is abused, how far compromise can propagate across interconnected environments, and how quickly operational dependency can transform a single intrusion into sector-wide disruption.
##
ABOUT THE AUTHOR

Liora Ziv is a cyber threat intelligence analyst who combines a strategic view of global cyber trends with the analysis of modern threat-actor behavior. With a background in international relations and fluency in multiple languages, she brings a global, contextual lens to her work, helping organizations better understand the forces shaping today’s cyber landscape.
[1] https://www.infosecurity-magazine.com/news/cyberattacks-surge-63-annually/?utm_source=chatgpt.com
[2] https://www.infosecurity-magazine.com/news/uk-education-sector-faces-surge-in/?utm_source=chatgpt.com
[3] https://cybersecuritynews.com/udemy-data-breach/?utm_source=chatgpt.com
[4] https://www.darkreading.com/cyberattacks-data-breaches/instructure-breach-exposes-schools-vendor-dependence?utm_source=chatgpt.com
[5] https://dnyuz.com/2026/05/09/canvas-hack-exposes-schools-vulnerability-to-cyberattacks/?utm_source=chatgpt.com






