Normal view

There are new articles available, click to refresh the page.
Before yesterdayDataBreaches.Net

What Canvas learned from a massive cyberattack

By: Dissent
7 August 2026 at 09:39
Alcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed. Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton...

Source

TN: Sumner County Schools provides limited update on data breach

By: Dissent
2 August 2026 at 10:02
Abbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Board of Education on July 21, one day after the...

Source

Suspected cyberattack disrupts Oceanside, California, school district systems

By: Dissent
1 August 2026 at 10:18
DysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disruption but did not identify its cause. NC Pipeline reported that a separate district text described the incident as a cyberattack....

Source

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)

By: Dissent
27 July 2026 at 15:20
Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier...

Source

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

By: Dissent
24 July 2026 at 08:49
Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on this breach are at the end of this article.  Background In 1976, an Albuquerque detective had...

Source

IL: Weeks after cyberattack, ETHS students receive phishing scam emails

By: Dissent
24 July 2026 at 08:07
Bob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and came from a student’s ETHS email account. The emails were signed by “Human Resource”...

Source

TN: Data breach delays start of Sumner County school year

By: Dissent
22 July 2026 at 20:25
Camellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the district calendar so the problem could be resolved before students return...

Source

Instructure Incident Driving 58 Percent of Breach Notices in 2026

By: Dissent
22 July 2026 at 19:12
GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident —...

Source

The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem

By: Dissent
16 July 2026 at 16:46
Jeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the company began delivering the first wave of institution-specific data packets, through a permissioned file-sharing link...

Source

Uniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)

By: Dissent
8 July 2026 at 15:27
In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls.  The audit report found, in part: District officials did not adequately manage nonstudent network user accounts and permissions. As a...

Source

The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?

By: Dissent
6 July 2026 at 19:05
Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornography, and pedophilia.  Overview On March 18, 2026, DDoSecrets and Straight Arrow News reported on a dataset provided...

Source

Global Schools Holdings Cites Two Injunctions in a Bid to Chill Our Reporting. It Won’t Work.

By: Dissent
2 July 2026 at 14:15
My About page is pretty clear about legal threats: If you want to send me legal threats about my reporting or comments, knock yourself out, but don’t be surprised to see me report on your threat, any confidentiality sig blocks you may attach notwithstanding. I have been threatened with lawsuits many times, and to be...

Source

NI: Updated warning to parents over schools cyber attack

By: Dissent
29 June 2026 at 14:16
Niall Glynn and Auryn Cox report: The number of schools in Northern Ireland affected by a recent cyber-attack is larger than previously thought. In a letter issued by the Education Authority (EA) on Thursday, some parents were warned that their child’s personal data may have been accessed. The EA said the letters were sent to 23 schools,...

Source

ZA: Copying the wrong person on an email could be considered a data breach in South Africa

By: Dissent
29 June 2026 at 08:54
Jan Vermeulen reports: Misdirected internal emails that expose personal information can trigger mandatory data breach reporting under South Africa’s data privacy law, POPIA, even when the disclosure was accidental. Armand Swart, Hlonelwa Lutuli, and Isabella Keeves from Werksmans Attorneys said an Information Regulator enforcement notice against Central Johannesburg TVET College confirmed this position. The case...

Source

Iranian-Turkish national sought by US on hacking charges arrested in Montenegro

By: Dissent
26 June 2026 at 10:06
Predrag Milic  reports: An Iranian national who is wanted by the United States for mass hacking attacks that caused damage of $3.4 billion was arrested in Montenegro, police in the Balkan country said late Thursday. The 39-year-old man, who holds both the Iranian and Turkish citizenship, is wanted by a court in New York on multiple charges, including...

Source

UK: ICO statement on ‘Edtech examined’ report

By: Dissent
26 June 2026 at 09:01
The UK Information Commissioner’s Office (ICO) has released a report titled “EdTech examined — Key Findings from Our Audits.” The ICO issued the following statement to accompany the report’s release: Today, the ICO has published ‘Edtech examined’, a new report which outlines how we have worked directly with edtech providers to review and improve data protection practices...

Source

Global Schools Group Obtained Two Court Injunctions That Didn’t Seem to Change Much—and Might Backfire (1)

By: Dissent
20 June 2026 at 09:01
Following a major data security incident involving sensitive student and parent information, Global Schools Group sought court injunctions prohibiting the publication of data acquired by FulcrumSec. They obtained the injunctions, but once again, injunctions do not affect threat actors — or at least, not in the way the plaintiffs hoped.  Yesterday, DataBreaches reported that Global...

Source

Data analysis of the Global Schools Group breach, Part 2

By: Dissent
18 June 2026 at 12:59
In Part 1,  DataBreaches published some totals and aggregate data from the recent Global Schools Group data breach. All analyses and statistics were provided to this site by FulcrumSec, who had attacked Global Schools Group (GSG) and exfiltrated the data. Data from three of GSG’s school brands were included in Part 1. Data for the...

Source

Data analysis of the Global Schools Group breach, Part 1

By: Dissent
18 June 2026 at 10:46
This is the first part of a two-part report of findings from the Global Schools Group data breach. All statistical analyses and findings were provided to DataBreaches by FulcrumSec, and are presented to assist those investigating the breach as well as parents and employees who might be concerned as to what types of data were...

Source

Cybercriminals Are Targeting EdTech: Data Breaches and Ransomware Attacks on the Rise

By: Dissent
17 June 2026 at 07:48
Resecurity writes: The education technology (EdTech) sector has become a prime target for cybercriminals as attacks against educational institutions and related platforms continue to escalate. With sensitive data, including student records, employee information, and payment data, stored on EdTech systems, the sector has become an appealing target for cybercriminals seeking financial gain, data exploitation, and...

Source

❌
❌