Schools sit at the top of ransomware victim statistics year after year because they combine everything extortion crews prize: irreplaceable scheduling pressure (you cannot reschedule a semester), sensitive data on minors, aging and underfunded IT, distributed networks of buildings and contractors, and a track record of paying under pressure. The 2026 Canvas LMS breach — the learning platform used by thousands of schools hit by an extortion crew — was the year's highest-profile reminder that the education sector's problems extend beyond district networks to the vendor layer every district shares. Understanding why schools are targeted explains both the attacks and the under-resourced defense against them.
What do the numbers show?
Education consistently ranks among the most-attacked sectors in vendor ransomware telemetry, with K-12 districts the dominant victim class — hundreds of U.S. districts reported incidents annually through the mid-2020s. The Government Accountability Office has repeatedly reported on schools' cyber posture, noting rising incidents and districts' limited security budgets. Individual cases set the pattern's scale: Los Angeles Unified, the second-largest U.S. district, was hit in 2022 in an incident that disrupted systems at the year's start; districts from Baltimore County to Albuquerque have lost weeks of instructional time. The United States' Cybersecurity and Infrastructure Security Agency has run dedicated K-12 security programs — including grants and guidance campaigns — precisely because the sector's victimization is structural, not incidental.
Why exactly do attackers favor them?
- Downtime intolerance with fixed calendars. Ransomware leverage is about what stops when systems stop; attendance, scheduling, transportation, and payroll all freeze, and the public pressure to restore lands on superintendents, not CISOs — many districts do not have one.
- Data on minors. Student records — names, birthdates, addresses, health and special-education data, sometimes SSNs — are long-lived identity material, valuable in fraud and legally sensitive under FERPA, adding regulatory pressure to the extortion math.
- Aging, heterogeneous systems. Decades-old student-information systems, donated devices, building-control networks, and one-to-one device programs multiplying endpoints — managed by IT departments staffing a fraction of what equivalent-size businesses employ.
- Open by mission. Schools serve communities: parents need access, students bring their own devices, contractors and vendors plug in. An institution built for openness is structurally harder to close.
- Proven payouts. A history of payments — and of insurance coverage — keeps crews returning to a sector where extortion has demonstrably worked.
Why did Canvas change the picture?
Because it moved the target upstream. Districts can harden their own networks and still fall with a vendor: Canvas is a single platform underlying thousands of institutions' coursework, grading, and communication, so one intrusion at Instructure (late April 2026, per the company's acknowledgment and federal alerts) reached a whole sector at once — the same consolidation logic driving attacks on payments processors and regulators' associations. For districts, vendor risk stopped being an abstract questionnaire item and became the year's central incident: FERPA obligations, community notification, and a federal Department of Education alert all following from someone else's breach.
What actually helps?
The measures that repeatedly differentiate districts that recover well:
- MFA everywhere — staff email first. The single control most district incidents trace back to its absence.
- Tested offline backups of student-information and scheduling systems — the difference between restoring in days versus weeks.
- An incident-response plan that includes operations: how attendance, payroll, and communication run on paper; who calls whom; how families are notified.
- E-rate and grant funding used for security: the FCC's Schools and Libraries program expanded to cover security services, and CISA's K-12 resources map the practical starting points.
- Vendor risk as real risk: requiring breach-notification timelines and MFA/SOC attestations from the platforms holding student data — the Canvas lesson operationalized.
What can families do?
Treat school-account credentials as valuable — unique passwords and MFA on student and parent portals; watch for phishing referencing real teachers and courses, especially after any incident (attackers work from stolen context); and keep an eye on credit as children reach SSN-using milestones, since student-record breaches surface in identity fraud years later. Schools cannot buy their way out of a sector-wide pattern quickly; families' own hygiene is the layer the district's budget never covers.
For more context, read The cybersecurity skills shortage: how many jobs, and does it even exist?.
For more context, read open source security funding.
For more context, read cyber insurance.

