Preparing for the Next Data Breach: Steps Colleges, Universities, and Schools Should Take Now

Insights

Litigation and Dispute Resolution: Preparing for the Next Data Breach: Steps Colleges, Universities, and Schools Should Take Now

24 July 2026


The EdTech company Instructure startled the higher education world in May by informing users of its Canvas online learning platform that hackers had gained unauthorized access. Beyond the disruption to exams and year-end learning, the larger and more serious implication of this attack was the breach of student data. The hacker group ShinyHunters claimed responsibility for the attack and threatened to leak data associated with approximately 275 million individuals across over 8,800 institutions around the world. After several nerve-wracking days for administrations, faculties, students, and families, Instructure reached an agreement to pay ShinyHunters and subsequently received confirmation that the data had been deleted.

Instructure informed the public that the stolen data may have included:

  • Names
  • Email addresses
  • Student ID numbers
  • Messages sent through Canvas

Reports suggest there is no evidence of exposure of more sensitive data (e.g., SSNs, birthdates, financial information), but affected users should remain vigilant and alert for the misuse of their personal information.

Institutions of higher education and independent schools must remain on guard and prepared for the next cybersecurity incident. Those that were prepared for this breach had plans in place for such an event and were able to act and respond immediately.

Whether you managed this breach like a pro, were caught flat-footed, or somewhere in between, there are important steps to take in the event of the next major breach.

  • Work with Counsel: Prior to addressing impacted individuals, communicating with the impacted vendor, beginning internal investigations, or reaching out for third-party support, contact cybersecurity counsel. Lawyers are equipped to guide you through the regulatory notification obligations, provide advice, and allow the response to proceed under the attorney-client communications and work-product privileges.
  • Information and Cybersecurity Response: Following a cybersecurity incident, work with your information technology and cybersecurity teams to reset passwords and revoke and/or reissue credentials, API, and/or other developer keys.
  • Inform the School: We recommend issuing a short, plain-language update to the school community, including what information is known and what remains unknown at the time. Any such statement should be neutral and should not speculate on the actors, motives, or what data may have been compromised. Schools should also be mindful that an informal update is not a substitute for a formal breach notification.
  • Work with Your Cyber Insurance Carrier: Most cyber policies require notification of an incident. Understand the timeframe for such notification even if you do not expect that the costs will exceed your policy limit.
  • Issue Formal Notifications: Evaluate your regulatory notification obligations. Relevant federal laws include the Family Educational Rights and Privacy Act (FERPA) and the Children’s Online Privacy Protection Act (COPPA), along with over 100 state privacy statutes. Nearly all of these statutes require the institution (not the vendor) to issue the notifications.
  • Establish a Point of Contact: Following a major incident, we advise setting up a unique email address and phone number for inquiries and follow-up. Likewise, activate your incident response team, which should include high-level technical, legal, and operations professionals.
  • Perform an After-Action Assessment: Evaluate whether the technical tool has mitigated vulnerabilities such that its continued use does not pose a threat to the school community. Also assess what protections the platform may need to implement, and whether there are steps that you should have taken to further enhance protection of data.

We live in a time when the next breach is “when,” not “if.” Universities, colleges, and schools need to be prepared.