Artificial intelligence has made it easier for cyberattackers to breach college and university systems and steal valuable student and staff data. Canvas, education’s most high-profile victim this year, is remodeling its security to prepare for the inevitable next attempt.
What experts have learned is that many K12 districts and colleges may be sorely underprepared for the next evolution in cybersecurity.
“A lot of the conversation around cybersecurity in the next six months is going to be about speed,” says Zach Pendleton, chief architect at Instructure. “Everything that made a good security program a year ago still matters, but the speed at which we’re implementing them doesn’t match the moment.”
Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in education.
Your next read: Many teachers don’t trust AI. Utah has a plan
Experts at Instructure recognized earlier this year that conventional security practices were being challenged by AI-powered threats, Pendleton says. The company’s renewed defenses remained unfinished when the attack occurred.
“It was a pretty awful situation,” Pendleton adds. “What this means for LMS providers and education in general is that we were one of the first targets, but we’re not going to be the last.”
Retooling cybersecurity
The Canvas breach in May disrupted classes across dozens of districts. The hackers behind the attack claimed it exposed approximately 3.5TB of user data from more than 8,800 institutions.
The scope of the attack was an important reminder of how consequential learning management systems are to classroom operations. One polling firm found that most K12 teachers report using a learning management system occasionally or daily.
Faculty can best prepare for that level of disruption by backing up gradebooks and course rosters onto a server or storage device not owned by their learning management system.
Instructure plans to prevent further breaches by using AI to harden its defenses and speed up the security review process—a lesson that extends to all software providers working in education.
The company is also conducting more frequent penetration tests, which simulate real-world attacks to uncover vulnerabilities before cybercriminals can exploit them.
Instructure has developed tools that actively probe new code for weaknesses before it reaches production environments.
Districts should follow Canvas’ lead in strengthening their defenses as AI lowers the cost and complexity of cyberattacks, Pendleton says. Districts need to test systems more rigorously so they can identify and react to threats more quickly. They should also consider introducing Zero Trust Security practices and consider cybersecurity during every phase of their operations.





