Schools sit at the top of ransomware victim statistics year after year because they combine everything extortion crews prize: irreplaceable scheduling pressure (you cannot reschedule a semester), sensitive data on minors, aging and underfunded IT, distributed networks of buildings and contractors, and a track record of paying under pressure. The 2026 Canvas LMS breach — the learning platform used by thousands of schools hit by an extortion crew — was the year's highest-profile reminder that the education sector's problems extend beyond district networks to the vendor layer every district shares. Understanding why schools are targeted explains both the attacks and the under-resourced defense against them.
What do the numbers show?
Education consistently ranks among the most-attacked sectors in vendor ransomware telemetry, with K-12 districts the dominant victim class — hundreds of U.S. districts reported incidents annually through the mid-2020s. The Government Accountability Office has repeatedly reported on schools' cyber posture, noting rising incidents and districts' limited security budgets. Individual cases set the pattern's scale: Los Angeles Unified, the second-largest U.S. district, was hit in 2022 in an incident that disrupted systems at the year's start; districts from Baltimore County to Albuquerque have lost weeks of instructional time. The United States' Cybersecurity and Infrastructure Security Agency has run dedicated K-12 security programs — including grants and guidance campaigns — precisely because the sector's victimization is structural, not incidental.
Why exactly do attackers favor them?
- Downtime intolerance with fixed calendars. Ransomware leverage is about what stops when systems stop; attendance, scheduling, transportation, and payroll all freeze, and the public pressure to restore lands on superintendents, not CISOs — many districts do not have one.
- Data on minors. Student records — names, birthdates, addresses, health and special-education data, sometimes SSNs — are long-lived identity material, valuable in fraud and legally sensitive under FERPA, adding regulatory pressure to the extortion math.
- Aging, heterogeneous systems. Decades-old student-information systems, donated devices, building-control networks, and one-to-one device programs multiplying endpoints — managed by IT departments staffing a fraction of what equivalent-size businesses employ.
- Open by mission. Schools serve communities: parents need access, students bring their own devices, contractors and vendors plug in. An institution built for openness is structurally harder to close.
- Proven payouts. A history of payments — and of insurance coverage — keeps crews returning to a sector where extortion has demonstrably worked.
Related stories: Match Group confirms cybersecurity incident after ShinyHunters claim 10 million records · Cyber insurance explained: what policies cover, what they demand, and what they exclude.
Why did Canvas change the picture?
Because it moved the target upstream. Districts can harden their own networks and still fall with a vendor: Canvas is a single platform underlying thousands of institutions' coursework, grading, and communication, so one intrusion at Instructure (late April 2026, per the company's acknowledgment and federal alerts) reached a whole sector at once — the same consolidation logic driving attacks on payments processors and regulators' associations. For districts, vendor risk stopped being an abstract questionnaire item and became the year's central incident: FERPA obligations, community notification, and a federal Department of Education alert all following from someone else's breach.
What actually helps?
The measures that repeatedly differentiate districts that recover well:
- MFA everywhere — staff email first. The single control most district incidents trace back to its absence.
- Tested offline backups of student-information and scheduling systems — the difference between restoring in days versus weeks.
- An incident-response plan that includes operations: how attendance, payroll, and communication run on paper; who calls whom; how families are notified.
- E-rate and grant funding used for security: the FCC's Schools and Libraries program expanded to cover security services, and CISA's K-12 resources map the practical starting points.
- Vendor risk as real risk: requiring breach-notification timelines and MFA/SOC attestations from the platforms holding student data — the Canvas lesson operationalized.
What can families do?
Treat school-account credentials as valuable — unique passwords and MFA on student and parent portals; watch for phishing referencing real teachers and courses, especially after any incident (attackers work from stolen context); and keep an eye on credit as children reach SSN-using milestones, since student-record breaches surface in identity fraud years later. Schools cannot buy their way out of a sector-wide pattern quickly; families' own hygiene is the layer the district's budget never covers.

