Cybercriminals are increasingly targeting education technology vendors and learning platforms to reach large numbers of schools, students, and staff in a single intrusion. Reporting tied the trend to attacks claimed by ShinyHunters, including breaches involving EdTech platforms, a Salesforce-related theft affecting Infinite Campus staff accounts, and a major compromise of Instructure Canvas LMS that allegedly exposed 3.65TB of data spanning nearly 9,000 schools and 275 million users. Additional incidents reportedly affected higher-education environments running Oracle PeopleSoft, while newly named victims included Glendale Community College and Moody Bible Institute.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
After the Canvas-related activity, subsequent attacks were reportedly observed involving Oracle PeopleSoft environments in higher education institutions.
Dark Reading reports that in 2026, Shiny Hunters claimed an attack on Instructure's Canvas LMS involving 3.65TB of stolen data affecting nearly 9,000 schools and 275 million users.
Resecurity newly identified Glendale Community College and Moody Bible Institute as victims in the broader EdTech targeting trend.
Authorities in Singapore and other affected countries opened investigations into the Global Schools Foundation incident.
Global Schools Foundation confirmed the cyber incident and said it was working with cybersecurity experts and law enforcement in response.
In early June 2026, FulcrumSec claimed a ransomware and double-extortion attack against Global Schools Foundation that disrupted operations across multiple countries and allegedly stole student, financial, employee, and parent-administrator communications data.
Reporting says ShinyHunters expanded into the EdTech sector, breaching learning platforms and exposing more than 4 million student and educator records.
In March 2026, a Salesforce-related data theft affected Infinite Campus staff accounts, as cited in reporting on EdTech-targeted intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcedarkreading.com
Open sourceresecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.