Institutions are becoming increasingly reliant on third-party vendors. The risk is escalating. Combine this with cyber risk, and you have an even more heightened risk exposure.
The cyber attack on Instructure underscores the importance of this risk. I am not going to rehash what the news has already reported, but let's think about this: Instructure, which owns Canvas, is one of the nation's most popular learning management systems, used by 41% of higher education institutions across North America. The hackers claimed the attack affected nearly 9,000 schools worldwide and would compromise the personally identifiable information of 275 million people, including students, teachers, and staff. The risk is clear: third-party risk is real and will impact even the most sophisticated vendors and well-prepared schools. The 2024 Crowdstrike outage taught us that!
"Freemium" is a Risk
As I researched the breach, I found articles stating that the hackers used "Free-For-Teacher" (FFT) accounts to access the system. Freemium features on enterprise platforms tend to be underexamined risks. Most vendor security questionnaires focus on the core product. A free tier sitting on shared infrastructure, with lighter identity verification and its own support system, is rarely assessed separately, even though it may share backend access. The assumption that open access and light verification constitute an acceptable trade-off for convenience is a very big risk!
Therefore, the key risk management failure in this breach is related to insufficient tenant isolation. The FFT environment was designed for individual, unverified, low-stakes users, but it had pathways into data belonging to paying institutional customers. This is a classic architecture risk: a low-security front door connected to a high-value back room.
A Pattern Emerges
And here is the part that I did not recall. The hackers "ShinyHunters" apparently hit Instructure in 2025, hit Infinite Campus in March, and McGraw-Hill in April. Cyber experts had been watching the pattern for 18 months, which demonstrated that attackers were moving up the data supply chain to platforms that sit underneath thousands of institutions at once.
Unlike the private sector, where risk sharing is more common, had more institutions actively participated with organizations like REN-ISAC, the ShinyHunters pattern targeting ed-tech vendors may have triggered sector-wide mitigation efforts before the breach.
What Can Be Done?
Enhance third-party vendor due diligence. The attack followed a clear pattern. ShinyHunters' approach is to exploit a trusted third-party integration to reach a higher-valued target. Do not just accept the vendor's self-attestation. Dig deeper into their controls and strongly dissuade the use of "freemium" features.
Contracts with key vendors should include mandatory breach-notification timelines, audit rights, and strong indemnification clauses. Make sure that your contract language includes insurance and indemnification requirements that reflect the sensitivity of the data the vendors maintain. Be aware and avoid agreeing to Limitations of Liability that can negate indemnification and insurance requirements.
Institutions should immediately alert staff, faculty, and students to expect convincing phishing emails that reference real course and advisor names because attackers now have the data to make those emails appear very credible.
Keep sensitive content on any platform to a minimum. In doing this, you minimize the risk of PII exposure during breaches. When sensitive communications occur, such as disability accommodations, redirect these conversations to other purpose-built systems such as disability services or counseling platforms. Don't concentrate all your sensitive data in one system to reduce risk.
Make sure your Business Continuity Plan is real, not a once-a-year check-the-box exercise. It appears many schools may not have had a plan for delivering courses without Canvas. During the Canvas interruption, Instructure put the platform in "maintenance mode" as it investigated the issue. (in the middle of finals week!) Schools that regularly test their backup procedures (alternate communication channels, offline syllabi, and grade backup exports) will be more resilient.
Institutions can join REN-ISAC and work with EDUCAUSE to share risk intelligence to get ahead of these cyber risks. The Canvas breach was not an isolated incident; it was a signal. The institutions that treat it as one will be better prepared to face the next challenge.
References:
https://www.nytimes.com/2026/05/12/us/canvas-instructure-hackers-deal.html
https://mashable.com/article/instructure-canvas-hack-shinyhunters-breach-school-websites
https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor