Skip to content

🎓 Education

Schools, universities, edtech · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D1▼ −1
Prior 30D2
Active actor L90DShinyHunters · 3
Active actor L90DInterlock · 2
Active actor L90DUnknown · 1

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

Mathspace discloses breach of ~1.08M students, parents and staff across Australia and New Zealand after attackers exploited an unpatched Metabase SQL-injection flaw in an internal reporting tool.HighEducationUnauthorized access dates back to Aug 10; the Australian reporting database was downloaded Aug 27. Exposed: names, emails, usernames, country/timezone and account metadata — Mathspace says no passwords, academic records or API credentials were taken. The same Metabase SQLi flaw already hit Framework, Tally and Kilo Code in August; this is the fourth confirmed victim of the same unpatched-component pattern. Help Net Security · BleepingComputer
PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078) — Metasploit module published Sep 1; attacks escalated to hands-on-keyboard; CISA KEV Aug 31; federal deadline Sep 14; 1,000+ internet-exposed instancesCriticalEducationHealthcare & Life SciencesGovernment & Public SectorThe PaperCut zero-day exploit chain (CVE-2026-81578 improper access control CVSS 8.8 + CVE-2026-82078 unsafe Java class-loading CVSS 9.4) has moved from active zero-day to Metasploit-module-available in six days. Rapid7 published module `multi/http/papercut_ng_external_user_lookup_rce` (PR #21842, 845 lines) supporting unauthenticated RCE on PaperCut MF/NG versions 24.x, 25.x, 26.x. The module bypasses PaperCut's first emergency patch (v1 bypassed within 48h; v2 is the current remediation). CISA added both CVEs to KEV on August 31; federal agency deadline is September 14. ShadowServer counts 1,000+ internet-exposed PaperCut instances. Attacks have progressed from scanning to hands-on-keyboard intrusion activity, per SecurityWeek. Any organization running PaperCut in higher education, healthcare, or government — the primary deployment verticals — must treat this as critical and patch to v2 immediately. SecurityWeek · Rapid7 · BleepingComputer · The Hacker News
The PaperCut Metasploit module being public before the federal remediation deadline (Sep 14) represents a structural gap: government policy timelines are calibrated to pre-AI, pre-Metasploit exploit development cycles and are now systematically too slow.CriticalGovernment & Public SectorEducationWhen a CVSS 9.4 zero-day has a public Metasploit module six days after disclosure, the 14-day KEV remediation window is not a deadline; it is a target the adversary will pass before most organizations patch. PaperCut is deployed at scale in universities, hospitals, and government print-management environments — precisely the sectors where patch cadence is slowest and IT staffing thinnest. The structural fix is not faster deadlines but automated patch deployment at the hypervisor level, which the current BOD 26-04 framework does not yet mandate. CISA KEV Catalog · Rapid7

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 08 Mathspace Unknown Ransomware · Education · Australia Unauthorized access to internal Metabase reporting system (SQLi in unpatched Metabase instance) exposed names, emails, usernames and account metadata for 1,079,819 students, parents and staff across Australia and New Zealand; no passwords, academic records or API credentials taken. Fourth confirmed victim of the same unpatched-Metabase pattern after Framework, Tally and Kilo Code in August. · Sources: https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ · https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/

July 2026

Jul 31 Southeastern Oklahoma State University Interlock Ransomware · Education · USA Interlock ransomware attack on public university in Durant OK; confidential financial records including unaudited earnings reports and tax files stolen; campus closed 3 days; 42,000 students locked out; DLS claim posted Aug 19 2026 · Sources: https://www.kxii.com/video/2026/08/03/southeastern-oklahoma-state-university-reopen-tuesday-after-cybersecurity-incident/
Jul 20 TimeTEX GmbH SafePay Ransomware · education · Germany German educational supplies company; SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 14 Cedar Crest College NightSpire Ransomware · Education · USA Liberal arts college in Allentown PA listed on NightSpire DLS July 14. Estimated attack date July 13. No public statement from Cedar Crest College. · Sources: https://ransomware.live/group/nightspire

June 2026

Jun 29 Musashino University Qilin Ransomware · education · Japan Qilin DLS claim June 29, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.redpacketsecurity.com/qilin-ransomware-victim-musashino-university/ · Sources: [RedPacket Security]
Jun 26 911 Driving School PrinzEugen Ransomware · education · driving instruction/US national driving school chain; PrinzEugen DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 25 San Silvestre School Krybit Ransomware · education · Peru 148.75 GB claimed; 🟥 unverified — possible re-listing of prior Qilin-targeted school; treat as claimed only pending victim statement · https://x.com/FalconFeedsio/status/2070123961552371874 · Sources: [FalconFeeds]
Jun 23 Reynella East College Interlock Ransomware · education · Australia all IT systems offline; 1,900+ students and staff at risk; school disclosed breach June 9 in letter to parents; Interlock DLS claim posted June 23; investigation ongoing, data exposure unconfirmed · https://www.cyberdaily.au/security/13731-parents-warned-after-cyber-security-breach-at-south-australia-s-reynella-east-college · https://www.ransomware.live/ · Sources: [Cyber Daily] · [ransomware.live]
Jun 20 BITS Pilani DragonForce Ransomware · higher education · India https://www.redpacketsecurity.com/dragonforce-ransomware-victim-bits-pilani-ac-in/ · https://www.ransomware.live/group/dragonforce · Sources: [RedPacket Security] · [ransomware.live]
Jun 16 Moody Bible Institute ShinyHunters Extortion · education · US 1,300+ files claimed; group alleged "tens of millions of records" related to enrollment, donor relations, payroll, and communications; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 16, 2026; scope unverified; law firm class action investigation underway — 🟥 unverified · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.classaction.org/data-breach-lawsuits/moody-bible-institute-june-2026 · Sources: [Google Cloud Blog] · [classaction.org]
Jun 15 Glendale Community College ShinyHunters Extortion · education · US 62GB exfiltrated (304,000+ files); Oracle PeopleSoft Campus Solutions compromised via CVE-2026-35273; 150,000+ student records including names, DOBs, student emails, enrollment, financial aid, and transcript data (Sept 2020–June 2026); DLS claim June 15–16, 2026; final ransom warning before June 18 deadline · https://www.ransomware.live/id/Z2xlbmRhbGUuZWR1QHNoaW55aHVudGVycw · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-glendale-edu/ · https://cybernews.com/security/google-shinyhunters-oracle-peoplesoft-zero-day-extortion/ · Sources: [ransomware.live] · [RedPacket Security] · [Cybernews]
Jun 15 Illinois Central College ShinyHunters Extortion · education · US 28GB data claimed; Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim June 15, 2026; final ransom warning issued · https://www.dexpose.io/shinyhunters-breach-illinois-central-college/ · https://www.breachsense.com/breaches/illinois-central-college-data-breach/ · Sources: [DeXpose] · [Breachsense]
Jun 11 Colégio Santo Inácio LockBit Ransomware · education · Brazil Sources: FalconFeeds
Jun 10 Global Schools Foundation FulcrumSec Ransomware · education · Singapore Sources: ransomware.live DLS
Jun 09 University of Nottingham ShinyHunters Extortion · education · UK 454,600+ student and alumni records including names, addresses, phone numbers, passport numbers, ethnicity and disability data, and academic records; Oracle PeopleSoft CVE-2026-35273 confirmed access vector (attack window May 27–June 9); university confirmed incident June 11, 2026 · https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/ · https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961 · https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/ · Sources: [BleepingComputer] · [The Register] · [Help Net Security]
Jun 09 Houston City College ShinyHunters Extortion · education · US Oracle PeopleSoft CVE-2026-35273 attack vector; DLS claim first posted June 9 onwards; named victim confirmed in Google Cloud/Mandiant ShinyHunters education sector campaign report (June 2026) · https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit · https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/ · Sources: [Google Cloud Blog] · [Higher Ed Dive]
Jun 08 Kinetic Education Qilin Ransomware · education · Australia Sources: ransomware.live DLS
Jun 01 School Facility Consultants Abyss Ransomware · education planning and consulting · US California-based firm advising school districts on facility planning, project management, and construction; Abyss DLS claim June 1, 2026; sensitive information threatened for release; scope unconfirmed · https://www.dexpose.io/abyss-ransomware-targets-school-facility-consultants/ · https://www.hookphish.com/blog/ransomware-group-abyss-hits-school-facility-consultants/ · Sources: [DeXpose] · [HookPhish]

May 2026

May 15 Krum Public Library NightSpire Ransomware · education-library · US 50 GB claimed exfiltrated: financial docs, HR data, supervisor info; attack May 14 2026; city of Krum confirmed ransomware in June 3 public notice; no SSNs/financial account info compromised; backups prevented permanent data loss; 🟨 city-confirmed · https://dysruptionhub.com/krum-library-ransomware-wifi/ · https://www.ransomware.live/id/S3J1bSBQdWJsaWMgTGlicmFyeUBuaWdodHNwaXJl · Sources: [Dysruption Hub] · [ransomware.live]

April 2026

Apr 25 Instructure/Canvas ShinyHunters Extortion · education technology platform · US 275 million users across 8,809 universities, educational ministries, and institutions worldwide; attack April 25, 2026; Instructure detected intrusion April 29 and revoked access; disclosed May 1; data includes student names, email addresses, student ID numbers, and user messages; described as the largest educational data breach on record; Instructure paid ransom, "shred logs" provided May 11; FBI warned students and staff of ongoing phishing risk post-ransom · https://www.malwarebytes.com/blog/news/2026/05/millions-of-students-personal-data-stolen-in-major-education-cyberattack · https://www.bitdefender.com/en-us/blog/hotforsecurity/canvas-data-breach-2026 · Sources: [Malwarebytes] · [Bitdefender]
Apr 24 Udemy ShinyHunters Extortion · education technology · US 1.4 million records claimed; listed DLS April 24, data published April 27 after ransom deadline; no Udemy public confirmation — 🟥 unverified · https://cybernews.com/security/shinyhunters-claim-udemy-data-theft/ · https://www.scworld.com/brief/udemy-allegedly-breached-by-shinyhunters-data-leak-warned · Sources: [Cybernews] · [SC Media]

March 2026

Mar 18 Infinite Campus ShinyHunters Extortion · education technology · US student information system serving 3,200+ school districts and 11M students across 46 US states; Salesforce account vishing attack March 18, 2026; 137,123 unique school staff accounts' data exfiltrated: names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets; Infinite Campus confirmed breach (staff data only; no evidence student databases compromised); HIBP notification June 15, 2026; Salesforce vector (not PeopleSoft CVE-2026-35273) · https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/ · https://cybernews.com/cybercrime/shinyhunters-data-infinite-campus-137k-students-exposed/ · https://www.techradar.com/pro/security/11-million-students-possibly-at-risk-after-classroom-software-used-by-millions-hacked · Sources: [BleepingComputer] · [Cybernews] · [TechRadar]

February 2026

Feb 24 Strategic Education Unattributed Breach · education · US incident 23–25 Feb 2026

← All industries · Victim database →