The next higher ed cyber crisis will likely start off campus

Date:

Share post:

Colleges and universities must strengthen defenses beyond IT as critical data breaches now originate outside of campus networks.

Expensive software and staff training may not be enough to protect students and staff as bad actors increasingly bypass these measures by exploiting third-party vendors.

Institutions have slowly accumulated a web of learning management systems, cloud services and other software to support daily operations and different department needs.

Each third-party vendor increases a college’s risk exposure, says James Lee, president of the Identity Theft Resource Center. A single point of failure can cascade across different systems, exposing multiple institutions.

“Supply chain attacks are very prevalent, and they lead to a significant number of data breaches because they go and look for that weak link,” he says. “Why would I want to attack 100 companies individually when I can find the one company that all 100 organizations use?”

Global hacking groups that successfully targeted weak links have wreaked havoc on higher education over the past three years.

The Canvas attack in May exposed over 3.5 TB of data—including full names, student ID numbers and messages—from thousands of U.S. institutions. It marked the largest data breach in terms of victims in the U.S. so far this year, Lee says.

The same group behind the Canvas attack, ShinyHunters, recently exploited a vulnerability in an Oracle program managing human resources, payroll and student records, The Register reports. An undisclosed number of U.S. colleges may be implicated; the University of Nottingham in the U.K. confirmed it was hit.

Companies—and the colleges they service—are more likely to be attacked as criminals use AI to create sophisticated phishing and malware attempts.

Securing cyber defenses before the next breach

Cabinet-level leaders must prioritize cybersecurity in governance, business and procurement practices as institutions expand their digital footprint and as successful attacks become more frequent, Lee says.

“You need to look at what can we do to protect ourselves against the stuff we don’t know about,” he adds. “There is a level of additional due diligence that institutions need to be doing.”

While artificial intelligence often dominates cybersecurity conversations, Lee believes some of the most effective safeguards are rooted in institutional policy.


Your next read: How this university reduced data siloes to maximize a chatbot’s potential


One of the simplest strategies is data minimization. Many colleges collect information they do not need or retain data long after its intended purpose has been fulfilled, increasing the amount of information available to cybercriminals during a breach.

Institutions should collect only necessary information, delete records once they are no longer required and encrypt data that must be retained for legal or operational purposes.

Passkeys are a promising replacement for traditional password-based authentication, he adds. Because passkeys rely on device-based biometrics and cryptographic keys rather than shared passwords, they can eliminate many of the most common forms of credential theft and phishing attacks.

“The five largest attacks last year would never have happened if we’d had passkeys in place at those organizations,” Lee says.

The risk won’t be conquered by the latest technology trends. Leaders who understand what data they collect, where it resides and who can access it are the best defense.

“If you don’t have the data, it can’t be compromised,” Lee says.

Alcino Donadel
Alcino Donadel
Alcino Donadel is editor at University Business covering college leadership, enrollment, and career readiness since 2023. He is a first-generation journalism graduate from the University of Florida with triple citizenship from the U.S., Ecuador, and Brazil. Find Alcino on LinkedIn or email him at [email protected].

The Always-On Insight and Networking Platform for Superintendents and Their Teams

AI-driven insights peer-to-peer collaboration and more build exclusively fot K-12 Superintendents and thier leaders
Built for the uniqueness of the superintendent role and their supporting team.Most platforms treat all K–12 leaders the same. DA+ recognizes that superintendents face a unique level of pressure, complexity, visibility, and responsibility—and gives them a space designed specifically for the demands of the top job.
A community where you don’t have to explain the context.Skip the backstory. DA+ understands the job, the politics, the stakes, and the pace.
Your decisions shape communities.Find the tools and peer insight to make them with confidence here.
Leadership tailored to the realities of running a district.From board relations to budgets, crisis response to community trust—DA+ focuses on the challenges only superintendents navigate each day.
Built for superintendents.Powered by superintendents. Trusted by superintendents. If you run a district, you belong here.

Related Articles