Edtech is in the spotlight again. For the second time in roughly eighteen months there has been a major platform hack, a ransom demanded and paid. In late 2024 it was PowerSchool; last week it was Canvas, owned by Instructure. Both are owned by private equity: Bain Capital acquired PowerSchool for $5.6 billion; Kohlberg Kravis Roberts (KKR) and Dragoneer Investment Group acquired Instructure for $4.8 billion. Both companies paid their hackers and in both cases, the group that claimed responsibility was ShinyHunters (but it wasn’t).
That last point deserves a pause, because ShinyHunters is routinely mischaracterised. They are not a loose collective of teenagers from Britain or America. The convicted members identified so far are French, most notably Sebastien Raoult, arrested in Morocco in 2022 and extradited to the US. According to threat intelligence firms, ShinyHunters is a financially-motivated extortion group active since 2020, having operational overlap with other hacker groups including Scattered Spider and LAPSUS$. The Canvas attack hit during final examinations at institutions across the US, Canada, Australia, New Zealand, the Netherlands, Hong Kong, and Singapore, affecting 8,809 institutions worldwide with approximately 275m user records claimed. That was not accidental.
A history of soft targets
Education has always been a soft target. Long before cybercrime was a recognised category, hackers were stealing student data such as names, US Social Security numbers, addresses, etc and using them to apply for loans and credit cards, trashing the credit records of young people before most had even left school. One of the earliest documented university cases was the theft of 3,000 student records at the University of Indiana 36 years ago. The problem then, as now, was concealment: most early breaches were handled internally or never reported. California enacted the first US state breach notification law, SB 1386, in 2003. Before that, educational institutions had no legal obligation to disclose hacks. In 2005, the University of Southern California’s admissions site was taken offline after a programming flaw had likely exposed a database of 270,000 prospective students spanning applications from 1997 onwards. It took until 2020 for the creation of the K-12 Security Information eXchange (K12 SIX) a dedicated non-profit, information-sharing centre for the US K-12 sector. Better late than never, but it arrived after decades of the sector treating cybersecurity as someone else’s problem.
PowerSchool: a timeline that should alarm private equity everywhere
I look at edtech through an investment lens, and that lens is what makes the PowerSchool story so instructive.
In August 2023, PowerSchool was sued over its Naviance platform (now called PowerSchool CCLR Naviance). The lawsuit alleged the company had “systematically” violated students’ privacy rights through covert tracking of student communications via 3rd party analytics software, cited as “unlawful wiretapping and eavesdropping”, and characterised at the time as a precedent-setting case in edtech. It was settled in February 2026 for $17.25 million ($1.72 per student before legal costs). Under the terms of the agreement, PowerSchool was required to establish a’ web governance committee’ and barred from using third-party code in Naviance for two years. Final court approval is scheduled for August 19, 2026.
Bain Capital (who also own 7education) began its acquisition discussions in August 2022. The merger agreement was signed June 6, 2024 while the Naviance litigation was still live, with the deal closing October 1, 2024. Critically, the merger agreement granted Bain consent rights over capital spending exceeding $5m, vendor contracts and workforce changes, giving it effective operational influence months before formal ownership. In early 2024, plans were announced to move PowerSchool’s cybersecurity and IT functions to Movate’s Indian business, a decision courts have since treated as evidence of Bain’s control of PowerSchool’s day-to-day operations.
In September 2024, Matthew Lane, a 19-year-old (and not a member of ShinyHunters as has sometimes been claimed), used stolen contractor credentials found online to access PowerSchool’s network and transfer the personal data of approximately 60m students and 10m teachers, including Social Security numbers, medical information, disability records, etc, to a server in Ukraine. The breach was not discovered until December 28, 2024 after which Lane demanded $2.85m in Bitcoin, threatening to leak the data “worldwide” and, in one message, to “destroy your company and bankrupt it to the point of no absolute return”. PowerSchool paid, Lane claimed to have deleted the data, only he hadn’t as US schools and school districts subsequently received new ransom demands linked to their stolen records.
Lane was convicted of cyber extortion conspiracy, unauthorised access to protected computers and aggravated identity and sentenced in October 2025 to four years in federal prison and ordered to pay $14.1 million in restitution, an amount prosecutors acknowledged would never be recovered.
The litigation did not end with Lane. After more than fifty class-action lawsuits, the US Judicial Panel on Multidistrict Litigation consolidated the cases in the Southern District of California. In March 2026, the court denied motions to dismiss from both PowerSchool and Bain Capital, finding the plaintiffs’ allegations of ‘operational control’ sufficient to allow claims of negligence, unjust enrichment and violations of California’s Unfair Competition Law to proceed directly against the Bain and the merger agreement’s “disclaimer of control” clause, This is not a final verdict, but it is a precedent that private equity ownership, combined with documented operational influence, can attract direct liability for the data breaches of a portfolio company. Estimated damages to PowerSchool, including class action exposure of $5–$15 per impacted individual and $100–$300m already committed for credit monitoring through Experian and TransUnion, is likely to exceed $1bn. With Bain now in the frame, the numbers get worse.
Instructure: same playbook, bigger blast radius
KKR and Dragoneer completed their acquisition of Instructure six weeks after Bain closed on PowerSchool (November 13, 2024) so they should have had PowerSchool’s hack on their radar. Canvas had also suffered a ShinyHunters-related incident in September 2025, when a social engineering attack gave threat actors access to Instructure’s Salesforce instance. Instructure said no Canvas product data was accessed. Whatever remediation followed now looks grossly insufficient.
On April 25, 2026, ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account mechanism, not a stolen password but a structural flaw in how the platform managed a service tier, and stole 3.65Tb of data. When Instructure chose to patch rather than negotiate, the group defaced Canvas login pages at approximately 330 institutions and switched to extorting individual institutions directly, timing the escalation to coincide with final exams for many. On May 11, Instructure confirmed it had reached an agreement with ShinyHunters, had paid a ransom (undisclosed amount) and that the compromised data had been destroyed.
The legal exposure for KKR and Dragoneer will be impacted materially by what happens to Bain in the PowerSchool litigation. If the agency theory holds, that an acquirer exercising meaningful operational control can be held liable for security failures, then PE firms acquiring data-heavy platforms are in genuinely new legal territory. That is before accounting for the likely involvement of international regulators: GCHQ, the Australian Signals Directorate, ENISA and their equivalents across affected jurisdictions will not be spectators (and that’s before litigation against the affected institutions globally).
The due diligence question
I have been involved in the due diligence process for several UK edtech deals. While microscopic by these standards, what I consistently observed was that buyers were at best willing to spend 1–2% of a deal cost on due diligence, exclusively limited to legal and financial analysis. Technical diligence, the serious examination of what is broadly called ‘technical debt’, the accumulated cost of fast solutions built over sound long-term architecture was either totally absent or at best cosmetic (known as ‘lipstick on a pig’). For companies entrusted with the sensitive personal data of tens of millions of students, many of whom are young children, the nature and depth of that technical debt is not a footnote, it is the beating heart of the deal’s value and risk.
There’s another dimension worth noting. PowerSchool’s products, including Naviance, still carry the ISTE seal of approval. In the US this is the edtech sector’s standard badge of validated quality. ISTE markets the seal as evidence that a product has been “rigorously tested” for quality, usability and educational alignment but it says nothing about security. As James O’Hagan observed in Chalkdust & Silicon earlier this year, the seal validates the pedagogical pitch while the technical foundation goes unexamined. That is not ISTE’s fault alone, this type of kitemark, the likes of which I have seen previously in the UK and Australia, were never a security certification (e.g. SOC 2 Type II, ISO/IEC 27001, NIST/CSF 2.0, etc), but it illustrates how trust architecture in edtech operates – the surface is validated, but the basic architecture and security are ignored.
PE firms have long been characterised as ‘barbarians at the gate’. In fact this phrase was probably first used in public by the investor Ted Forstmann to describe his opposition to KKR’s leveraged buyout of RJR Nabisco in 1998. In edtech, as deals have gotten bigger, we have welcomed in and handed the keys to some of the most sensitive personal data repositories in existence. The question is no longer whether their models (debt-loading, excessive ‘management fee’ extraction, cost-cutting, offshoring, etc) are appropriate for technology businesses holding children’s data. That question has been answered. The question now is whether courts and regulators will hold them to the same standard of accountability as the platforms they bought?
Postscript
Hackers will keep targeting education until the sector takes security seriously as a structural commitment, not a compliance checkbox. ShinyHunters’ sustained focus on edtech is a spotlight, not an anomaly. And we have not yet begun to reckon with the number of North Korean state actors documented as posing as Western IT professionals, quietly embedded in technology companies, including, with high probability, some in edtech, exploiting the permissiveness of remote working arrangements. That story is coming.

Leave a Reply