Planer

  • Home
  • About
  • Privacy
  • Contact Me

Barbarians inside the gates

Edtech is in the spotlight again. For the second time in roughly eighteen months there has been a major platform hack, a ransom demanded and paid. In late 2024 it was PowerSchool; last week it was Canvas, owned by Instructure. Both are owned by private equity: Bain Capital acquired PowerSchool for $5.6 billion; Kohlberg Kravis Roberts (KKR) and Dragoneer Investment Group acquired Instructure for $4.8 billion. Both companies paid their hackers and in both cases, the group that claimed responsibility was ShinyHunters (but it wasn’t).

That last point deserves a pause, because ShinyHunters is routinely mischaracterised. They are not a loose collective of teenagers from Britain or America. The convicted members identified so far are French, most notably Sebastien Raoult, arrested in Morocco in 2022 and extradited to the US. According to threat intelligence firms, ShinyHunters is a financially-motivated extortion group active since 2020, having operational overlap with other hacker groups including Scattered Spider and LAPSUS$. The Canvas attack hit during final examinations at institutions across the US, Canada, Australia, New Zealand, the Netherlands, Hong Kong, and Singapore, affecting 8,809 institutions worldwide with approximately 275m user records claimed. That was not accidental.

A history of soft targets

Education has always been a soft target. Long before cybercrime was a recognised category, hackers were stealing student data such as names, US Social Security numbers, addresses, etc and using them to apply for loans and credit cards, trashing the credit records of young people before most had even left school. One of the earliest documented university cases was the theft of 3,000 student records at the University of Indiana 36 years ago. The problem then, as now, was concealment: most early breaches were handled internally or never reported. California enacted the first US state breach notification law, SB 1386, in 2003. Before that, educational institutions had no legal obligation to disclose hacks. In 2005, the University of Southern California’s admissions site was taken offline after a programming flaw had likely exposed a database of 270,000 prospective students spanning applications from 1997 onwards. It took until 2020 for the creation of the K-12 Security Information eXchange (K12 SIX)  a dedicated non-profit, information-sharing centre for the US K-12 sector. Better late than never, but it arrived after decades of the sector treating cybersecurity as someone else’s problem.

PowerSchool: a timeline that should alarm private equity everywhere

I look at edtech through an investment lens, and that lens is what makes the PowerSchool story so instructive.

In August 2023, PowerSchool was sued over its Naviance platform (now called PowerSchool CCLR Naviance). The lawsuit alleged the company had “systematically” violated students’ privacy rights through covert tracking of student communications via 3rd party analytics software, cited as “unlawful wiretapping and eavesdropping”, and characterised at the time as a precedent-setting case in edtech. It was settled in February 2026 for $17.25 million ($1.72 per student before legal costs).  Under the terms of the agreement, PowerSchool was required to establish a’ web governance committee’ and barred from using third-party code in Naviance for two years. Final court approval is scheduled for August 19, 2026.

Bain Capital (who also own 7education) began its acquisition discussions in August 2022. The merger agreement was signed June 6, 2024 while the Naviance litigation was still live, with the deal closing October 1, 2024. Critically, the merger agreement granted Bain consent rights over capital spending exceeding $5m, vendor contracts and workforce changes, giving it effective operational influence months before formal ownership. In early 2024, plans were announced to move PowerSchool’s cybersecurity and IT functions to Movate’s Indian business,  a decision courts have since treated as evidence of Bain’s control of PowerSchool’s day-to-day operations.

In September 2024, Matthew Lane, a 19-year-old (and not a member of ShinyHunters as has sometimes been claimed), used stolen contractor credentials found online to access PowerSchool’s network and transfer the personal data of approximately 60m students and 10m teachers, including Social Security numbers, medical information, disability records, etc, to a server in Ukraine. The breach was not discovered until December 28, 2024 after which Lane demanded $2.85m in Bitcoin, threatening to leak the data “worldwide” and, in one message, to “destroy your company and bankrupt it to the point of no absolute return”. PowerSchool paid, Lane claimed to have deleted the data, only he hadn’t as US schools and school districts subsequently received new ransom demands linked to their stolen records.

Lane was convicted of cyber extortion conspiracy, unauthorised access to protected computers and aggravated identity and sentenced in October 2025 to four years in federal prison and ordered to pay $14.1 million in restitution, an amount prosecutors acknowledged would never be recovered.

The litigation did not end with Lane. After more than fifty class-action lawsuits, the US Judicial Panel on Multidistrict Litigation consolidated the cases in the Southern District of California. In March 2026, the court denied motions to dismiss from both PowerSchool and Bain Capital, finding the plaintiffs’ allegations of ‘operational control’ sufficient to allow claims of negligence, unjust enrichment and violations of California’s Unfair Competition Law to proceed directly against the Bain and the merger agreement’s “disclaimer of control” clause, This is not a final verdict, but it is a precedent that private equity ownership, combined with documented operational influence, can attract direct liability for the data breaches of a portfolio company. Estimated damages to PowerSchool, including class action exposure of $5–$15 per impacted individual and $100–$300m already committed for credit monitoring through Experian and TransUnion, is likely to exceed $1bn. With Bain now in the frame, the numbers get worse.

Instructure: same playbook, bigger blast radius

KKR and Dragoneer completed their acquisition of Instructure six weeks after Bain closed on PowerSchool (November 13, 2024) so they should have had PowerSchool’s hack on their radar. Canvas had also suffered a ShinyHunters-related incident in September 2025, when a social engineering attack gave threat actors access to Instructure’s Salesforce instance. Instructure said no Canvas product data was accessed. Whatever remediation followed now looks grossly insufficient.

On April 25, 2026, ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account mechanism,  not a stolen password but a structural flaw in how the platform managed a service tier, and stole 3.65Tb of data. When Instructure chose to patch rather than negotiate, the group defaced Canvas login pages at approximately 330 institutions and switched to extorting individual institutions directly, timing the escalation to coincide with final exams for many. On May 11, Instructure confirmed it had reached an agreement with ShinyHunters, had paid a ransom (undisclosed amount) and that the compromised data had been destroyed.

The legal exposure for KKR and Dragoneer will be impacted materially by what happens to Bain in the PowerSchool litigation. If the agency theory holds, that an acquirer exercising meaningful operational control can be held liable for security failures, then PE firms acquiring data-heavy platforms are in genuinely new legal territory. That is before accounting for the likely involvement of international regulators: GCHQ, the Australian Signals Directorate, ENISA and their equivalents across affected jurisdictions will not be spectators (and that’s before litigation against the affected institutions globally).

The due diligence question

I have been involved in the due diligence process for several UK edtech deals. While microscopic by these standards, what I consistently observed was that buyers were at best willing to spend 1–2% of a deal cost on due diligence, exclusively limited to legal and financial analysis. Technical diligence, the serious examination of what is broadly called ‘technical debt’, the accumulated cost of fast solutions built over sound long-term architecture was either totally absent or at best cosmetic (known as ‘lipstick on a pig’). For companies entrusted with the sensitive personal data of tens of millions of students, many of whom are young children, the nature and depth of that technical debt is not a footnote, it is the beating heart of the deal’s value and risk.

There’s another dimension worth noting. PowerSchool’s products, including Naviance, still carry the ISTE seal of approval. In the US this is the edtech sector’s standard badge of validated quality. ISTE markets the seal as evidence that a product has been “rigorously tested” for quality, usability and educational alignment but it says nothing about security. As James O’Hagan observed in Chalkdust & Silicon earlier this year, the seal validates the pedagogical pitch while the technical foundation goes unexamined. That is not ISTE’s fault alone, this type of kitemark, the likes of which I have seen previously in the UK and Australia, were never a security certification (e.g. SOC 2 Type II, ISO/IEC 27001, NIST/CSF 2.0, etc),  but it illustrates how trust architecture in edtech operates – the surface is validated, but the basic architecture and security are ignored.

PE firms have long been characterised as ‘barbarians at the gate’. In fact this phrase was probably first used in public by the investor Ted Forstmann to describe his opposition to KKR’s leveraged buyout of RJR Nabisco in 1998. In edtech, as deals have gotten bigger, we have welcomed in and handed the keys to some of the most sensitive personal data repositories in existence. The question is no longer whether their models (debt-loading, excessive ‘management fee’ extraction, cost-cutting, offshoring, etc) are appropriate for technology businesses holding children’s data. That question has been answered. The question now is whether courts and regulators will hold them to the same standard of accountability as the platforms they bought?

Postscript

Hackers will keep targeting education until the sector takes security seriously as a structural commitment, not a compliance checkbox. ShinyHunters’ sustained focus on edtech is a spotlight, not an anomaly. And we have not yet begun to reckon with the number of North Korean state actors documented as posing as Western IT professionals, quietly embedded in technology companies, including, with high probability, some in edtech, exploiting the permissiveness of remote working arrangements. That story is coming.

 

May 14, 2026Richard Taylor
4 months ago EducationBain Capital, CANVAS, cybersecurity, Dragoneer Investment Group, due diligence, ENISA, GCHQ, hacking, Instructure, ISTE, K12 SIX, KKR, Kohlberg Kravis Roberts, Movate, Naviance, PE, PowerSchool, privacy, ShinyHunters, Technical debt0
Richard Taylor
Agentic AIOver the Boundary (and Out?)

Leave a Reply Cancel reply

Archives
  • July 2026 (4)
  • June 2026 (2)
  • May 2026 (4)
  • March 2026 (2)
  • January 2026 (1)
  • September 2025 (3)
  • July 2025 (2)
  • June 2025 (1)
  • May 2025 (2)
  • March 2025 (1)
  • February 2025 (2)
  • January 2025 (2)
  • December 2024 (1)
  • September 2024 (2)
  • June 2024 (1)
  • May 2024 (1)
  • April 2024 (1)
  • February 2024 (1)
  • January 2024 (1)
  • December 2023 (1)
  • October 2023 (1)
  • September 2023 (1)
  • August 2023 (1)
  • June 2023 (1)
  • May 2023 (1)
  • February 2023 (1)
  • December 2022 (1)
  • November 2022 (1)
  • September 2022 (1)
  • July 2022 (2)
  • June 2022 (2)
  • April 2022 (1)
  • March 2022 (2)
  • February 2022 (1)
  • September 2021 (2)
  • August 2021 (2)
  • July 2021 (1)
  • June 2021 (1)
  • May 2021 (2)
  • March 2021 (1)
  • January 2021 (2)
  • November 2020 (1)
  • October 2020 (2)
  • July 2020 (1)
  • June 2020 (1)
  • April 2020 (1)
  • January 2020 (2)
  • November 2019 (1)
  • September 2019 (1)
  • July 2019 (1)
  • June 2019 (2)
  • May 2019 (1)
  • March 2019 (1)
  • January 2019 (1)
  • May 2018 (1)
  • June 2017 (1)
  • May 2017 (2)
  • April 2017 (1)
  • March 2017 (1)
  • February 2017 (4)
  • January 2017 (1)
  • December 2016 (1)
  • November 2016 (2)
  • May 2016 (4)
  • April 2016 (1)
  • February 2016 (1)
  • January 2016 (1)
  • January 2015 (1)
  • May 2014 (2)
  • April 2014 (1)
  • March 2014 (2)
  • February 2014 (5)
  • October 2013 (1)
  • September 2013 (2)
  • August 2013 (1)
  • July 2013 (1)
  • June 2013 (2)
  • May 2013 (4)
  • April 2013 (2)
  • February 2013 (3)
  • January 2013 (3)
  • September 2012 (2)
  • August 2012 (2)
  • April 2012 (1)
  • February 2012 (3)
  • November 2011 (1)
  • October 2011 (2)
  • September 2011 (5)
  • August 2011 (5)
  • July 2011 (2)
  • June 2011 (2)
  • May 2011 (1)
2014 © Media Taylor