Edtech breach case studies: what actually happened, and what each one teaches
Breach discussion in procurement is usually hypothetical — "what if?" — which lets everyone round it down. The record is better teaching material: children's-data breaches have happened at scale, repeatedly, at organisations schools trusted, and each major incident proves a specific design lesson that hypotheticals let vendors dodge.
VTech (2015): collection sets the harm ceiling
The Hong Kong toymaker's connected-toy platform was breached, exposing profiles reported at several million children and parent accounts — names, birth dates, photos, and parent–child chat logs. The attacker claimed no malicious intent; the exposure was total either way. The US FTC later settled COPPA charges with VTech (2018). The lesson: nobody made VTech collect children's photos and chat logs to run toy features — the harm ceiling was set at the product-design meeting, years before the breach. Every field collected is a field breachable; minimisation is breach response done in advance.
Edmodo (2017): the identifier layer is the crown jewels
The classroom social platform was breached with tens of millions of accounts (reported ~77M) — usernames, email addresses, hashed passwords — offered for sale. Password hashing limited one harm; the email layer was the durable one: an email address links a person across the internet, and education-platform emails identify teachers and students as such, a targeting gift. (Separately, the FTC acted against Edmodo in 2023 over ad-directed use of children's data — a reminder that breach and business model are different failure modes of the same collection.) The lesson: identifiers outlive passwords; a system with no email layer has no email layer to lose.
Blackbaud (2020): the vendor's vendor, and the ransom-deletion fiction
Ransomware struck the fundraising/CRM provider used by thousands of schools, universities and nonprofits worldwide; exfiltrated data spanned donor and community records. Blackbaud paid the ransom in exchange for a deletion promise — from criminals — and its subsequent disclosures drew a US SEC settlement (2023) and FTC order. The lessons: your data estate includes your vendors' vendors (schools that never chose Blackbaud were in it via their systems — the register must reach that deep); and "the data was deleted" from an extortionist is not a control (deletion is hard enough when the deleter is honest).
Illuminate Education (2022): the encryption claim nobody checked
A breach at the US student-data platform exposed records of current and former students — New York City alone reported roughly 800,000+ affected, with further districts nationally — including sensitive categories like special-education status. Reporting and subsequent state action established that data represented as encrypted was not. The lessons: security claims are procurement inputs only if verified (ask, then check); and former students count — retention past purpose turned alumni into victims, which is APP 11's calendar duty written in consequences.
PowerSchool (2024–25): concentration risk, and paying doesn't end it
The largest K-12 student-information-system provider disclosed (January 2025) that an attacker had used a compromised support credential to export student and teacher data across a large share of its customer base — reports spanned tens of millions of records, historical data included, with sensitive fields for some. PowerSchool reportedly paid for deletion assurances; months later, individual districts received fresh extortion demands drawing on the same data. A young attacker later pleaded guilty in US federal court. The lessons: sector concentration turns one credential into a continent-scale children's-data event; support and admin access paths are part of the attack surface a vendor conversation should cover (MFA on their side, not just yours); and the ransom-deletion fiction got its definitive counterexample — data exfiltrated is data gone, forever negotiable.
The pattern across all five
Collection set every ceiling; identifiers and sensitive fields did the lasting damage; retention widened every blast radius; promises (encryption claims, deletion assurances, criminal pinky-swears) failed exactly when needed; and in no case did the affected families choose the vendor. Which yields the procurement stance this pillar keeps arriving at from different directions: prefer vendors where the honest answer to "what would a breach of you disclose?" is boring — and put the breach-notification clock in the contract before you need it.
References
- US FTC — United States v. VTech Electronics (2018 settlement); FTC v. Edmodo (2023); Blackbaud order (2024). US SEC — Blackbaud settlement (2023).
- New York State / NYC investigations and reporting on Illuminate Education (2022).
- PowerSchool incident disclosures (January 2025) and subsequent US DOJ prosecution reporting (2025).
- K12 Security Information Exchange (K12 SIX) — State of K-12 Cybersecurity annual reports: the sector-wide incident base rate behind these headline cases.
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.