Cybersecurity is becoming a core school safety issue in Arizona
Districts are struggling to keep up
Image by: Metro Creative
Students increasingly rely on digital learning platforms for assignments, testing and communication, making cybersecurity disruptions a growing concern for schools nationwide. Recent attacks targeting educational systems have forced some districts to temporarily shut down online learning tools during critical academic periods.
Posted
The Issue:
Cybersecurity threats are increasingly disrupting schools across the country, exposing student data, interrupting instruction and forcing districts to spend millions recovering from ransomware attacks and system failures. As schools rely more heavily on digital learning platforms, cybersecurity is rapidly becoming one of the most significant operational and safety challenges facing education.
The Stats:
The Center for Internet Security found that 82% of K-12 organizations experienced cyber threat impacts between July 2023 and December 2024, resulting in nearly 14,000 security events and more than 9,300 confirmed cybersecurity incidents nationwide. Ransomware attacks against education institutions rose 23% during the first half of 2025, with schools accounting for roughly one out of every 13 reported ransomware incidents globally. Cybersecurity analysts say average ransom demands against education organizations now exceed $550,000 per attack, while total recovery costs can climb into the millions once districts factor in operational shutdowns, forensic investigations, legal costs and student data protection services.
The Solution:
Federal agencies and cybersecurity experts say schools must begin treating cybersecurity as part of overall school safety and infrastructure planning. Recommended strategies include stronger password protections, staff training, software updates, multi-factor authentication, offline backups and incident response planning that allows schools to continue operating during attacks.
A nationwide ransomware attack targeting the educational platform Canvas disrupted schools and colleges across Arizona during one of the busiest academic periods of the year, forcing districts including Peoria Unified, Higley Unified and Mesa Public Schools to temporarily disable or restrict access to the system during finals season.
The breach, which involved hackers known as ShinyHunters, reportedly exposed student ID numbers, names and messages exchanged through the platform.
Canvas parent company Instructure later confirmed it had negotiated with the attackers in an effort to ensure the stolen data was deleted and prevent further release of information.
The incident rippled through schools across the Phoenix area. Arizona State University and other higher education institutions also experienced disruptions, with some instructors canceling or modifying final exams during the outage.
Mesa Public Schools proactively shut down Canvas access after reports of the attack surfaced, while Peoria Unified and Higley Unified warned families and limited use of the platform as the company worked to contain the breach.
Not every district was affected. Scottsdale Unified and Queen Creek Unified officials said their systems remained operational because they either do not use Canvas or had not yet fully implemented the platform.
The attack highlighted how deeply schools depend on digital learning systems — and how quickly cybersecurity threats can disrupt instruction, communication and daily operations across entire districts.
“Cybersecurity threats to K-12 institutions are rising rapidly,” the Cybersecurity and Infrastructure Security Agency said in a recent report. “For K-12 schools, cyber incidents are so prevalent that, on average, there is more than one incident per school day.”
Cyberattacks growing more frequent
Arizona districts are adapting to a growing wave of cyber threats. After ransomware hit Agua Fria Union High School District in 2024, IT Director Brandon Gabel said the district’s response plan became critical to restoring operations quickly. “It’s imperative that you have a blueprint,” Gabel said. “Trust the process, because we put the process in place for a reason.”
For many schools, cybersecurity used to be viewed as a back-office technology issue. Today, it can determine whether students can attend class, submit assignments, access grades or even communicate with teachers.
Across the country, cyberattacks targeting schools are becoming more frequent, more sophisticated and more disruptive. Ransomware attacks, phishing schemes targeting government offices and data breaches are now forcing districts to close campuses, cancel instruction and spend significant amounts of time and money restoring systems.
The growing threat has pushed federal agencies, state leaders and education organizations to warn that cybersecurity must now be considered part of modern school safety planning.
CISA has repeatedly warned that K-12 schools remain attractive targets for cybercriminals because they hold large amounts of sensitive data while often operating with limited cybersecurity staffing and aging technology systems.
That data can include student records, disciplinary histories, health information, transportation systems, payroll records and communication platforms used daily by students and families.
Schools are prime targets
According to the 2025 CIS MS-ISAC K-12 Cybersecurity Report, more than four out of five reporting schools experienced some form of cyber threat impact over an 18-month period. Researchers tracked about 14,000 security events and more than 9,300 confirmed incidents involving schools nationwide in a 2025 white paper released by the agency.
Experts say cybercriminals increasingly target schools because districts often face a difficult balance: maintaining open, collaborative learning environments while protecting complex digital systems.
Unlike many corporations, schools must provide broad access to students, teachers, families and third-party vendors — all while operating under tight budgets and staffing shortages.
The U.S. Department of Education notes that phishing emails and outdated software remain two of the most common vulnerabilities exploited in school cyberattacks.
Federal agencies including the FBI and CISA have warned that ransomware attacks can render school systems inaccessible for basic educational functions, including distance learning, attendance systems and communication platforms.
One challenge facing K-12 cybersecurity is that school districts generally operate independent technology systems rather than a single statewide network.
That decentralization can be a strength, as a cyberattack that compromises one district's systems typically does not automatically spread to every school in the state. However, it can also create uneven levels of protection, with larger districts often able to invest in dedicated cybersecurity staff and advanced monitoring tools while smaller or rural districts may have limited resources and expertise.
As a result, cybersecurity preparedness can vary significantly from one district to another, prompting some states to explore regional partnerships, shared services and statewide cybersecurity support programs to help close those gaps.
The cost of disruption
The impact of a cyberattack on a school system often extends far beyond temporary inconvenience.
The funding challenge is becoming increasingly visible. The FCC’s Schools and Libraries Cybersecurity Pilot Program drew more than $3.7 billion in requests despite having only $200 million available over three years — a sign of how urgently districts say cybersecurity investments are needed. At the same time, many schools are navigating the post-ESSER fiscal cliff as pandemic relief dollars disappear and technology costs continue rising.
When systems are shut down, districts may lose access to lesson plans, testing systems, transportation routing, cafeteria systems and emergency communication tools. Teachers must revert to paper instruction while IT departments work to restore operations.
In some cases, schools have been forced to close entirely during recovery efforts.
Cybersecurity researchers say attacks against schools are increasingly tied to ransomware groups seeking large payouts in exchange for restoring access to systems or preventing the release of stolen data.
Education institutions experienced 130 ransomware attacks in the first half of 2025 alone, with average ransom demands reaching approximately $556,000, according to cybersecurity reporting organizations tracking attacks nationwide.
Recovery costs can extend well beyond ransom demands themselves. Districts may face legal expenses, forensic investigations, system replacement costs and long-term monitoring for exposed student information.
Some estimates place the average recovery cost for K-12 organizations in the millions of dollars per incident.
Student data carries long-term risks
One of the largest concerns involves the long-term exposure of student data.
Unlike adults, children often have little or no established credit history, making stolen identities valuable to cybercriminals. Experts warn that compromised student records can remain undetected for years before fraudulent activity surfaces.
School systems also frequently store detailed personal information, including birthdates, addresses, family contacts, medical information and disciplinary records.
Cybersecurity experts note that attacks on schools are no longer isolated to large universities or major districts. Smaller and rural districts may face greater vulnerabilities because they often lack dedicated cybersecurity personnel or advanced monitoring systems.
What schools are being told to do
Federal agencies are increasingly urging districts to adopt basic cybersecurity practices that can significantly reduce risk.Recommendations from CISA and national cybersecurity organizations include:
Multi-factor authentication for all staff accounts
Frequent software and security updates
Staff training to identify phishing attempts
Regular offline backups of critical systems
Stronger password requirements
Limiting administrator-level access
Vendor risk assessments for third-party software providers
Incident response plans for continuing instruction during outages
Many experts also argue cybersecurity education itself must become part of student digital literacy efforts, especially as students increasingly use cloud-based learning systems beginning in elementary school.
States and schools are beginning to respond
While cybersecurity threats continue escalating, schools and state leaders across the country are also expanding efforts to strengthen digital protections and incident response systems.
More than 600 schools and districts nationwide — including large urban districts and small rural systems — were selected to receive support through the Federal Communications Commission’s $200 million Schools and Libraries Cybersecurity Pilot Program, which is helping schools test cybersecurity monitoring, protection and response tools.
Several states are also beginning to build statewide cybersecurity frameworks specifically for K-12 education.
Indiana and Ohio have expanded support to help schools meet new cybersecurity training expectations for staff and administrators. North Carolina developed a statewide Joint Cybersecurity Task Force that includes the FBI, National Guard, state education officials and local school districts.
North Dakota became the first state to require K-12 cybersecurity education, while Connecticut’s statewide education network now provides cybersecurity services to every public school district at no cost.
Investment is also rising at the district level despite mounting financial pressure. According to the Consortium for School Networking’s 2025 national survey, more than 78% of education technology leaders reported schools are increasing spending on cybersecurity monitoring, detection and response systems even as cybersecurity insurance and technology costs continue climbing.
Federal officials say the cybersecurity threat facing schools is no longer theoretical. “Schools and libraries are increasingly frequent targets of cyberattacks, which can disrupt learning, expose personal information, and impose significant financial costs,” said former FCC Chairwoman Jessica Rosenworcel while announcing the federal Schools and Libraries Cybersecurity Pilot Program.
Education technology leaders say the issue has evolved beyond technology departments alone.
“Cybersecurity is no longer just an IT issue. It’s a district leadership issue,” said Keith Krueger, CEO of the Consortium for School Networking.
A new definition of school safety
For years, school safety discussions focused largely on physical security — campus entrances, emergency drills and school resource officers.
Today, education leaders say digital security must become part of that same conversation.
A single cyberattack can disrupt learning across entire districts, expose thousands of student records and interrupt operations for days or weeks. As schools continue integrating technology into nearly every aspect of instruction, cybersecurity preparedness is increasingly becoming as essential as any other infrastructure investment.
And experts warn the problem is unlikely to slow down anytime soon.
Editor’s note: A grant from the Arizona Local News Foundation made this story possible. The foundation awarded 15 newsrooms to pay for solutions-focused education reporters for two years. Please submit comments at yourvalley.net/letters. We are committed to publishing a wide variety of reader opinions, as long as they meet our Civility Guidelines.
Meet Stacy Stacy Mantle is joining the team at Independent Newsmedia, Inc. as an Education Solutions journalist, thanks to a grant from the Arizona Community Collaborative. She has a long history in education that ranges from teaching junior high and middle school to developing curriculum and standards-based assessments.
Community: A longtime advocate for animal welfare, Stacy is deeply involved in rescue efforts and volunteers with several nonprofit organizations.
Random Fact: Once upon a time, she shared her home with a pet coyote and two wolf hybrids. The experiences were wild enough to become the subject of her first book!
Education: She holds a BA in English with a minor in Political Science, a Post-baccalaureate in Secondary Education, and an MBA with a emphasis on Marketing.
Hobbies: In her spare time, Stacy writes fast-paced urban fantasy novels, crafts small-batch artisan soap, and is always up for hiking or off-roading through the Arizona wilderness with her husband of 23 years.
Comments
No comments on this item Please log in to comment by clicking here