Log in

Education Solutions

Cybersecurity is becoming a core school safety issue in Arizona

Districts are struggling to keep up

Posted

A nationwide ransomware attack targeting the educational platform Canvas disrupted schools and colleges across Arizona during one of the busiest academic periods of the year, forcing districts including Peoria Unified, Higley Unified and Mesa Public Schools to temporarily disable or restrict access to the system during finals season.

The breach, which involved hackers known as ShinyHunters, reportedly exposed student ID numbers, names and messages exchanged through the platform.

Canvas parent company Instructure later confirmed it had negotiated with the attackers in an effort to ensure the stolen data was deleted and prevent further release of information.

The incident rippled through schools across the Phoenix area.  Arizona State University and other higher education institutions also experienced disruptions, with some instructors canceling or modifying final exams during the outage.

Mesa Public Schools proactively shut down Canvas access after reports of the attack surfaced, while Peoria Unified and Higley Unified warned families and limited use of the platform as the company worked to contain the breach.

Not every district was affected. Scottsdale Unified and Queen Creek Unified officials said their systems remained operational because they either do not use Canvas or had not yet fully implemented the platform.

The attack highlighted how deeply schools depend on digital learning systems — and how quickly cybersecurity threats can disrupt instruction, communication and daily operations across entire districts.

“Cybersecurity threats to K-12 institutions are rising rapidly,” the Cybersecurity and Infrastructure Security Agency said in a recent report. “For K-12 schools, cyber incidents are so prevalent that, on average, there is more than one incident per school day.”

Cyberattacks growing more frequent

Arizona districts are adapting to a growing wave of cyber threats. After ransomware hit Agua Fria Union High School District in 2024, IT Director Brandon Gabel said the district’s response plan became critical to restoring operations quickly. “It’s imperative that you have a blueprint,” Gabel said. “Trust the process, because we put the process in place for a reason.”

For many schools, cybersecurity used to be viewed as a back-office technology issue. Today, it can determine whether students can attend class, submit assignments, access grades or even communicate with teachers.

Across the country, cyberattacks targeting schools are becoming more frequent, more sophisticated and more disruptive. Ransomware attacks, phishing schemes targeting government offices and data breaches are now forcing districts to close campuses, cancel instruction and spend significant amounts of time and money restoring systems.

The growing threat has pushed federal agencies, state leaders and education organizations to warn that cybersecurity must now be considered part of modern school safety planning.

CISA has repeatedly warned that K-12 schools remain attractive targets for cybercriminals because they hold large amounts of sensitive data while often operating with limited cybersecurity staffing and aging technology systems. 

That data can include student records, disciplinary histories, health information, transportation systems, payroll records and communication platforms used daily by students and families.

Schools are prime targets

According to the 2025 CIS MS-ISAC K-12 Cybersecurity Report, more than four out of five reporting schools experienced some form of cyber threat impact over an 18-month period. Researchers tracked about 14,000 security events and more than 9,300 confirmed incidents involving schools nationwide in a 2025 white paper released by the agency.

Experts say cybercriminals increasingly target schools because districts often face a difficult balance: maintaining open, collaborative learning environments while protecting complex digital systems.

Unlike many corporations, schools must provide broad access to students, teachers, families and third-party vendors — all while operating under tight budgets and staffing shortages.

The U.S. Department of Education notes that phishing emails and outdated software remain two of the most common vulnerabilities exploited in school cyberattacks.

Federal agencies including the FBI and CISA have warned that ransomware attacks can render school systems inaccessible for basic educational functions, including distance learning, attendance systems and communication platforms.

One challenge facing K-12 cybersecurity is that school districts generally operate independent technology systems rather than a single statewide network.

That decentralization can be a strength, as a cyberattack that compromises one district's systems typically does not automatically spread to every school in the state. However, it can also create uneven levels of protection, with larger districts often able to invest in dedicated cybersecurity staff and advanced monitoring tools while smaller or rural districts may have limited resources and expertise.

As a result, cybersecurity preparedness can vary significantly from one district to another, prompting some states to explore regional partnerships, shared services and statewide cybersecurity support programs to help close those gaps.

The cost of disruption

The impact of a cyberattack on a school system often extends far beyond temporary inconvenience.

The funding challenge is becoming increasingly visible. The FCC’s Schools and Libraries Cybersecurity Pilot Program drew more than $3.7 billion in requests despite having only $200 million available over three years — a sign of how urgently districts say cybersecurity investments are needed. At the same time, many schools are navigating the post-ESSER fiscal cliff as pandemic relief dollars disappear and technology costs continue rising. 

When systems are shut down, districts may lose access to lesson plans, testing systems, transportation routing, cafeteria systems and emergency communication tools. Teachers must revert to paper instruction while IT departments work to restore operations.

In some cases, schools have been forced to close entirely during recovery efforts.

Cybersecurity researchers say attacks against schools are increasingly tied to ransomware groups seeking large payouts in exchange for restoring access to systems or preventing the release of stolen data.

Education institutions experienced 130 ransomware attacks in the first half of 2025 alone, with average ransom demands reaching approximately $556,000, according to cybersecurity reporting organizations tracking attacks nationwide. 

Recovery costs can extend well beyond ransom demands themselves. Districts may face legal expenses, forensic investigations, system replacement costs and long-term monitoring for exposed student information.

Some estimates place the average recovery cost for K-12 organizations in the millions of dollars per incident. 

Student data carries long-term risks

One of the largest concerns involves the long-term exposure of student data.

Unlike adults, children often have little or no established credit history, making stolen identities valuable to cybercriminals. Experts warn that compromised student records can remain undetected for years before fraudulent activity surfaces.

School systems also frequently store detailed personal information, including birthdates, addresses, family contacts, medical information and disciplinary records.

Cybersecurity experts note that attacks on schools are no longer isolated to large universities or major districts. Smaller and rural districts may face greater vulnerabilities because they often lack dedicated cybersecurity personnel or advanced monitoring systems. 

What schools are being told to do

Federal agencies are increasingly urging districts to adopt basic cybersecurity practices that can significantly reduce risk. Recommendations from CISA and national cybersecurity organizations include:

  • Multi-factor authentication for all staff accounts 
  • Frequent software and security updates
  • Staff training to identify phishing attempts
  • Regular offline backups of critical systems
  • Stronger password requirements
  • Limiting administrator-level access
  • Vendor risk assessments for third-party software providers
  • Incident response plans for continuing instruction during outages

Many experts also argue cybersecurity education itself must become part of student digital literacy efforts, especially as students increasingly use cloud-based learning systems beginning in elementary school.

States and schools are beginning to respond

While cybersecurity threats continue escalating, schools and state leaders across the country are also expanding efforts to strengthen digital protections and incident response systems.

More than 600 schools and districts nationwide — including large urban districts and small rural systems — were selected to receive support through the Federal Communications Commission’s $200 million Schools and Libraries Cybersecurity Pilot Program, which is helping schools test cybersecurity monitoring, protection and response tools.

Several states are also beginning to build statewide cybersecurity frameworks specifically for K-12 education.

Indiana and Ohio have expanded support to help schools meet new cybersecurity training expectations for staff and administrators. North Carolina developed a statewide Joint Cybersecurity Task Force that includes the FBI, National Guard, state education officials and local school districts.

North Dakota became the first state to require K-12 cybersecurity education, while Connecticut’s statewide education network now provides cybersecurity services to every public school district at no cost.

Investment is also rising at the district level despite mounting financial pressure. According to the Consortium for School Networking’s 2025 national survey, more than 78% of education technology leaders reported schools are increasing spending on cybersecurity monitoring, detection and response systems even as cybersecurity insurance and technology costs continue climbing.

Federal officials say the cybersecurity threat facing schools is no longer theoretical. “Schools and libraries are increasingly frequent targets of cyberattacks, which can disrupt learning, expose personal information, and impose significant financial costs,” said former FCC Chairwoman Jessica Rosenworcel while announcing the federal Schools and Libraries Cybersecurity Pilot Program.

Education technology leaders say the issue has evolved beyond technology departments alone.

“Cybersecurity is no longer just an IT issue. It’s a district leadership issue,” said Keith Krueger, CEO of the Consortium for School Networking. 

A new definition of school safety

For years, school safety discussions focused largely on physical security — campus entrances, emergency drills and school resource officers.

Today, education leaders say digital security must become part of that same conversation.

A single cyberattack can disrupt learning across entire districts, expose thousands of student records and interrupt operations for days or weeks. As schools continue integrating technology into nearly every aspect of instruction, cybersecurity preparedness is increasingly becoming as essential as any other infrastructure investment.

And experts warn the problem is unlikely to slow down anytime soon.

Editor’s note: A grant from the Arizona Local News Foundation made this story possible. The foundation awarded 15 newsrooms to pay for solutions-focused education reporters for two years. Please submit comments at yourvalley.net/letters. We are committed to publishing a wide variety of reader opinions, as long as they meet our Civility Guidelines.

Share with others


Have an opinion on this story? Click here to send a letter to our editors.

Comments

No comments on this item Please log in to comment by clicking here