Every few weeks this year, a headline lands that reads almost the same way: a university confirms a data breach, a criminal group claims a leak site listing, and administrators say there's no evidence of broader compromise. Each incident gets reported as its own isolated story, then the news cycle moves on, and it happens again somewhere else.
But they're not isolated. If you look closely at 2026's higher ed breach disclosures, you see a pattern emerge. It's the same story, told four or five times, just with different characters.
The pattern: it's rarely a sophisticated attack
In August, Newcastle University confirmed that a misconfiguration tied to its admissions system exposed contact information for roughly 440,000 people. The university traced the exposure back to a single connection setting.
Two months earlier, the University of Western Australia found that an administrator had left system access credentials for Callista, its student information system, exposed online. Just a credential that shouldn't have been reachable, sitting in the open until someone found it.
Around the same time, Avans University of Applied Sciences in the Netherlands discovered a Power BI misconfiguration had quietly exposed personal data to unauthorized viewers for nearly a year before anyone noticed.
And earlier this year, Instructure's Canvas platform, used by roughly 9,000 schools, was breached by the extortion group ShinyHunters. The group claimed 275 million records and later defaced Canvas login portals at hundreds of institutions, timed to land during finals week. 90 days after that, the same group exploited an unpatched remote-code-execution flaw in Oracle PeopleSoft, reaching more than 300 instances at over 100 organizations, most of them universities.
Different platforms, different countries, same throughline: an opening sat exposed until an attacker found it and used it.
Why this keeps happening to universities specifically
It's tempting to chalk this up to bad luck, or to assume higher ed is just a bigger target than other sectors. Neither are the issue here.
What actually distinguishes higher education is structural. A university runs an enormous digital estate—admissions platforms, student information systems, research infrastructure, alumni and donor databases, learning management systems, and dozens of departmental tools procured independently—and that estate is governed in a decentralized way almost by design. Individual departments, colleges, and administrative offices often manage their own systems and vendor relationships, each with its own security standards, its own IT staffing, and its own blind spots.
That's exactly what produces configuration gaps: nobody owns the full picture, so nobody notices when one piece of it opens up.
And here's the uncomfortable part of this pattern: these are hygiene gaps. None of them require advanced attacker skill. A misconfigured system connection should get caught before it ships, not after a criminal group posts a sample to a leak site. Students, applicants, and alumni have no way to check whether the admissions vendor connection or the third-party dashboard pulling their data is configured correctly. They're trusting the institution to get the basics right, and that trust runs into a hard reality: lean IT and security teams, already stretched across identity, endpoints, and everyday support, often don't have the staffing to keep up with every connected system.
At Black Hat, Jen Easterly talked to Caitlin Sarian (aka Cybersecurity Girl) about this very issue. Watch their conversation on why education tech vendors need to own more of the security burden and how schools should operate in a fragile digital world.
Why this matters
Attackers are opportunistic. They don't need to pick between finding a misconfiguration and stealing a credential—they'll take whichever door is open.
Most of these incidents started as exposure problems: a setting or credential that was wrong before an attacker got involved. That's a different entry point than the identity-based attack techniques we've been seeing elsewhere, like credential-driven ransomware or mailbox hijacking. But an open door and a stolen key lead an attacker to the same place: standing inside a system that should have required more than what they had. Whether the gap is a misconfigured connection or a compromised login, identity and access are usually where the real damage decision gets made, well before ransomware or a leak site listing enters the picture.
What actually breaks this pattern
If the failure mode is "nobody saw the gap before an attacker did," the fix isn't a bigger security budget or another point tool bolted onto an already sprawling stack. Keeping education environments safe requires visibility into what's actually exposed, before it becomes a headline.
That means:
Knowing what's connected and how. Third-party integrations, dashboard connections, and extensions accumulate quietly across departments. Without an inventory of what's exposed and how it's configured, the first sign of trouble is often a leak site listing.
Watching identity as closely as endpoints. Several of this year's biggest higher ed incidents point back to credentials and identity rather than malware. A misconfiguration is often the door; identity is what an attacker walks through once they're inside.
Designing for decentralization, since it isn't going away. Most universities can't and won't consolidate every departmental system under one central IT function. Continuous visibility across a distributed environment is a more realistic goal than a single command center with control nobody actually has.
The takeaway
Higher education isn't unlucky in 2026. It's structurally exposed in a way that keeps producing the same story: a decentralized environment, inconsistent standards across departments and vendors, and a configuration error that sits open until a criminal group finds it.
While every institution moved fast to contain and disclose the gap once it surfaced, the harder work is finding those gaps before someone outside the institution does. And that comes down to knowing what's actually exposed and reachable across your environment.
Want the fuller picture of how attacks on schools and universities are evolving? Huntress' 2026 Education Threat Report breaks down the shift toward quieter, identity-based, living-off-the-land techniques in education environments, with real examples and specific steps on what stronger security looks like.