惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
博客园 - Franky
V
V2EX
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
博客园 - 叶小钗
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
M
MIT News - Artificial intelligence
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
D
Docker
博客园 - 【当耐特】
阮一峰的网络日志
阮一峰的网络日志

Cyber Daily News

Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure OpenAI partners with PwC to assist CFOs with AI agents Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay APRA warns of cyber and governance risk due to lagging AI risk management Op-Ed: Australia’s next budget must treat cyber resilience as essential infrastructure Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ Report: AI-based data incidents on the rise in Australia WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July US Federal Reserve outlines AI's influence on the finance sector Exclusive: Major Australian jewellery brand confirms cyber incident Australian government establishes new Cyber Incident Review Board Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack
New South Wales, other states, investigating Instructure/...
david.hollin · 2026-05-07 · via Cyber Daily News

Education departments across the country are responding to a major breach at a third-party cloud education platform; expert warns: “third-party risk can no longer be treated as a procurement or compliance exercise”.

The New South Wales Department of Education is investigating the impact of a third-party data breach that has already compromised school students and staff in Queensland.

“The department is aware of the publicly reported data breach affecting Instructure's Canvas platform,” a department spokesman told Cyber Daily.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“The department is working with Instructure to establish if any NSW schools have been impacted and the nature of any data involved.

“Schools using the departmental sign-on do not have their passwords stored with Canvas, so there is no risk of credential exposure in those cases.”

Cyber Daily understands that many schools in NSW procure the Canvas platform directly from Instructure, while the Department has said any schools impacted by the breach will be supported.

The Queensland Education Minister confirmed today, May 7, that Education Queensland schools were impacted by the Instructure incident, which first came to light late last week.

“Advice at this stage is names, email addresses, and school locations have been compromised in the international data breach. No evidence of passwords, dates of birth, or financial information being accessed in the data breach,” John-Paul Langbroek said earlier today.

“School principals are in the process of contacting families and teachers to advise them of the breach.”

The ShinyHunters cyber extortion group is behind the incident and is claiming to have compromised millions of students and staff globally, and thousands of schools. In total, the hackers claim to have stolen more than 3.6 terabytes of data.

National response

Lieutenant General Michelle McGuinness, Australia’s National Cyber Security Coordinator, said in a post to LinkedIn that she was actively working to establish the scope of the breach.

"We are in the early stages of assessing the impacts, and I will share further updates as we gain a better understanding of the incident," Lieutenant General McGuinness said.

"If you think you may be impacted by this breach, the best way you can protect yourself is to not respond to unsolicited contact."

Tasmania’s Department of Education is also investigating the incident.

"Investigations commenced immediately and are ongoing. At this stage, while DECYP has been identified as being impacted by the cyber security incident, the specific impact of the incident is subject to further investigation by Instructure," a Department spokesperson said in a statement.

The University of Technology Sydney and the University of Sydney are also working on a response.

"If a breach of personal data has occurred, we will notify affected individuals and work closely with the National Office of Cybersecurity to manage the impact of the incident," a USyd spokesperson said.

"The university is one of approximately 9,000 educational institutions worldwide that is potentially impacted."

Why education?

Kash Sharma, Managing Director, ANZ, at cyber security firm BlueVoyant, said that breaches such as Instructure’s show that “schools are becoming an increasingly attractive target for cybercriminals”.

“Earlier this year, more than 1,700 Victorian government schools were similarly affected, exposing sensitive student records just as families prepared for the new school year,” Sharma told Cyber Daily.

“These incidents underscore a growing reality: education systems are no longer defending only their own networks, but also the expanding ecosystem of external vendors, platforms, and service providers connected to them.”

The issue is the sheer scope of the attack surface in the education sector. Not only are third-party providers such as Instructure driving attacks, but so are cloud services more generally, the adoption of online learning tools, and growing amounts of personal data held on aging school networks.

“For education leaders, third-party risk can no longer be treated as a procurement or compliance exercise. Institutional resilience now depends on the security posture of every connected vendor,” Sharma said.

“Effective third-party risk management requires continuous oversight across the full vendor lifecycle – from due diligence and onboarding through to ongoing monitoring, auditing, and incident response. Schools and education departments must move beyond static assessments and establish continuous visibility into vendor activity, security controls, and emerging threats.

“Without this shift, the rapid digitisation of education will continue to outpace the sector’s ability to secure it.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: