Universities worldwide have been struck by a string of data exposures this year that reveal a common pattern: most incidents are not the result of sophisticated, nation-state style intrusions but rather basic security failures such as misconfigured systems, exposed credentials and unpatched software.
Simple mistakes, big consequences
Several recent cases show how small errors can produce large breaches. In one incident, a configuration issue in an admissions system at a UK university left contact details for about 440,000 people accessible. Another higher education institution discovered that an administrator had inadvertently left access credentials for its student information system publicly reachable. Elsewhere, a misconfigured Power BI deployment exposed personal data for almost a year before being detected.
These examples are contrasted with attacks that exploited platform vulnerabilities at scale. The education-focused learning management platform Canvas, used by roughly 9,000 schools, was hit by the extortion group ShinyHunters, which claimed 275 million records and also defaced login portals during a critical assessment period. Within three months the same group used an unpatched remote-code-execution flaw in Oracle PeopleSoft to reach more than 300 instances across over 100 organisations, many of them universities.
Why universities keep showing up in breach reports
Higher education institutions typically operate extensive and complex digital estates that combine legacy systems, third-party platforms, research data stores and numerous administrative applications. That scale and diversity increase the chance that a single overlooked setting or unprotected credential will create a route into sensitive data.
- Complexity: Multiple systems and vendors expand the attack surface.
- Accessibility: Universities often prioritise openness for collaboration and teaching, making strict segmentation harder.
- Resource constraints: IT teams can be underfunded and stretched across many priorities, delaying routine patching and audits.
Implications for students, staff and research
When student or staff data is exposed it can have immediate privacy and safety impacts, and when research environments are compromised the consequences extend to intellectual property and institutional reputation. The timing of some attacks — for instance, during exams or deadlines — also magnifies disruption and distress.
| Incident type | Illustrative scale |
|---|---|
| Admissions system misconfiguration | ~440,000 contact records exposed |
| Learning platform compromise (Canvas) | ~275 million records claimed |
| Unpatched enterprise software (PeopleSoft) | > 300 instances affected at > 100 organisations |
These figures indicate that the problem is not limited to single institutions or regions; the same classes of error recur across countries and platforms.
What can South African institutions take from this pattern?
While the reported incidents relate to universities abroad and international platforms, the lessons are directly relevant to South African higher education and to any organisation that manages large volumes of personal and research data. Practical steps that institutions should prioritise include:
- regular configuration audits of public-facing systems and dashboards;
- robust credential management, including removing hardcoded or publicly stored access keys;
- timely patching of enterprise software and clear vendor update processes;
- network segmentation to limit the blast radius if one system is compromised;
- ongoing staff training so administrators and researchers recognise risky settings and phishing attempts.
Many of the incidents described were avoidable through basic cyber-hygiene and governance. Institutions should balance openness with protective controls so that collaborative work and teaching do not come at the expense of personal data security.
For students, parents and staff, transparency after an incident is critical: clear communication about what was exposed, how the institution will mitigate harm and what support will be offered helps rebuild trust.
As higher education continues to rely on cloud services, third-party platforms and interconnected systems, the sector must treat cyber security as a core academic and administrative responsibility rather than a peripheral IT issue. The recurring pattern in 2026 shows that the weakest link is often a simple oversight — and fixing those oversights is a matter of governance, resourcing and routine practice.