Texas K-12 School Districts — Cyber Threat Brief 2026

The School District Is the Target

CISA and MS-ISAC explicitly name K-12 as a primary ransomware target. The PowerSchool breach (Dec 2024) exfiltrated millions of student records — months later, individual TX districts received targeted follow-on attacks using the stolen data. The Canvas LMS breach (Jan 2025) hit 8,000 institutions. FERPA, HB 18/SCOPE Act, CJIS v6.0, and SB 820 create a four-framework compliance stack for Texas ISDs.

30M+
Canvas LMS users affected Jan 2025
1.4M
TTUHSC patient records via Interlock
6,500+
TX districts in PowerSchool breach follow-on attacks
Major Student Data Breach
PowerSchool — Dec 2024
ShinyHunters/Scattered Spider — student records from millions of K-12 students
Major LMS Breach
Canvas LMS — Jan 2025
3.65 TB from ~30M users across 8,000 institutions — TX universities during finals
TX Higher Ed Impact
TTUHSC — 1.4M exposed
Interlock ransomware — September 2024 breach disclosed 2025
Cooperative Contracts Available
TIPS / BuyBoard / DIR
CoreRecon at $89/endpoint — no RFP required

Why Texas School Districts Are Targets

CISA and MS-ISAC name K-12 as a primary ransomware target — particularly Phobos and RaaS variants optimized for SLTT

1–3
Average IT staff for a typical TX ISD — entire district, all campuses
Summer
Ransomware groups time attacks to minimum district staffing — summer break, Thanksgiving, winter break
$8.6M
Average cost of a K-12 ransomware incident including recovery, downtime, and notification (Comparitech 2024)
48 hrs
SB 820 requires incident notification to Texas Education Agency within 48 hours of discovery

Key attack patterns for Texas K-12: (1) Phishing emails to staff — credential harvesting via fake Office 365 login pages is the #1 entry vector; (2) Student data platforms — PowerSchool and Canvas LMS breaches gave attackers a massive dataset of student PII to weaponize for follow-on attacks; (3) Shared credentials across devices — same login for student Chromebooks, teacher laptops, and admin systems creates a wide, weakly defended surface; (4) Underfunded patching — many TX ISDs still run Windows 7 and Server 2012 with no security updates available; (5) Vendor-linked attacks — a compromised EdTech vendor can cascade into every district using that vendor.

Major Texas K-12 / Education Incidents — 2024–2026

December 2024 — K-12 National
PowerSchool Data Breach
Attributed to ShinyHunters/Scattered Spider. Exfiltrated student records (names, SSNs, medical info) from millions of K-12 students nationally. Multiple Texas ISDs confirmed exposure. Months later, follow-on targeted attacks against individual districts using the stolen data began. Districts received phishing emails containing the exact student information obtained in the breach.
January 2025 — Higher Ed / K-12
Canvas LMS Breach
Exfiltrated 3.65 TB of data from ~30 million users across 8,000+ institutions. Major Texas universities (UT Austin, Texas A&M, Texas Tech) affected during final exam periods. The breach included student grades, assignments, communications, and enrollment data. CISA attributed the attack to a compromised contractor environment.
September 2024 → Disclosed 2025
TTUHSC / Interlock Ransomware
Texas Tech University Health Sciences Center disclosed a September 2024 breach affecting approximately 1.4 million individuals. Interlock ransomware group claimed responsibility. The breach included patient medical records, demographic information, and potentially research data. OCR breach notification filed.
August 2022 — TX K-12
Dallas ISD (RansomHouse)
Dallas ISD ransomware (Aug 2022, RansomHouse) — 2,000+ student SSNs and personal data exfiltrated. The attack exposed a critical vulnerability in how school districts store and protect student PII. Athens ISD paid $50K to recover encrypted systems. The Dallas ISD precedent is cited in every subsequent TX K-12 risk discussion.

Texas K-12 Cybersecurity Compliance Requirements

Four frameworks simultaneously govern TX school district data security

Framework Scope Status Key Requirement
FERPA
Family Educational Rights and Privacy Act
All public schools receiving federal funding Active — federal Protect student education records; breach notification to parents, U.S. Dept. of Education; up to $100/violation per instance
HB 18 / SCOPE Act
Effective September 1, 2024
TX digital service providers with student data Active — TX state Data minimization, parental consent, privacy notice obligations for vendors processing minor student data; districts must ensure vendor compliance
CJIS v6.0
Full compliance: Oct 1, 2027
ISDs with School Resource Officer (SRO) programs / campus PD Active audit / Oct 2027 deadline 13 CJIS security policy areas; FBI audit scope for campus law enforcement systems; criminal justice data protection requirements
SB 820 (TX 88th Leg.)
TX Education Code §37.083
All Texas school districts Active — TX state Designate a cybersecurity coordinator; report cybersecurity incidents to Texas Education Agency within 48 hours; maintain cybersecurity policies

How CoreRecon Protects Texas K-12 Districts

30 min
Contractual incident response SLA — catches the compromise before student data exfiltration begins
$89/endpoint
Sentinel tier — specifically priced for TX K-12 IT budgets; procurable via TIPS/BuyBoard/DIR cooperative contracts
FERPA-aligned
SIS/LMS anomaly detection for FERPA-protected education records; breach documentation ready for OCR reporting

Key protection layers for K-12: Phishing defense with anomalous link detection and fake Office 365 login page blocking (stops the credential harvesting that precedes most ransomware), SIS/LMS activity monitoring for unauthorized access to student records (FERPA breach detection), summer and holiday attack prevention (the most common ransomware timing for K-12 is when IT staff is minimal), and SB 820 incident documentation that satisfies the 48-hour TEA notification requirement. CoreRecon maps all FERPA, HB 18/SCOPE Act, CJIS v6.0, and SB 820 requirements to SOC monitoring evidence packages that can be provided to auditors and the Texas Education Agency.

Frequently Asked Questions

What happened in the PowerSchool and Canvas LMS breaches that affected Texas schools?
The PowerSchool breach (December 2024, attributed to ShinyHunters/Scattered Spider) exfiltrated student records from millions of K-12 students nationally — including records from multiple Texas school districts. Months after the initial breach, individual school districts began receiving targeted follow-on attacks using the stolen student data. The Canvas LMS breach (January 2025) exfiltrated 3.65 TB from ~30 million users across 8,000 institutions, with major Texas universities affected during final exam periods. The cascading nature — initial breach, data weaponization, targeted follow-on attacks — is now a standard K-12 targeting playbook.
What are the specific Texas K-12 cybersecurity compliance requirements?
Four frameworks converge on Texas K-12 districts: (1) FERPA — federal student privacy law with up to $100/violation per instance; (2) HB 18/SCOPE Act (effective Sep 2024) — Texas data minimization, parental consent, and privacy obligations for digital service providers working with student data; (3) CJIS v6.0 — required for school resource officer programs with campus police; full compliance deadline is October 1, 2027; (4) SB 820 — requires Texas school districts to designate a cybersecurity coordinator and report incidents to Texas Education Agency within 48 hours. CoreRecon maps all four frameworks to SOC monitoring and generates audit-ready evidence packages.
Can Texas school districts procure CoreRecon through TIPS, BuyBoard, or DIR cooperative contracts?
Yes. CoreRecon is available through Texas cooperative purchasing programs including TIPS (The Interlocal Purchasing System), BuyBoard (Texas Association of School Boards cooperative), and DIR (Department of Information Resources). Cooperative contracts eliminate the need for a standalone RFP, satisfy competitive bidding requirements under Texas Education Code Chapter 44, and dramatically shorten procurement timelines from months to weeks. Region ESC purchasing offices can also coordinate district onboarding. Contact us for cooperative contract numbers and procurement documentation.
Why are ransomware groups specifically targeting TX K-12 school districts?
CISA and MS-ISAC explicitly name K-12 as a primary target for ransomware groups — particularly Phobos and RaaS variants optimized for SLTT environments. Key reasons: (1) Underfunded IT security — average TX ISD has 1–3 IT staff for the entire district; (2) High-value student data — FERPA-protected records are attractive for identity theft and resale; (3) Time-sensitive operations — school calendars create hard deadlines that make districts more likely to pay; (4) Legacy systems — many TX ISDs run Windows 7/Server 2012 systems no longer patched; (5) Shared credentials across student, teacher, and admin systems create a wide attack surface. CoreRecon's Sentinel tier at $89/endpoint is specifically priced for K-12 IT budgets.
How does FERPA breach notification work and what does it cost?
FERPA requires schools to notify parents within 60 days of discovering a breach of student education records, and to notify the U.S. Department of Education. Individual notification letters, credit monitoring services for affected families, regulatory reporting, and legal costs can exceed $50 per student affected — for a district with 5,000 students, a single breach notification event can cost $250,000+ before accounting for the breach itself. CoreRecon's SOC detects the indicators of compromise that precede a FERPA-reportable breach — before the student directory is exfiltrated, not after.

Protect Your District's Student Data

30-minute security posture assessment for Texas K-12 ISDs. We'll identify your FERPA exposure, student data system vulnerabilities, and the gaps between your current protection and what a breach-ready defense looks like. No obligation, no sales pressure.