TL;DR: Cyberattacks on education providers in 2025 show that compromised credentials, privileged portal access, and password reliance remain enough to expose student data, according to Saviynt. The lesson is that schools and software providers need stronger PAM, zero-standing privilege, and passwordless identity controls before attackers turn routine access into broad compromise.
At a glance
What this is: Saviynt’s analysis argues that recent education-sector attacks were driven by compromised credentials, privileged access, and weak password dependence.
Why it matters: It matters because schools and education vendors handle sensitive student data, so IAM and PAM teams need controls that reduce standing privilege and remove reusable credential exposure.
By the numbers:
- Today, somewhere between 60% to 70% of all cybersecurity incidents are using compromised credentials.
- PowerSchool supports more than 50 million students.
- Around 1,400 different accounts received phishing emails in the Maine school district incident.
👉 Read Saviynt's analysis of 2025 education cyberattacks and identity lessons
Context
Education identity security is often treated as a matter of user convenience, but these incidents show it is also a matter of privileged access containment. When a support portal, a school email account, or a reused credential is enough to open a path into sensitive systems, the control problem is not edge security alone, it is identity governance.
For IAM, PAM, and IGA teams, the core issue is that student information and payment data sit behind identities that were never designed for persistent trust. That creates a familiar pattern: access is granted for operational efficiency, then reused, overextended, and eventually abused by an attacker who needs very little friction to move from login to impact.
Key questions
Q: How should education providers reduce the impact of compromised credentials?
A: They should combine stronger authentication with tighter privilege boundaries. The most important move is to stop a single support or admin credential from opening multiple systems. JIT elevation, session logging, and separate approval for high-risk actions reduce the blast radius when a credential is stolen.
Q: Why do support portals create disproportionate identity risk?
A: Support portals often sit at the junction between external users and internal systems, so they inherit both trust and reach. If portal accounts can trigger privileged operations or access sensitive records, attackers do not need a full application breach. They only need one valid account and one weak boundary.
Q: What do schools and education vendors get wrong about passwordless identity?
A: They sometimes treat passwordless as a complete solution rather than one control in a broader identity model. If recovery, delegated support, or privileged escalation still relies on weak identity checks, attackers will target those paths instead. Passwordless must be backed by lifecycle governance and privilege controls.
Q: Who is accountable when privileged access to student data is abused?
A: Accountability sits with the organisation that owns the identity path, not just the attacker. That means IAM, PAM, application owners, and support operations all share responsibility for how privilege is granted, elevated, monitored, and revoked across the system.
Technical breakdown
Compromised credentials as the first step into education systems
Education providers often rely on support portals, admin consoles, and service workflows that concentrate privilege in a few accounts. When attackers obtain a credential, they do not need to break the underlying application first. They log in as a legitimate user, inherit the portal’s trust, and then pivot to higher-value systems if the portal is already linked to operational access. That is why credential compromise is not just an authentication issue. It becomes an access architecture issue when one identity can open multiple downstream paths.
Practical implication: treat support portals and administrative consoles as privilege-bearing entry points and review their connected access paths as part of PAM governance.
Why zero-standing privilege matters in shared-service environments
Zero-standing privilege, or ZSP, removes persistent access and replaces it with task-scoped elevation. In environments like education software, that matters because administrators, support engineers, and platform operators often need temporary access to student records, payment flows, or system settings. If privilege is always on, the attack surface is always open. If access is time-bound and task-bound, the attacker’s usable window narrows sharply. This is especially relevant where service teams support thousands of institutional tenants through a shared portal.
Practical implication: move high-risk support and admin functions to JIT workflows so privileged access exists only for approved tasks.
Password dependence keeps exposure patterns predictable
Password-based identity remains vulnerable because it creates reusable secrets that can be guessed, phished, reused, or stolen. In sectors with many users and many support relationships, that predictability helps attackers scale. Passwordless authentication reduces the number of credentials that can be captured and reused, but it only works as part of a broader identity design that also governs recovery, session control, and privileged escalation. Without that, passwordless becomes one control among several rather than a material reduction in breach likelihood.
Practical implication: pair passwordless rollout with recovery-path review and privileged session controls so attackers cannot bypass one control through another.
Threat narrative
Attacker objective: The attacker’s objective was to turn a single compromised credential into broader access to student and payment data.
- Entry occurred when attackers used a compromised credential to access a customer support portal linked to additional internal systems. Escalation followed when that portal provided additive access to privileged user accounts that could reach sensitive student information. Impact came through exposure of personal and payment-related data across a large education environment.
Breaches seen in the wild
- MongoBleed breach — MongoBleed exposed secrets across 87K MongoDB servers.
- IOS app secrets leakage report — iOS apps leaking hardcoded secrets and credentials endangering user privacy.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Standing privilege is the failure mode this article exposes. The PowerSchool incident shows what happens when a support portal can hand an attacker additive access without a separate elevation decision. That is not a user-login problem alone. It is a privilege boundary problem, and education providers should read it as a warning that portal access and privileged access have been allowed to blur.
Compromised credentials remain the most efficient route into identity-led environments. Saviynt cites compromised credentials in 60% to 70% of incidents, which is consistent with the broader NHI and IAM pattern we see across sectors. The problem is not that defenders lack authentication tools. The problem is that reusable access still exists in places where trust has been assumed rather than continuously re-earned.
Zero-standing privilege is now a practical resilience measure, not a luxury control. If a school district, edtech provider, or managed support team can only protect student data through always-on admin paths, the breach window stays open by design. JIT elevation, narrow entitlements, and stricter portal-to-system segmentation change that structure. The implication is that privilege must be treated as a temporary condition, not an identity property.
Passwordless future: is the right direction, but only when paired with lifecycle controls. The article correctly points to password reduction, yet the larger governance issue is that credentials are still recoverable, resettable, and often overexposed in support processes. That means the security model must shift from password elimination alone to end-to-end identity lifecycle control. Practitioners should treat recovery, escalation, and delegated support as part of the same risk surface.
Education is a high-volume identity environment with low tolerance for access drift. Student data, parent payment details, and district operations create a large blast radius when access is overextended. The operational lesson is that sector size does not reduce attacker interest; it often increases it because control maturity is uneven. IAM and PAM teams need to assume adversaries will probe the easiest identity path first and make that path expensive to abuse.
From our research:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which is why privileged access often outpaces governance.
- Use the 52 NHI Breaches Analysis to compare this breach pattern with other cases where access paths, not malware, created the opening.
What this signals
Education providers should expect identity attacks to keep targeting the easiest delegated path, not the best-defended one. The practical response is to align PAM, support workflows, and access reviews around the identities that actually carry data access, including service accounts and portal-admin accounts.
Support-path privilege drift: when a help-desk or customer portal can touch production data, that portal becomes part of the identity control plane. Teams that still separate support governance from privileged governance will miss the real attack surface. See the Ultimate Guide to NHIs for the lifecycle controls that help close that gap.
For practitioners
- Map support portals to privilege boundaries Inventory every support portal, admin console, and tenant management path that can reach student records or internal systems. Require a separate elevation step before any privileged action is allowed, and verify that no portal session can directly inherit system administration rights.
- Adopt zero-standing privilege for privileged operators Move administrative access to JIT workflows with approval, expiration, and logging. Make sure the access granted for one support task cannot be reused for another without a fresh entitlement decision.
- Reduce password dependence in recovery and support flows Replace reusable passwords where possible and review account recovery paths that still depend on help-desk verification. Passwordless authentication only reduces risk if the fallback and reset paths are equally governed.
- Segment student-data access from operational support tools Separate systems that handle student information and payment-related data from general-purpose support tooling. Apply least privilege to the connectors, APIs, and delegated accounts that bridge those environments.
Key takeaways
- The breach pattern here is privilege expansion through a compromised support credential, not a novel exploit chain.
- The scale of exposure is visible in the data: Saviynt cites compromised credentials in 60% to 70% of incidents and more than 50 million students supported by PowerSchool.
- Zero-standing privilege, tighter portal segmentation, and governed passwordless recovery are the controls that change the outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on compromised credentials and privileged access paths. |
| NIST CSF 2.0 | PR.AC-4 | Least privilege and access restrictions are the key controls in this article. |
| NIST SP 800-53 Rev 5 | IA-5 | Password and authenticator management is directly relevant to the article's passwordless argument. |
| NIST Zero Trust (SP 800-207) | Zero Trust principles align with the article's call to remove implicit portal trust. |
Review NHI credential issuance and revocation paths, then remove any standing privilege from support workflows.
Key terms
- Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
- Compromised Credential Screening: Compromised credential screening checks new or changed secrets against known breach corpuses before they are accepted. In practice, it prevents users and service owners from choosing passwords that have already been exposed, which lowers account takeover risk and reduces the chance that an identity programme certifies a broken secret.
- PAM — Privileged Access Management: Solutions that control, monitor, and audit privileged access for both human and non-human identities. Traditional PAM tools are being extended to cover machine identities, service accounts, and agentic AI workloads.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific education-sector attack chain discussed in the source article, including how credential compromise led to additional access.
- The vendor's explanation of why zero-standing privilege and JIT access matter in privileged support environments.
- The article's treatment of passwordless identity as a response to credential exposure in school and edtech environments.
- The original commentary on how attackers prioritise vulnerable targets and scale their efforts across the education sector.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org