TL;DR: Cyberattacks on education providers in 2025 show that compromised credentials, privileged portal access, and password reliance remain enough to expose student data, according to Saviynt. The lesson is that schools and software providers need stronger PAM, zero-standing privilege, and passwordless identity controls before attackers turn routine access into broad compromise.
NHIMG editorial — based on content published by Saviynt: 3 Lessons Learned from 2025 New Year Cyber Attacks on Education
By the numbers:
- Today, somewhere between 60% to 70% of all cybersecurity incidents are using compromised credentials.
- PowerSchool supports more than 50 million students.
- Around 1,400 different accounts received phishing emails in the Maine school district incident.
Questions worth separating out
Q: How should education providers reduce the impact of compromised credentials?
A: They should combine stronger authentication with tighter privilege boundaries.
Q: Why do support portals create disproportionate identity risk?
A: Support portals often sit at the junction between external users and internal systems, so they inherit both trust and reach.
Q: What do schools and education vendors get wrong about passwordless identity?
A: They sometimes treat passwordless as a complete solution rather than one control in a broader identity model.
Practitioner guidance
- Map support portals to privilege boundaries Inventory every support portal, admin console, and tenant management path that can reach student records or internal systems.
- Adopt zero-standing privilege for privileged operators Move administrative access to JIT workflows with approval, expiration, and logging.
- Reduce password dependence in recovery and support flows Replace reusable passwords where possible and review account recovery paths that still depend on help-desk verification.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific education-sector attack chain discussed in the source article, including how credential compromise led to additional access.
- The vendor's explanation of why zero-standing privilege and JIT access matter in privileged support environments.
- The article's treatment of passwordless identity as a response to credential exposure in school and edtech environments.
- The original commentary on how attackers prioritise vulnerable targets and scale their efforts across the education sector.
👉 Read Saviynt's analysis of 2025 education cyberattacks and identity lessons →
Education cyberattacks: what IAM and PAM teams need to fix now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Standing privilege is the failure mode this article exposes. The PowerSchool incident shows what happens when a support portal can hand an attacker additive access without a separate elevation decision. That is not a user-login problem alone. It is a privilege boundary problem, and education providers should read it as a warning that portal access and privileged access have been allowed to blur.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which is why privileged access often outpaces governance.
A question worth separating out:
Q: Who is accountable when privileged access to student data is abused?
A: Accountability sits with the organisation that owns the identity path, not just the attacker. That means IAM, PAM, application owners, and support operations all share responsibility for how privilege is granted, elevated, monitored, and revoked across the system.
👉 Read our full editorial: Education sector cyberattacks expose credential and privilege gaps