AI in Schools
Canvas hit twice, Sydney and Melbourne confirm exposure
Three stories today, all about who looks after student data when the platform underneath the school does not. Canvas got hit a second time on Wednesday, the OAIC's draft Children's Online Privacy Code has another month of public consultation, and the federal budget on Tuesday will say what the government plans to spend on the problem.
Canvas got defaced on Wednesday, and the new ransom deadline is Tuesday 12 May
ShinyHunters compromised Instructure's Free-For-Teacher accounts on 7 May, injected an HTML file that replaced login pages at affected schools with a public extortion notice, and reset the deadline. The group now claims data on 275 million users across roughly 9,000 institutions and is demanding a settlement by 12 May or it leaks the lot. Instructure shut down the Free-For-Teacher tier, applied patches, and confirmed Canvas was "fully back online" by Friday morning Australian time. The University of Sydney and the University of Melbourne have now both confirmed that vendor advice puts their data in the breach scope. The University of Canberra was notified on 4 May, with a follow-up confirmation on 6 May, joining a list of 25 ANZ universities now caught up. Cyber Daily reported a search of the published victim list returned 27 Australian hits.
Why this matters: This is the second compromise inside two weeks, on the same vendor, against the same group. For Australian institutions the operational read has shifted. The first incident was a data-exposure question, narrow and manageable. The second is a vendor-resilience question, which is harder. Pro-vice-chancellors who signed off a Canvas business case in 2024 should expect their council's risk committee to ask, between now and June, what the contract says about a third compromise and what the exit cost would be. The free-tier vector is the part education policy teams should read carefully, because every Australian school where a teacher set up a personal Canvas account to trial a unit is now in the same blast radius as the institutional tenancies. Cyber Daily on the second hit and the Australian list, TechCrunch on the defacement and the 12 May deadline, and University of Canberra's media release.
The OAIC's draft Children's Online Privacy Code is open for consultation until 5 June, and the Canvas breach just sharpened every word in it
The Information Commissioner released the exposure draft of the Code on 31 March and is consulting until 5 June, with the final Code to be registered by 10 December 2026. The Code applies to online services likely to be accessed by children or "primarily concerned with the activities of children", which by the OAIC's own scoping note covers childhood-development apps, parent-photo-sharing tools, and platforms that "support schools to monitor student performance". It introduces a statutory right for children and parents to request deletion of personal information, treats geolocation tracking as a high-risk default-off, and lifts the bar on age assurance well above the current self-declaration norm.
Why this matters: The Code is the back-end answer to the front-end story this week. Schools cannot procure their way out of vendor risk on their own, but a registered code creates baseline obligations every ed-tech vendor selling into Australian schools has to meet, and a clean enforcement lever the OAIC can pull when they do not. For SBMs and IT leaders running procurement now, the practical move is to draft tender questions today against the exposure-draft text, because every Code requirement is a vendor obligation in seven months, and the suppliers that cannot answer in May will not be ready in December. The OAIC's exposure draft and consultation portal.
Tuesday's federal budget is the next inflection point for ed-tech spending
Treasurer Jim Chalmers delivers the 2026-27 Budget on Tuesday 12 May at 7.30pm AEST. Chalmers has signalled a productivity package, a tax-reform interest, and "substantial" savings. Most pre-budget commentary frames the sector picture as cost-of-living, healthcare, housing, and education assistance, with technology and services treated as targeted reform rather than headline spend.
Why this matters: For ed-tech specifically, the four lines worth circling on Tuesday night are: any new envelope for the proposed Teaching and Learning Commission, anything that names ATEC's 2027 Managed Growth allocation in dollar terms, the next tranche of the Better and Fairer Schools Agreement profile through 2034, and any cyber-resilience funding directed at the school and university sector specifically. The Canvas incident lands the cyber line in particular as a politically live ask, not a notional one, and Tuesday is the first chance the Treasurer has to put a number against it. SBS News on the Treasurer's pre-budget signals.
The convergence this week is awkward and useful. Privacy Awareness Week 2026 runs 4 to 10 May with the theme "Trust is built here", the OAIC's Children's Code consultation has another month, and the largest LMS breach on record is in its second round. The reading is that vendor-side controls are now doing more of the work than school-side policies, and the regulators are quietly catching up to that fact. More on the operational landscape at digitalattitudes.com.au.