AI-powered scams raise stakes of student data breaches, cybersecurity expert warns Pic: AI generated
Do You Know

AI-powered scams raise stakes of student data breaches, cybersecurity expert warns

EdTech platforms rely on third-party services to manage payments, communications and student records. A cybersecurity expert explains how gaps in vendor security can expose children and their families to data breaches and AI-enabled fraud.

Sashikanth Yechuri

EdTech platforms handling student information may be exposing children to cyber risks through the third-party services they rely on, cybersecurity expert Sarthak Dubey has warned. From payment gateways and cloud providers to messaging services and school management systems, every integration can create another point of vulnerability if security checks are inadequate.

Dubey said his experience running a K-12 EdTech platform that managed data relating to more than 600,000 students across India, highlighted how widely student information can be shared across digital services.

The information included names, dates of birth, photographs, videos, school details, phone numbers, parents’ contact information, fee records and academic performance. While these details help institutions manage operations and communicate with families, their movement across multiple systems can increase the risk of unauthorised access.

“The danger rarely sits in the platform a parent signs up for. It sits in the web of third-party systems behind it, and in how those systems talk to each other,” Dubey said.

How a data leak can put children at risk

A breach involving student records could expose information that criminals may use to target children and their families. When personal details are combined with publicly available photographs, videos or audio, the risks can extend beyond identity theft and financial fraud.

Dubey warned that generative AI could make such scams more convincing by enabling criminals to clone voices and create deceptive scenarios using stolen personal information. For instance, a fraudster could impersonate a child in distress and pressure a parent into transferring money urgently.

The concern extends beyond EdTech platforms to schools and colleges, which handle admissions documents, identity records, medical information, disciplinary records, fee details and scholarship data.

Dubey said common security weaknesses include shared administrator passwords, the absence of multi-factor authentication, vendor accounts that remain active after contracts end, exposed API keys and inadequate monitoring. When several service providers exchange information, gaps in responsibility can make these weaknesses harder to detect.

What schools and EdTech companies can do

India’s Digital Personal Data Protection Act, 2023, includes specific safeguards for children’s personal data, including requirements concerning verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising, subject to the law’s applicable provisions.

However, protecting student information also requires institutions to examine how their vendors collect, store, access and transfer data.

Dubey recommended mapping data flows across all service providers, assessing vendors before and during contracts, collecting only necessary information and deleting records when they are no longer required. He also stressed the importance of multi-factor authentication, limiting vendor access to essential functions, monitoring systems continuously and maintaining a tested incident-response plan.

Parents, too, need clear guidance on recognising potential fraud. Institutions should explain how official payment requests are communicated and provide families with a reliable way to verify urgent requests.

As education increasingly depends on connected digital platforms, cybersecurity cannot stop at the institution’s own systems. The services handling student data must be part of the same security framework, with clear responsibilities for protecting children’s information.

RCB Industrial Biotechnology Admissions 2027 open for 30 Seats: Apply by November 13

Karnataka SSLC Exam Time Table 2027 Released: Exam 1 from March 22, Exam 2 from May 24; check subject-wise dates

Karnataka 2nd PUC Time Table 2027 Released: Exam 1 from February 27, Exam 2 from May 3; check subject-wise dates

Maharashtra shifts both MHT-CET 2027 attempts to after Class 12 board exams

TG SET Answer Key 2026 Challenge Window Opens October 12: Objections accepted until October 15