ShinyHunters didn't hack 9,000 schools. They hacked one API.
The Instructure/Canvas breach (3.65TB stolen) proves that when your LMS is also your identity hub, one leaked token compromises 275M users. Most schools are too locked into their vendors to leave, even when security lags.
As Brian Bell, CEO of FusionAuth, puts it: "Vendor trust cannot be a one-time procurement decision. In edtech, it has to be continuously earned."
High switching costs shouldn't be a substitute for a robust security posture. We believe identity should be portable and self-hostable. If you can't move your data and rotate your keys on your own terms, you don't have security—you have a lease.