Why AI Is a Big Problem for School Cybersecurity
Artificial intelligence is transforming education technology and expanding cybersecurity risks. In the Education Week article, experts examine how AI adoption is creating new challenges for schools.
Read the article to learn how AI tools are expanding the cybersecurity attack surface in education, why automated threats and phishing attacks are becoming more sophisticated, and what security considerations schools should evaluate as AI adoption grows.
Why AI is reshaping cyber risk for schools
AI is changing the way cyberattacks are planned and executed, and schools are feeling that shift.
On the attacker side, generative AI tools now help cybercriminals:
- Write convincing phishing emails in fluent American English, without the spelling and grammar errors that used to be red flags.
- Impersonate trusted leaders by mimicking a superintendent’s writing style, voice, or even appearance using deepfakes.
- Research targets at scale by combing through public information—budgets, vendor lists, staff emails—to tailor scams and payment fraud.
At the same time, schools are attractive targets because they:
- Hold large volumes of sensitive data on children and staff, including Social Security numbers and financial information.
- Manage significant funds and payments to vendors, which can be redirected in fraud schemes.
- Often have limited budgets and staff dedicated to cybersecurity compared with banks or hospitals.
Personal data belonging to children is especially valuable on the dark web because kids typically have “clean” credit histories and there’s no standard system to alert families when a child’s identity is misused.
All of this means AI doesn’t just help educators work faster—it also helps hackers work faster, cheaper, and at greater scale, which raises the overall cyber risk for K-12 systems.
Impact of funding cuts on school cybersecurity
AI-driven threats are increasing at the same time that several key federal supports for school cybersecurity have been reduced or reshaped.
Key changes include:
- MS-ISAC funding cuts: The Multi-State Information Sharing and Analysis Center, once a major source of free cybersecurity support for schools, lost its federal cooperative agreement. It still operates, but districts now face membership fees unless their state covers the cost.
- Suspension and relocation of coordination bodies: The federal K-12 Cybersecurity Government Coordinating Council, which brought together agencies, states, districts, and vendors to coordinate responses, was effectively suspended and has since moved to the Institute for Security and Technology.
- Closure of the Office of Educational Technology: The U.S. Department of Education closed this office, which had helped states and districts navigate emerging technologies, including AI and cyber risk.
One remaining federal initiative is a 3-year FCC pilot that initially aimed to provide up to $200 million in competitive grants so schools and libraries can purchase cybersecurity products and services through E-rate. However, experts note that it’s unclear what will happen after the first round of grants and whether the program will become permanent.
These shifts matter because the federal government has visibility into national and global threats that individual districts and even states do not. Losing easy access to that intelligence and to subsidized services makes it harder for resource-constrained K-12 systems to keep pace with AI-enabled attackers.
Practical steps to strengthen AI-era defenses
Districts don’t need a blank check to make meaningful progress. A combination of collaboration, training, and basic controls can significantly improve resilience, even as AI changes the threat landscape.
1. Join or build information-sharing networks
- Explore membership in MS-ISAC, which offers services on a sliding fee scale based on budget size. Several states—Alaska, Connecticut, Kansas, Maine, Mississippi, New Jersey, Oregon, Texas, and Vermont—have joined MS-ISAC so districts there can access services at no additional cost.
- Collaborate with neighboring districts or state-level groups (such as CoSN chapters) to share threat intelligence, policies, and best practices.
2. Invest in people, processes, and practice
- Run tabletop exercises with district leadership to rehearse how you would prevent, detect, and respond to a cyber incident.
- Define clear cybersecurity protocols for staff, including how to handle suspicious emails, payment requests, and data access.
- Introduce verification steps for financial transactions—such as code words or secondary approvals—so staff don’t act solely on an email, phone call, or video that appears to come from a senior leader.
3. Train staff to spot AI-enhanced phishing
- Use software that sends fake phishing emails to employees. When someone clicks, route them to a short training video on how to recognize phishing attempts.
- Reinforce that no payment should ever be rushed based only on a sense of urgency in an email or call, even if it seems to come from the superintendent.
4. Double down on cybersecurity basics
Experts emphasize that “blocking and tackling” still matters, even in the AI era:
- Enable multi-factor authentication (MFA) for staff and critical systems.
- Require strong, unique passwords and support password managers where possible.
- Keep software and systems patched and up to date to close known vulnerabilities.
In a recent CoSN survey, 60% of district technology leaders said AI will lead to new forms of cyberattacks, and another 34% said they were moderately concerned. That level of concern can be channeled into practical action: collaboration, continuous staff education, and disciplined attention to the fundamentals.

Why AI Is a Big Problem for School Cybersecurity
published by Mayhem Shield
More about us
Mayhem Shield is an independent, buyer-side assurance practice for enterprise AI deployments. When an organization is preparing to approve an AI tool for production, a coding assistant, a RAG pipeline, an agentic system, its approval forums need evidence of how the implementation will actually operate in that environment, not a vendor marketing pack. That evidence is what we produce.
We do not sell, implement, or operate the AI products we review. We are paid only by the buyer, never by the vendor. That separation is the product: it is what makes our findings defensible in front of security, architecture, risk, and audit stakeholders.
How we work
- Structured, repeatable review logic. Phases, evidence rules, severity calibration, and gate criteria are defined in advance, not invented per engagement. The methodology is published and inspectable on GitHub without a sales call.
- Grounded in your environment. Findings are tested against your identities, data paths, integrations, and workflows as actually deployed, not against the vendor's reference architecture.
- Decision-ready outputs. Every engagement ends in a written position: go, conditional go, or no-go, with a traceable findings register, evidence requests, and conditions tied to POC, pilot, and production gates.
Core capabilities
- AI implementation assurance reviews. Fixed-structure packages from a two-week rapid readiness review of one tool through a portfolio program covering three or more tools under one assurance standard.
- Architecture and trust-boundary analysis. Deployment model, data flow, identity, and integration scope for AI systems, documented in formats governance forums already recognize.
- AI vendor claim verification. Assessment of whether a vendor's published security and data-handling claims are checkable, contractual-only, or unverifiable, before those claims underwrite an approval.
- Security and governance advisory. Buyer-side support for AI review boards, evidence standards, and approval gate design.
We maintain relationships with major cloud and technology providers for market and technical visibility. Because our work is buyer-side assurance, we take no resale margin or implementation fees from any vendor, and any relationship relevant to a specific review is disclosed to the client at scoping.
Our commitment
Approvers carry personal and organizational risk when they sign off on an AI deployment. Our job is to make sure they sign with evidence in hand. For more information, visit www.mayhemshield.com or contact us at info@mayhemshield.com.