What these breaches actually look like
The examples below are from the last few years. New breaches are reported regularly, but the pattern stays the same.
A 19-year-old used a stolen contractor password to access PowerSchool, the student information system used by thousands of schools across North America. The breach exposed the data of more than 60 million students and around 10 million teachers.
What was potentially taken: names, home addresses, phone numbers, Social Security Numbers, grades, bus stops, passwords, medical alerts, and parent contact details. Not every student had every type of data stored, but fewer than a quarter of affected students had Social Security Numbers in the system.
PowerSchool paid the hackers a ransom in exchange for a promise that the data would be deleted. The data is still unaccounted for, and individual school districts continued to receive extortion demands months later.
A group calling themselves Radiant broke into the systems of Kido International, an early-years nursery chain headquartered in London with locations in the UK, US, China and India. They leaked personal data on about 8,000 children and staff.
What was taken: names, photographs, dates of birth, home addresses, parent and carer contact details, safeguarding notes, and medical information.
To pressure the company, the group posted a sample of 10 children’s profiles on a dark-web site and began phoning parents directly to demand a ransom of around £600,000. After widespread public backlash, the group removed the data and claimed to have deleted it. They did not receive the ransom. Two teenagers were later arrested.
Attackers accessed Canvas, the learning platform used by around 30 million students and teachers worldwide across about 8,800 schools and universities. It is now considered the largest education data breach ever recorded.
What was taken: names, email addresses, student ID numbers, course information, and private messages between students and teachers. Because Canvas is also where students often disclose medical conditions to request accommodations and have private conversations with advisors, those sensitive messages were likely included.
The hackers, a group called ShinyHunters, claimed they stole 3.65 terabytes of data on 275 million users. Instructure later reached an agreement with the group and said the data had been destroyed, though there is no way to verify that
why this matters for kids
A child starts leaving a data trail from birth. Nursery systems, paediatric records, school portals, homework apps, gaming accounts, clubs and after-school activities. By the time they are eleven, dozens of companies hold information about them. By eighteen, more than a decade of leaks are already sitting on criminal forums and data broker sites, attached to a person who had no say in any of it. This is the part I cover in more detail in Digital Footprint for Kids.
There are also a few practical differences worth knowing:
Adults build up a sense of which message looks suspicious, which link not to click, which call sounds wrong. A nine-year-old does not have that filter, and neither does a tired parent juggling school messages at 8am.
Safeguarding notes, allergy alerts, pickup permissions, class photos, parent contact details. This kind of information is not collected about adults. When it leaks, it directly enables scams that target the family through the child.
A leaked email address an adult stops using is a dead end. A leaked home address, school name, and date of birth of a five-year-old will still be accurate when they are fifteen.
how leaked data is actually used
This is the part most coverage skips. A breach in the news feels like a single event. In practice, leaked data is a building block.
Criminal groups, and the data broker industry that sits next to them, combine breaches. A name and email from one leak. A home address and date of birth from another. A school name from a third. Each leak on its own looks small. Together they build a profile of a real child in a real family.
In the cybersecurity world, this is called data enrichment. It is the foundation of most modern phishing. Attackers no longer send generic emails to a million addresses hoping someone clicks. They send messages that already know your name, your child’s name, your school, and sometimes your phone number, because all of that came from leaks they bought or downloaded.
A few examples of what this looks like in practice:
- A WhatsApp message addressed to you by name, mentioning your child’s actual school, asking you to pay for a trip via a link.
- A phone call to a grandparent that uses the child’s name and date of birth to sound credible.
- A fake “parent portal” login page sent by email, designed to harvest your real school password.
- An account takeover attempt on your child’s gaming account, using a password reused from a breached site.
None of these require a single huge attack. They require small details from many small leaks, combined.
What parents can actually do
You cannot stop the next breach from happening. The companies holding your child’s data are the ones responsible for that. But there are real things within your control.
Every app permission, every loyalty card, every “create an account to continue”, every form that asks for a date of birth is another database that can be breached. Saying no to the ones that are not essential is the cheapest protection there is. The same logic applies to what you share publicly, which is something I covered in how Facebook quietly processes your camera roll.
If a leak contains your child’s school name and your phone number, a scam pretending to be from the school becomes very easy to write. Any message asking you to pay, click, or confirm something urgent is worth checking through the school’s normal channels first, even if it looks real.
When passwords are reused, one leaked password can open many doors. A password manager makes this easy.
Most parents are surprised by how much of their own and their child’s information is sitting in old accounts, on data broker sites, or in past breaches. A proper check across these sources is the first step to reducing it. If this is something you want help with, I offer a digital footprint check that does exactly this.
Before installing a new app or registering for a new service for your child, it is worth pausing to ask what data is being collected, why, and how long they keep it.
Where this leaves us
Your child’s data lives across dozens of systems. Their school, their nursery, their doctor, their favourite app, their homework platform, the company that prints their class photo.
That does not mean privacy is a lost cause. It is more about reducing how many places hold the data, paying attention to what is being asked of you, and treating the messages your family receives with the small dose of healthy doubt this era now requires.
FREQUENTLY ASKED QUESTIONS
How do I know if my child's data has been in a breach?
You usually do not. Schools and apps are legally required to notify families when they know about a breach, but many breaches are discovered months after they happen, and some are never disclosed publicly. The most reliable way is to actively check what data about your child and your family is already exposed across breach databases, data broker sites, and old accounts.
What should I do if my child's school had a data breach?
First, find out exactly what data was involved. Schools should tell you this in writing. Then change any reused passwords on accounts linked to that school, watch for school-themed phishing messages over the following months, and if Social Security numbers or government IDs were involved, ask the school what identity protection they are offering and whether a credit freeze is appropriate for your child.
Can I remove my child's data from the internet?
Some of it, yes. Old accounts can be deleted, data broker listings can be opted out of, and public social media posts can be removed. But data that has already leaked to criminal forums cannot be pulled back. The realistic goal is to reduce future exposure and clean up what is still under your control.
At what age should children have their own email and accounts?
There is no single right answer, but a few principles help. Use a family email address for younger children’s sign-ups, so you control what comes in. Avoid using your child’s real full name and date of birth on accounts that do not legally require it. When they are old enough for their own email (usually around 11-13), set it up together and walk them through privacy settings before they start signing up to things on their own.
What is the difference between a data breach and identity theft for a child?
A data breach is when a company holding your child’s information gets hacked or leaks it. Identity theft is when someone uses that information to open accounts, take out credit, or impersonate your child. Breaches are common. Identity theft of children is rarer but harder to detect, because most parents never check their child’s credit file. A child’s identity can be used for years before anyone notices.


