K-12 Cybersecurity Insider | 8/3/2026 edition

A public newsletter providing curated cybersecurity news to the K-12 community as a service of K12 SIX, the K-12 education ISAC. Allowlist info[@]k12six[.]org - and sign up for the K12 SIX mailing list - to have future editions delivered to your inbox.


Mark Your Calendar

In the News

In Like a Lion

While most K-12 school systems are still preparing to welcome students and teachers back for the kick-off of the fall semester, threat actors aren’t waiting. School systems in California, DC, Georgia, and Tennessee, for instance, have all reported recent incidents - to say nothing of the wave after wave of email-based phishing that school communities are currentlybeingbatteredby. It is no wonder that the IRS is warning of back-to-school scams.

Schools Should Plan Now for Significant Security Changes Coming to Microsoft, Google

Microsoft is retiring SMS and voice-based multi-factor authentication (MFA) in Microsoft Entra ID and replacing it with passkeys as the default. Starting September 1, 2026, users will be prompted to register a passkey during their next MFA challenge. By October 30, 2026, IT administrators will be forced to configure a supported telecom provider through the Microsoft Security Store if they can’t get off telephony-based MFA. On February 1, 2027, Microsoft-provided SMS and voice authentication will be officially dead. “There is no opt out from this February 1 behavior,” Microsoft says, “It will be enforced for all tenants.” For its part, Google is deprecating the Google SCEP (Simple Certificate Enrollment Protocol) API at the end of 2026. After that date, Chromebooks and other ChromeOS devices will no longer be able to enroll in school-managed enterprises if they have not migrated to another solution. Plan now to avoid (potentially significant) disruptions.

K12 SIX Joins National Council of ISACs

The National Council of ISACs (NCI) has welcomed K12 SIX to its membership, formally connecting the nation's K-12 education community to the broader network of critical infrastructure threat intelligence sharing. Formed in 2003, the NCI is a cross-sector partnership of Information Sharing and Analysis Centers (ISACs) that provides a forum for sharing all-hazards threats and mitigation strategies among the ISACs, as well as with government partners. "NCI is excited to welcome its latest member, K12 SIX," said Denise Anderson, Chair of NCI. "Schools face increasingly complex cyber threats in today’s environment. The involvement of K12 SIX in NCI extends vital threat intelligence and mitigation strategies to the K-12 community while strengthening cross-sector collaboration across all of the nation's critical infrastructure sectors." To learn more, read the accompanying press release.

Practical Vendor Risk Management for Districts and Schools

While some sectors and organizations outside of K-12 education have a deep history implementing third-party/vendor risk management programs, practical guidance for school and district technology leaders about how to implement and operate a K-12 vendor risk management program has been lacking. K12 SIX is pleased to help address that guidance gap. Developed by practicing K-12 cybersecurity practitioners serving on the K12 SIX Technical Working Group, Practical Vendor Risk Management for Districts and Schools can be accessed here. Other K-12 cybersecurity guidance, including our popular K12 SIX Essential Cybersecurity Protections, can always be found here.

Members Get More

The K12 Security Information eXchange (K12 SIX) operates as the independent, non-profit information sharing and analysis center (ISAC) exclusively for the K-12 education sector. Founded in 2020, organizations eligible for membership include school districts, charter schools and charter management organizations, private/independent schools, regional education agencies, and state education agencies. K12 SIX members get more.

Next
Next

Cybersecurity for Schools: The Summer Break Action Plan