Skip to content
MarketScale
‹ Back to IndustriesEducation Technology

Why Using Ethical Hackers Helps Protect Online Learning

About the Author: Ashish Gupta is the CEO of Bugcrowd. — In the wake of COVID-19, colleges and universities across the U.S. have embraced virtual and hybrid learning to combat the spread of the virus and protect students and staff. Recent research analyzed the reopening models of 3,000 higher-ed institutions and found that only 4 percent are allowing…

This story was produced through MarketScale. See how Education Technology teams put it to work with Executive Thought Leadership.

Share
Why Using Ethical Hackers Helps Protect Online Learning

Get featured

Want to get featured in MarketScale Education Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Education Technology coverage. No credit card, no demo required.

Start free

About the Author:

Ashish Gupta is the CEO of Bugcrowd.

In the wake of COVID-19, colleges and universities across the U.S. have embraced virtual and hybrid learning to combat the spread of the virus and protect students and staff.

Recent research analyzed the reopening models of 3,000 higher-ed institutions and found that only 4 percent are allowing in-person attendance, making learning management systems, or LMS solutions, critically important.

In short, LMS solutions are a comprehensive platform for students to see a list of their courses, interact with their professors, find assignments and link to applications, such as Zoom, to take part in the virtual classroom. However, many cybersecurity professionals, college students, and faculty are asking: are online LMS solutions safe?

Cybersecurity experts are seeing first-hand how LMS IT teams are working diligently to secure their platforms during these unbelievably challenging times.

The education industry has traditionally been a target for cybercrime. Since the advent of COVID-19 stay-at-home mandates, cybercriminals have ramped up their activity. Most recently, Heartland Community College in Illinois was forced to halt online operations, including classes, as they worked to contain a security breach just a few weeks into the fall semester.

Why LMS breaches can be devastating

Each time a student or faculty member logs onto an LMS solution, a wealth of sensitive information about the user is stored, including the student’s name, address, emergency contact, and other information. Any penetration or breach of a LMS solution could well result in personally identifiable information, or PII, being stolen and sold on the Dark Web for profit. If a bad actor successfully breaches a LMS system, students and faculty could be subject to identity fraud.

LMS solutions, like any software-based system, require continuous testing. These platforms are not free of vulnerabilities, and the recent rise in cybercrime underscores the need for LMS solutions to take a proactive approach to security.

Leveraging ethical hackers to protect LMS systems

The business world is undergoing changes of tectonic proportions that are threatening the future of digital business. Traditional cybersecurity tools, such as scanners, cannot always ascertain what human cybercriminals may decide to do. It often takes a human touch to compete against an army of adversaries, and bug bounty programs that use ethical hackers can provide LMS platforms with an army of their own.

Crowdsourced bug bounty programs are like neighborhood watch programs, but for the internet. These programs are powerful because no company, no matter how vigilant, can defend all its potential vulnerabilities. Even worse, most companies lack the highly specialized cybersecurity expertise required to research, prioritize, and remediate all their cybersecurity vulnerabilities. Crowdsourced cybersecurity gives companies priority access to a global marketplace of on-demand, highly specialized cybersecurity experts who protect companies – like LMS solutions – from constantly evolving adversaries and attack methodologies.

Ethical hackers James McLean and Michael Skelton, who work with LMS customers, provided some interesting insights into their work with the LMS platforms.

Skelton points out that anyone can be an “ethical hacker,” and many times, even the students themselves “…can be armed to be LMS warriors — offering a new level of security for LMS solutions.”

“With ethical hackers, LMS solutions now have an extra pair of eyes on the product that you didn’t have before,” he continued.

“[Hackers] can say, ‘OK, I found something’ and either exploit it against the school or take it to a bug bounty company and potentially receive a reward for it,” said McLean. “These incentives allow many young hackers to choose the right path.”

“We find the vulnerability, build a proof of concept and then report it via a bug bounty platform,” added McLean. “Schools and LMS organizations must be open to taking our feedback and be dedicated to remedying the issue.”

When Skelton and McLean worked on one large LMS solution a few years back, they found several vulnerabilities that could well circulate on today’s LMS platforms. One such vulnerability was called a Cross-site Scripting (XSS), an injection attack whereby the attacker aims to execute malicious scripts in a web browser by including malicious code in a legitimate web application.

Another form of malicious hacking that university LMS platforms have witnessed is crypto-jacking. Crypto-jacking is the unauthorized use of someone else’s computer to mine for cryptocurrency. Hackers do this by either getting the victim to click on a malicious link in an email that loads crypto mining code on the computer or infecting a website or online ads with JavaScript code that auto-executes once loaded in the victim’s browser.

Similar to this are ransomware attacks with LMS solutions as an origin. This issue became known in mid-September following a recent spike in hackers targeting universities with ransomware attacks. In these situations, malicious actors not only demanded a significant bitcoin ransom from victims of attacks, but they have also threatened to leak stolen personal data of students if they are not paid.

Protecting the future of online learning

Today, keeping LMS solutions safe is of utmost importance for the hundreds of millions of university students worldwide. Bug bounty programs provide a continuous method for testing and finding vulnerabilities and should be used along with other cybersecurity safeguards.

Given the extraordinary situation we find ourselves in today due to COVID-19, many LMS organizations are taking a proactive approach to strengthening their cybersecurity posture. As such, bug bounty programs are becoming the “new normal,” ensuring that human ingenuity can work alongside AI and other technological solutions to find potential vulnerabilities and exploits.

Your experts belong here

Every story in MarketScale Education Technology starts with a company putting its implementation leads, instructional designers, and district partners on the record. Buyers are already reading this topic. The only question is whose experts they find.

Procurement teams read long before they ever call, and your implementers get to answer their questions first.

Get your team featuredSee how it works15 minutes, straight to a calendar.

Follow Education Technology Insights

Get new expert content in your inbox.

Education Technology: are you visible to AI?

Before they reach out, Education Technology buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Education Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your implementation leads, instructional designers, and district partners into the articles, video, and social content Education Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Education Technology Insights

Schools are still catching up after Google opened Gemini to every student

Schools are still catching up after Google opened Gemini to every student

Google has made its Gemini chatbot available to all students, and Education Week reports schools were caught flat-footed, with open questions about age-appropriate use. Districts now have to decide which Gemini path they run and who supervises first use. The consequence lands on district technology directors and classroom teachers this fall.

  • 01Gemini reaches a school two ways: the free app (data protection for users 13 and older) and Gemini for Google Workspace inside Gmail, Docs and Slides, with Gemini Advanced for users over 18. A district policy has to cover both.
  • 02Guided Learning, the step-by-step mode inside Gemini, is the feature that bears most directly on the cheating-versus-learning question, and Fast Company noted it is similar to the Study mode OpenAI had announced in ChatGPT the week before.
  • 03The sharper question for a district tech lead is no longer whether students can reach a chatbot; it is which mode they land in and who is standing behind them the first time.

Sep 17, 2026

OpenAI says GPT-6 Astra is the first model to hit its 'Critical' cyber threshold

OpenAI says GPT-6 Astra is the first model to hit its 'Critical' cyber threshold

OpenAI has unveiled GPT-6 Astra and says it is the first model to reach the "Critical" cybersecurity tier of its Preparedness Framework, Campus Technology reported Sept. 10. The label is the vendor's own. Campus and district IT leaders now weigh it alongside Microsoft's legally enforceable AI data protections, open to all districts Nov. 1.

  • 01A frontier vendor is now publishing its own capability tier alongside a broadly deployed release, which gives procurement a sharper question to ask every AI supplier: which tier, and what mitigations come with it.
  • 02Microsoft's legally enforceable student and teacher data protections open to every U.S. district on Nov. 1, a concrete reference point for anyone negotiating AI contract terms with other vendors this fall.
  • 03OpenAI's Navier-Stokes claim and Anthropic's formal-proof work are, as reported, vendor claims; independent verification is the signal that would turn either into a result.

Sep 16, 2026

Morgan State won Maryland's first public AI degree in months by building it first

Morgan State won Maryland's first public AI degree in months by building it first

Morgan State University launched Maryland's first public AI bachelor's degree by converting an existing cloud computing program into a full AI curriculum, completing the regulatory approval in months rather than years. The program prioritizes foundational computer science alongside AI-specific coursework and hands-on reinforcement learning projects, positioning graduates to design and extend AI models rather than simply use them.

  • 01Morgan State built 18 AI courses and embedded 8 completed projects into the curriculum before formally proposing the degree, enabling regulatory approval in days once evidence of the running program was presented.
  • 02Every student learns classical programming and data structures first, then progresses through problem-based courses scaled by difficulty level, culminating in a capstone with no lectures where the instructor acts as support.
  • 03The program emphasizes reasoning grounded in reinforcement learning and the Markov decision process rather than statistical analysis alone, preparing students to extend AI models and control technology instead of being directed by it.

Sep 16, 2026

Explore More Education Technology Insights

Read more expert perspectives from across Education Technology.

Browse Education Technology Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Education Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512