ListedTech
  • Data Portals
    • Portal for Industry
    • Portal for Institutions
    • Webinars
  • Product Categories & Reports
  • Resources
    • Blog
    • Podcast
    • Documentation
    • Webinars
  • About Us
    • Our Story
    • Data Overview
    • Traditional IT Research vs. ListEdTech
    • In the Media
    • Contact Us

Search the website...

Go to Portal
Posted on July 28, 2019 | by Justin Ménard

Hackers Target Banner ERP Vulnerability

Customer Relationship Management Higher Ed Student Information Systems
Active Banner - LisTedTECH

Update:
Ellucian recently issued a joint statement with the Department of Education addressing the security alert. “Some of the issues mentioned in the alert may be unrelated to the vulnerability (Vulnerability) for which Ellucian released a patch on May 14, 2019. The Department and Ellucian have no reason to suspect that a breach has occurred as a result of this vulnerability.”

Original post
Ellucian’s Banner is one of the most popular ERP software used in HigherEd. Based on our data, it has a market share that is just under 25% in North America. For this reason, the news that came out this week about hackers who have been targeting a vulnerability in one of its modules is alarming.

Inside HigherEd describes the vulnerability: “Depending on the administrative privileges of the user, and the way data are organized by individual institutions, attackers could use this access to move laterally through administrative systems and access sensitive information.” “Ellucian fixed the vulnerability in May, and a public disclosure was published, by both the researcher and NIST” (ZDNet)

“According to Ellucian’s website, more than 1,400 institutions worldwide use Banner to manage student grades, staff payrolls, course schedules, admissions and student financial aid, among other tasks. Web Tailor and Enterprise Identity Services can be used by system administrators to get access to sensitive data protected under the Family Educational Rights and Privacy Act.” (Inside HigherEd) Authorities have mentioned that only older versions of Banner will be impacted. Institutions that have upgraded to Banner 9 should not be worried by potential attacks. As of July 20, 2019, 62 US institutions have reported attacks because of this vulnerability. (Koddos.net)

Although we don’t have all 1,400 institutions in our database (yet!), we do have 84% of them. Below is the global map of active implementations of Banner. As you can see, the vast majority of Banner users are in the US followed by Canada and the United Kingdom. They have an average enrollment of 8,856 students.

Post navigation

This Is What the K-12 SIS Market Looks Like
Historical SIS Market for HigherEd Institutions
  • Subscribe to Our Newsletter
  • CAPTCHA image

    * All fields are required.

  • Listen to Our Podcast


  • Recent Posts

    • K-12 LMS Market Update & Insights: May 2026 May 20, 2026
    • EdTech Incidents Come and Go. Responses Last Longer. May 13, 2026
    • Canvas Reimagined: Tiered Platforms and AI Strategy April 29, 2026
    • The Future of HigherEd: Moving Beyond the Legacy ERP to Agentic Innovation April 22, 2026
    • AACRAO’s Evolving Landscape: Signals from the Exhibit Floor April 15, 2026

Stay in the know…

Blog & News
ListEdTech

K-12 LMS Market Update & Insights: May 2026

Over the past decade, the K-12 Learning Management System (LMS) market has undergone significant consolidation and shifting user preferences. Our historical data shows that while some legacy systems have steadily declined, a clear trio of dominant platforms has emerged to capture the vast majority of the K-12 market share. Using the latest data from the ... K-12 LMS Market Update & Insights: May 2026  Read More
Cybersecurity

EdTech Incidents Come and Go. Responses Last Longer.

Last week, much of the conversation in EdTech focused on the recent Instructure / Canvas security incident. I received several emails asking whether we would cover the event in our weekly post. Since we had just finished our company summit and I’ve been traveling with my family, I was honestly happy to let others take ... EdTech Incidents Come and Go. Responses Last Longer.  Read More
Learning Management Systems

Canvas Reimagined: Tiered Platforms and AI Strategy

A few weeks ago, I sat down for a demo with Instructure to get a look at their new product tiering and AI platform strategy for Canvas. It wasn’t just a product update; it felt like a snapshot of where the entire EdTech market is headed. We’re seeing a massive shift in how software is delivered to schools ... Canvas Reimagined: Tiered Platforms and AI Strategy  Read More
Footer Logo - LisTedTECH
  • Contact Us
  • Frequently Asked Questions
  • Privacy Policy
  • Terms of Use
Hey AI, learn about this page