ListedTech
  • Data Portals
    • Portal for Industry
    • Portal for Institutions
    • Webinars
  • Product Categories & Reports
  • Resources
    • Blog
    • Podcast
    • Documentation
    • Webinars
  • About Us
    • Our Story
    • Data Overview
    • Traditional IT Research vs. ListEdTech
    • In the Media
    • Contact Us

Search the website...

Go to Portal
Posted on July 28, 2019 | by Justin Ménard

Hackers Target Banner ERP Vulnerability

Customer Relationship Management Higher Ed Student Information Systems
Active Banner - LisTedTECH

Update:
Ellucian recently issued a joint statement with the Department of Education addressing the security alert. “Some of the issues mentioned in the alert may be unrelated to the vulnerability (Vulnerability) for which Ellucian released a patch on May 14, 2019. The Department and Ellucian have no reason to suspect that a breach has occurred as a result of this vulnerability.”

Original post
Ellucian’s Banner is one of the most popular ERP software used in HigherEd. Based on our data, it has a market share that is just under 25% in North America. For this reason, the news that came out this week about hackers who have been targeting a vulnerability in one of its modules is alarming.

Inside HigherEd describes the vulnerability: “Depending on the administrative privileges of the user, and the way data are organized by individual institutions, attackers could use this access to move laterally through administrative systems and access sensitive information.” “Ellucian fixed the vulnerability in May, and a public disclosure was published, by both the researcher and NIST” (ZDNet)

“According to Ellucian’s website, more than 1,400 institutions worldwide use Banner to manage student grades, staff payrolls, course schedules, admissions and student financial aid, among other tasks. Web Tailor and Enterprise Identity Services can be used by system administrators to get access to sensitive data protected under the Family Educational Rights and Privacy Act.” (Inside HigherEd) Authorities have mentioned that only older versions of Banner will be impacted. Institutions that have upgraded to Banner 9 should not be worried by potential attacks. As of July 20, 2019, 62 US institutions have reported attacks because of this vulnerability. (Koddos.net)

Although we don’t have all 1,400 institutions in our database (yet!), we do have 84% of them. Below is the global map of active implementations of Banner. As you can see, the vast majority of Banner users are in the US followed by Canada and the United Kingdom. They have an average enrollment of 8,856 students.

Post navigation

This Is What the K-12 SIS Market Looks Like
Historical SIS Market for HigherEd Institutions
  • Subscribe to Our Newsletter
  • CAPTCHA image

    * All fields are required.

  • Listen to Our Podcast


  • Recent Posts

    • Who Are HigherEd’s Tech Leaders? October 15, 2025
    • Anthology’s Chapter 11 Filing: Breaking Up to Refocus October 1, 2025
    • Rethinking Market Saturation in EdTech September 24, 2025
    • Thesis: From Unit4 Spin‑Off to SIS Specialist September 17, 2025
    • How Institutions Discover What Tech Their Peers Are Using September 3, 2025

Stay in the know…

Blog & News
Higher Ed Market Data

Who Are HigherEd’s Tech Leaders?

This year, I’ve been revisiting some of the classic business books: Blue Ocean Shift, Free, The Innovator’s Dilemma, Zero to One, and of course, Crossing the Chasm. That last one really got me thinking about early adopters. In tech markets, they’re the people (or in HigherEd, the institutions) who are comfortable taking risks, trying something new, and shaping the market ... Who Are HigherEd’s Tech Leaders?  Read More
Market Data Market Movements

Anthology’s Chapter 11 Filing: Breaking Up to Refocus

September 2025 marked a major turning point for Anthology, the owner of Blackboard and several other higher education technology platforms. The company filed for Chapter 11 bankruptcy in the U.S. after efforts to sell itself or parts of its business outside of court failed. The filing is not a liquidation. Instead, it is a structured reorganization designed to ... Anthology’s Chapter 11 Filing: Breaking Up to Refocus  Read More
ListEdTech Market Data

Rethinking Market Saturation in EdTech

Market saturation is a concept we often discuss at ListEdTech because it comes up frequently with our clients. Investors want to know if a market still has room to grow, while startups want to understand whether they are entering a space with opportunities or one that is already crowded. Last year, we explored saturation by ... Rethinking Market Saturation in EdTech  Read More
Footer Logo - LisTedTECH
  • Contact Us
  • Frequently Asked Questions
  • Privacy Policy
  • Terms of Use