About 9,000 schools and universities across the United States, Canada and Australia were affected this week when a coordinated cyberattack tied by security researchers to the hacking group ShinyHunters forced the Canvas learning-management system offline as students approached end-of-term exams. Instructure, Canvas' parent company, acknowledged a cybersecurity incident in a May 1 statement attributed to chief information security officer Steve Proud and said most users could access the service while some test environments remained in maintenance mode. The outage disrupted course access, assignment submission and exam scheduling, prompting some campuses to postpone or cancel finals and to advise users to log out. Researchers and the alleged attackers set a May 12 deadline for threatened disclosure.

A widespread outage of the Canvas platform this week left students and staff scrambled as the academic year closed at many institutions. Security researchers and screenshots shared with news outlets show the hacking group ShinyHunters claimed responsibility, posting a ransom-style message that said it had exfiltrated large volumes of data and demanded contact to "negotiate a settlement".

Scope and immediate impact

The disruption affected course pages, assignment uploads, grading tools and exam schedules, university IT officials said. Some campuses temporarily disabled Canvas while they investigated, and administrators told users to log out if they were still connected. The outage affected both public and private universities in the United States, including Penn State, Mississippi State, Idaho State, the University of Michigan, Harvard, the University of California Los Angeles and the University of Chicago. Canadian institutions naming operational impacts included the University of British Columbia and the University of Toronto. In Australia, the University of Sydney told students that Canvas was unavailable and advised against logging in.

Instructure acknowledged the incident on May 1 in a statement attributed to CISO Steve Proud. The company said it was investigating and later reported that service was available for most users while some test environments remained in maintenance mode. In an update on May 2, Instructure said its review had found identifying information such as names, email addresses and student ID numbers among affected records, but that it had "found no evidence that passwords, dates of birth, government identifiers, or financial information were involved," a statement attributed to Steve Proud.

Campus IT directors and security officials sent alerts warning of heightened phishing risk and asking staff and students to expect further notices from their own institutions. The director of information technology at the University of Iowa’s College of Public Health described the incident as "a national-level cyber-security incident".

Data claims, responses and regional detail

Security researchers say the group began posting threats the previous Sunday and set deadlines for disclosure.

Both researchers and the alleged attackers identified May 12 as a date for threatened disclosure, and they warned institutions that extortion discussions could be ongoing as investigations continued.

Reports differ on the volume and types of data involved. One regional report cited a hacker claim of 3.65 terabytes of data, including "billions" of private messages.

Other accounts described the trove as affecting "millions" of people or as comprising billions of messages without referencing the 3.65 terabyte figure. The 3.65 terabyte figure appears only in the regional report, while Instructure’s public statements describe identified records more narrowly.

Security observers compared the incident to earlier breaches of education vendors, noting a trend of attackers targeting third-party education platforms to harvest digitised student records that previously existed on paper. Criminal groups often threaten to leak such records to extract ransom payments, observers said.

Australian regional reporting provided local details. Victoria’s government schools, which use a different, locally hosted system called Compass, were not affected, according to those reports. Still, some private and metropolitan institutions in Victoria were assessing impact after receiving notifications from Canvas that some of their data was involved in the breach.

Australia’s National Cybersecurity Co-ordinator Michelle McGuinness advised affected families to ignore unsolicited contact and warned that criminals use breached personal information to trick victims into handing over further credentials or funds. Universities and colleges across the affected countries urged students and staff to be vigilant about phishing and to follow institutional guidance on password resets and account security.

Institutions and Instructure said investigations and containment actions were ongoing as they worked to restore full service and assess the scope of exposed data. Some universities postponed or cancelled finals, and others adjusted exam schedules as they sought alternative arrangements or time to validate systems.

Related Articles

Investigations are continuing ahead of a May 12 deadline for threatened disclosure, as institutions and Instructure work to restore full service and assess exposed records.

This article was created with AI assistance.