The Canvas learning management system, operated by the Utah-based company Instructure, has been hit by a significant security breach and subsequent outage. The incident, which began in early May 2026, is considered one of the largest educational security breaches on record, affecting approximately 8,809 universities, educational ministries, and other institutions globally.
Instructure previously announced it was investigating an incident involving stolen user data, including names, email addresses, student ID numbers, and messages. While the company initially stated that passwords, financial information, and government identifiers were not involved, a second wave of disruption occurred on May 7 when the login page was replaced with a ransom message.
The criminal hacking group ShinyHunters has claimed responsibility for the attack. The group issued a ransom note threatening to release 3.65 terabytes of data, comprising roughly 275 million records, including private communications between students and teachers, unless payment is made by the end of May 12, 2026.
Following the group's claim that Instructure attempted to implement security patches instead of negotiating, an outage occurred on May 7. During this time, users were met with either a ransom note or a message stating the software was down for maintenance. Instructure later confirmed that the exploit was linked to an issue involving its Free-For-Teacher accounts.
The impact has been felt across several continents. In the United States, institutions such as Arizona State University, Sacramento State, and the University of California system reported disruptions or took preventative measures to block access. In Australia, the Queensland Department of Education and various universities have disabled Canvas access, while the National Office of Cyber Security is coordinating a response.
The breach has caused widespread disruption during the end of the academic year for many institutions. In Canada, at least eight universities and colleges have been affected, and in the Netherlands, 44 educational institutions reported impacts. Some institutions, such as the University of British Columbia, have already begun migrating courses to alternative platforms like Moodle.
As of May 8, Instructure reported that access to its website had been restored for most users, though some institutions remained offline for several days. The full scope of the data theft has not been independently verified.