Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Canvas breach halts classes across U.S. schools and colleges

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-05-11 T 20:15:03 Z | [ 2 MIN READ ]
Canvas breach halts classes across U.S. schools and colleges
2 Min Read
Share

Canvas breach forces nationwide class shutdowns

Early Thursday morning, a data‑extortion operation hijacked the login portal of Instructure’s Canvas platform, leaving students and faculty at ↓ 9,000 schools unable to submit assignments or access grades. The ransom note, posted by the ShinyHunters group, warned that data belonging to ↓ 275 million users could be published unless a payment was made.

How the breach unfolded

Instructure initially reported a breach on May 6, claiming only names, email addresses and student IDs had been exposed. Later that day, users were greeted by a defaced login screen demanding cash, prompting the company to pull Canvas offline and replace it with a generic “scheduled maintenance” banner.

“We are working around the clock to restore service and will communicate directly with affected institutions,” Instructure said on its status page.

The group’s extortion message urged each school to negotiate its own payout, sidestepping any corporate response. Sources close to the investigation told Reuters that several universities have already opened negotiations.

Security analyst Dipan Mann of Cloudskope blasted Instructure for downplaying the incident as routine maintenance. He noted that this is at least the third Canvas intrusion by ShinyHunters in eight months, following a 2025 breach of University of Pennsylvania data that was later linked to the same platform.

ShinyHunters, a notorious extortion gang, typically gains entry via voice‑phishing attacks on single‑sign‑on services. Recent campaigns have hit ADT, Medtronic and Carnival, according to Bloomberg.

With final exams in progress, the outage threatens to disrupt grading cycles and could force institutions to adopt emergency assessment methods, echoing challenges first seen during the pandemic when many schools shifted to remote learning.

Instructure announced on May 8 that Canvas is back online, but the company has permanently disabled “Free‑for‑Teacher” accounts, the vector allegedly exploited in the attack. A formal notice was sent to affected organizations on May 6, and the firm warned against relying on unverified third‑party lists.


Words by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

Aug 11, 2026
Water System Attacks Surge Across U.S., Iran Suspected

Water System Attacks Surge Across U.S., Iran Suspected

Aug 11, 2026
Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Aug 11, 2026
GhostJacking Reveals Critical Gaps in AI Identity Governance

GhostJacking Reveals Critical Gaps in AI Identity Governance

Aug 11, 2026
Atlassian Rovo data breach exposes Jira and Confluence files to hackers

Atlassian Rovo data breach exposes Jira and Confluence files to...

Aug 09, 2026
Can Your Email Ever Be as Secure as Your Texts? The Case for End-to-End Encrypted Email

Can Your Email Ever Be as Secure as Your Texts?...

Aug 08, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.