The Canvas education platform was the target of a major cyberattack that disrupted the operations of thousands of schools and universities in the United States . The ShinyHunters cybercriminal group managed to breach the platform and demand a ransom, threatening to leak data from 275 million students and faculty at nearly 9,000 educational institutions .
See also: Targeted cyberattack on Northern Ireland schools

Canvas ' parent company , Instructure , was forced to shut down the platform after attacks that corrupted the login page with ransom messages. Canvas is used by thousands of schools, universities, and businesses to manage courses, assignments, and communicate with students. The outage comes at a critical time, as many institutions are in the midst of final exams.
Instructure had acknowledged the data breach earlier this week, after the ShinyHunters group claimed responsibility and said it would leak data of tens of millions of students and faculty unless a ransom was paid. The original payment deadline was set for May 6 , but was later pushed back to May 12 .
In a statement on May 6, Instructure said its investigation showed that the stolen data included “some personally identifiable information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages between users.” The company said it found no evidence that the compromised data included more sensitive information, such as passwords, dates of birth, government identification numbers, or financial information.
See also: Inside a breach: What happens in the first 24 hours after a cyberattack

Canvas attack causes chaos in education
Although the May 6th update stated that Canvas was fully operational and Instructure was not seeing any ongoing unauthorized activity on their platform, by midnight on Thursday, May 7th , students and faculty at dozens of schools and universities flooded social media with comments that a ransom message from ShinyHunters had replaced the usual Canvas login page .
Instructure responded by taking Canvas offline and replacing the portal with the message “Canvas is currently undergoing scheduled maintenance. Please check back soon.” The move drew criticism from security experts, with Dipan Mann, founder and CEO of security firm Cloudskope, criticizing Instructure for referring to the outage as “scheduled maintenance” on its status page.
The extortion message that greeted countless Canvas advised affected schools to negotiate their own ransom payments to prevent their data from being published — regardless of whether Instructure decides to pay. “ShinyHunters have breached Instructure (again),” the extortion message stated. “Instead of contacting us to resolve this, they ignored us and made some ‘security fixes.'”
According to a source close to the investigation who was not authorized to speak to the press, several universities have already approached the cybercriminal group about the payment. The same source also noted that the ShinyHunters no longer lists Instructure among the current blackmail victims and that the data samples stolen from Canvas have also been removed.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web

This is not the first time ShinyHunters has targeted Instructure . In September 2025 , the same group conducted a social engineering attack on Instructure ’s Salesforce environment , making this May 2026 incident the second breach of the company by the same group in about 8 months . Data extortion groups like ShinyHunters typically remove victims from their leak sites only after receiving a ransom payment or after the victim agrees to negotiate.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
