A cyberattack against Instructure’s Canvas platform disrupted universities and K-12 schools across the United States, with major California institutions including UC, CSU, USC, Stanford, and community colleges reporting outages and academic disruption during finals. Ransom notes attributed to ShinyHunters appeared on some school homepages, and the FBI said it was assisting victims in multiple states while warning students and staff not to engage with extortionists or scammers. Schools extended deadlines, changed exam schedules, and shifted to alternate communication channels as Canvas services were restored.
Instructure said an unauthorized actor exploited a vulnerability tied to support tickets in its Free for Teacher environment, which the company temporarily disabled while conducting a broader security review. The company later confirmed unauthorized access to part of its environment and said exposed data could include usernames, email addresses, course names, enrollment information, student ID numbers, and user messages, while passwords, dates of birth, government identifiers, financial data, course content, submissions, and credentials were not compromised. The incident renewed scrutiny of centralized education technology providers after earlier education-sector extortion cases, including reports that PowerSchool paid a ransom following claims that data on 62 million students had been stolen.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
In its May 20, 2026 update, Instructure said the attacker exploited a vulnerability related to support tickets in its Free for Teacher environment and that the service had been temporarily disabled pending review.
On May 20, 2026, Instructure disclosed unauthorized access to part of its environment, listed exposed fields including usernames, email addresses, course names, enrollment information, and messages, and said credentials and course content were not compromised.
On 2026-05-11, Instructure said it had reached an agreement intended to prevent publication of data stolen in the Canvas attack and had received evidence that the data was deleted. The reference notes that such assurances from threat actors should not be fully trusted.
By 2026-05-10, reporting said ShinyHunters claimed the University of California was among the organizations affected in the Canvas-related breach, identifying a specific victim tied to the broader Instructure incident.
As the Canvas incident unfolded in early May 2026, the FBI said it was assisting affected organizations in multiple states and warned victims not to engage with extortionists or scammers.
By May 8, 2026, Instructure said it had restored broader Canvas access after temporarily shutting down Free-For-Teacher accounts tied to the exploited issue.
During the May 7, 2026 disruption, the extortion group ShinyHunters claimed it had breached Instructure and accessed data from millions of students, teachers, and staff.
On May 7, 2026, a cyberattack disrupted Instructure's Canvas platform during finals period, with ransom notes appearing on multiple school homepages and causing universities and K-12 schools to extend deadlines and use alternate channels.
On or around May 1, 2026, Instructure experienced a cybersecurity incident affecting Canvas in which data such as usernames, email addresses, student ID numbers, and communications from some institutions appeared to have been exposed.
By January 22, 2025, a threat actor claimed to have stolen data belonging to 62 million students from PowerSchool, escalating the apparent scale of the incident.
Reporting on January 9, 2025 said PowerSchool paid a ransom in an effort to prevent leaked publication of stolen student data following a breach affecting school records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcesophos.com
Open sourceinstructure.com
Open sourcetechjacksolutions.com
Open sourceedition.cnn.com
Open sourcelatimes.com
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.