Skip to main content
See every side of every news story

Canvas Restores Service After Cyber Breach Disrupts Finals Week

United States

Brandon Bell/Getty Images/Getty

Brandon Bell/Getty Images/Getty

What Happened

Instructure restored Canvas for most users after taking the platform into maintenance during a ShinyHunters cyberattack and deploying patches, revoking credentials and rotating keys. The company and outside forensics say the attack is contained, but investigations continue into stolen user data including names, emails, student IDs and messages.

What Happened

Instructure restored Canvas for most users after taking the platform into maintenance during a ShinyHunters cyberattack and deploying patches, revoking credentials and rotating keys. The company and outside forensics say the attack is contained, but investigations continue into stolen user data including names, emails, student IDs and messages.

Where Sources Agree

  • arrows_inputShinyHunters Ransom Deadline: Most accounts emphasize ShinyHunters claimed responsibility for the Canvas cyberattack and issued a ransom demand, setting a May 12, 2026, deadline for schools to negotiate a settlement and prevent a data leak, according to their claims and multiple reports.
  • arrows_inputAcademic Deadlines Extended: Outlets generally confirm universities postponed final exams and extended academic deadlines, with students losing access to Canvas during the cyberattack, according to student newspapers across the country and university statements.

Where Sources Disagree

  • arrows_outputBreach Containment Disputed: Instructure claimed the cybersecurity incident was contained by May 2 and Canvas was fully operational by May 6. However, ShinyHunters and security analysts asserted a re-compromise on May 7, citing defaced login pages and subsequent changes to Canvas pages on May 8.
  • arrows_outputRansom Negotiation Status: Instructure has not confirmed any ransom negotiations or payments to the ShinyHunters hacking group; however, some reports indicate that schools directly contacted the hackers, and the removal of Instructure from leak sites suggests negotiations or payment may have occurred.
  • arrows_outputData Compromise Scope: Instructure stated only names, emails, student IDs, and messages were compromised, with no passwords or financial info, while ShinyHunters claimed billions of private messages and phone numbers were stolen.

Timeline

May 12, 2026

Extortion deadline remains: The threat actor set an extortion deadline of May 12, 2026, warning it would leak data if not contacted, while Instructure continued an active investigation with outside forensics experts and shared updates with customers.

May 8, 2026

Service restored; company response: By May 8 Instructure reported Canvas was available for most users and later said the platform was fully back online while confirming data had been stolen; the company said there was no evidence passwords, dates of birth, government identifiers, or financial information were accessed and deployed patches, rotated keys, and increased monitoring.

May 7, 2026

Outages peak during finals week: Canvas outages spread widely on May 7, locking students and faculty out of coursework and exams during finals week and affecting thousands of institutions, with hundreds of login portals reportedly defaced.

Summaries by Ground AI

View All Sources

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal