Skip to main content
  1. Home
  2. Computing
  3. News

Canvas hack hit students at the worst time, and it’s a wake up call for schools everywhere

Canvas hack exposed the weak links in digital classrooms

Add as a preferred source on Google
Logo
Instructure

A cyberattack on Canvas could not have come at a worse time. The learning platform, used by schools and universities for assignments, exams, grades, lecture materials, and class communication, went down during finals week, leaving students and instructors scrambling for alternatives.

The incident has been linked to ShinyHunters, a hacking group known for data theft and extortion. According to BleepingComputer, Canvas login portals at hundreds of institutions were defaced with a ransom-style message warning that stolen student data would be leaked unless the attackers were contacted. The group claimed to have obtained data tied to millions of students, teachers, and staff across thousands of schools.

What went wrong inside Canvas?

Instructure, the company behind Canvas, said hackers exploited an issue related to its Free-for-Teacher accounts, forcing it to temporarily shut down the platform to investigate the matter. This outage caused major chaos during the ongoing finals season as students and teachers were suddenly locked out of a platform.

During the initial outage, the Canvas login screen reportedly displayed a message from ShinyHunters claiming it had breached Instructure “again” and warning schools to make contact before a May 12, 2026, deadline to prevent stolen data from being published. The message also included a list of affected schools, making it clear the attack was part of an extortion attempt.

Why did this hit students so hard?

This hack resulted in some institutions postponing exams, while others asked faculty to be flexible with deadlines and course requirements. For students already in the middle of finals, the outage created more stress around study materials, submissions, and exam schedules.

Recommended Videos

While Instructure has claimed that passwords or financial details were not compromised in this attack, the hackers did get access to millions of user names, email addresses, student IDs, and internal messages. This information could easily be used for phishing attacks that mention real classes, schools, or instructors.

Haven’t we seen ShinyHunters before?

ShinyHunters has been connected to several major breaches in the past, including incidents involving Ticketmaster and Rockstar. Even Instructure has had previous run-ins with the hacker group. In September 2025, ShinyHunters targeted Instructure’s Salesforce environment through social engineering to access business systems, but Instructure said no Canvas product data was accessed and that the exposed information was mainly public business contact details.

What now?

Canvas coming back online does not end the problem. Hackers are still holding data from millions of users for ransom, which means the risk remains. That said, ShinyHunters has reportedly removed Instructure from its “Pay or Leak” portal, suggesting negotiations may be underway.

The attack should be a wake-up call for every school that relies on a few digital platforms to run classes, exams, and communication. These tools are now essential to how schools operate, which means they need stronger cybersecurity to protect student data and backup plans in case another outage or attack happens.

Sudhanshu Kumar Mangalam
I’ve got about 4 years of experience, mostly covering gaming, PC hardware, and smartphones. In my free time, I like…
Fake DDR5 RAM sticks are now using plastic chips to fool buyers
PC hardware market continues to get messier.
RAM memory chips

If DDR5 prices were not painful enough already, counterfeit RAM is now entering the chat. Some fake memory sticks reportedly look convincing enough to fool buyers, right down to plastic chunks disguised as DRAM chips.

Fake DDR5 RAM sticks are now getting disturbingly convincing

Read more
macOS 27 to refine the Liquid Glass design approach, but nothing too dramatic
The futuristic UI is staying, just with fewer quirks.
Liquid Glass on macOS Tahoe 26 Dark Mode

Whether you like it or not, it's "clear" that Apple is not giving up on Liquid Glass. It is just trying to make it a little less… blindingly futuristic on Macs.

After the mixed reception to macOS Tahoe’s translucent interface, Apple is reportedly preparing a softer, cleaner version of the design language for macOS 27. But if anyone was expecting a dramatic rollback, that is apparently not happening.

Read more
Asus reveals ROG Strix XG129C, a tiny secondary monitor chasing Elgato’s gamer lunch
The secondary display category has been waiting for a product that combines a proper screen, real color accuracy, and gaming ecosystem integration in one tidy package.
Strix XG129C secondary display.

If you’ve ever wished your work desk had a dedicated screen for reviewing your system’s performance, chat windows, or streaming controls, so that you don’t have to disturb your main monitor, Asus has heard you. 

The ROG Strix XG129C is a 12.3-inch secondary display with a touchscreen, designed to sit beneath your primary monitor and handle everything that could be a distraction on your main screen, and it costs $199. 

Read more