Canvas Breach and Ransom Demand
Coverage from Inside Higher Ed, The Record, and others

Instructure's Canvas learning platform was hit by a breach and extortion campaign attributed to ShinyHunters, leading to temporary outages and threats to leak student and staff data.
The incident affected schools and universities that rely on Canvas for coursework, deadlines, and exams, making it both an operational disruption and a privacy risk. Instructure later said it reached an agreement with the attackers and received confirmation of data destruction, but the full scope of impacted data remains unclear.
The update adds limited clarification that passwords and financial data were not indicated as exposed, while emphasizing unresolved institutional notification obligations. The core breach, extortion, disruption, and data-destruction account remains unchanged.
