Canvas Breach Disrupts California Colleges
Coverage from The Hornet, Daily Breeze, and others

A cybersecurity incident at Instructure disrupted Canvas access across colleges and universities, including all 23 California State University campuses, during a critical academic period.
Instructure said potentially exposed information included names, email addresses, student and faculty ID numbers, rosters, and user messages, while reporting no evidence that passwords, financial data, birth dates, or government identifiers were involved at the time. The incident also generated extortion claims attributed to ShinyHunters, prompting institutions to restrict access, warn users about phishing, and develop contingency plans for online instruction.
The update adds a clearer timeline and sharper characterization of the incident: Instructure now pins it to May 1, confirms the affected data categories more precisely, and frames the situation as an ongoing extortion case tied to ShinyHunters. It also shows the operational response broadening from immediate access recovery to longer-term contingency planning for future Canvas outages.
