This is a concluded retrospective. ShinyHunters breached Instructure via the Free-For-Teacher (FFT) account program, first intruding April 25, 2026. Instructure detected the intrusion April 29 (a 4-day dwell), disclosed it publicly May 1, and declared the incident 'contained' on May 2. That containment claim was invalidated on May 7, when ShinyHunters defaced roughly 330 Canvas login portals via HTML injection and reset its leak deadline to May 12; Instructure took Canvas offline globally and then restored it late on May 7. On May 11-12 Instructure announced it had reached an agreement with the threat actor and 'received digital confirmation of data destruction (shred logs),' stating that no customers would be extorted as a result of the incident. The ransom amount was never officially disclosed (some outlets cited an unconfirmed ~$10 million figure); ShinyHunters delisted Instructure from its leak site, and the May 12 deadline passed with no public data dump. ShinyHunters had claimed ~3.65 TB covering ~275 million students, teachers and staff across roughly 8,800-9,000 institutions worldwide; Instructure never corroborated those totals and characterized the exposed data as names, email addresses, student ID numbers and Canvas Inbox messages, with no evidence that passwords, government IDs or financial data were taken. CEO Steve Daly published the first CEO-named apology on May 11. House Homeland Security Chair Andrew Garbarino opened a Congressional inquiry the same day, demanding a briefing by May 21. Federal Student Aid issued a Title IV technology-security alert on May 12. By late May, plaintiffs had filed well over a dozen federal class actions (early reporting counted at least seven in D. Utah plus one in S.D.N.Y. naming owner KKR; later reporting cited roughly 18 suits), with no JPML consolidation order at the time of this writing. Security experts caution that shred-log 'destruction' cannot be externally verified and that the PowerSchool precedent shows paying does not guarantee against later district-level re-extortion.
Last updated
June 2026
Incident Retrospective
Canvas / Instructure Cybersecurity Incident
A finalized retrospective on the April-May 2026 ShinyHunters breach of Instructure (Canvas LMS): primary sources, a closed vendor timeline, the settlement and Congressional aftermath, and an archived tracker of how US colleges and universities responded during finals week.
How it concluded · key developments
- →**Settlement, Instructure announces agreement with ShinyHunters May 11-12**, one day before the threat actor's May 12 leak deadline. Vendor received 'digital confirmation of data destruction (shred logs)' and states 'no Instructure customers will be extorted as a result of this incident.' Ransom amount undisclosed. ShinyHunters delisted Instructure from its dark-web leak site.
- →**CEO Steve Daly publishes apology blog post May 11**, first CEO-named statement of record. 'I'll start where I should: with an apology... You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that.' Through May 8 evening, all corporate communication had been from CISO Steve Proud or unnamed spokespeople.
- →**House Homeland Security opens inquiry May 11**, Chair Andrew Garbarino sends letter to CEO Daly demanding briefing by May 21. First Congressional action of record. Senate HELP, Commerce, HSGAC, Intel; House E&C, Ed & Workforce; Markey-Cassidy COPPA 2.0; all state AGs remain silent.
- →**FBI Facebook advisory May 8**, first US federal public communication on the breach. 'Threat actors often exaggerate or fabricate their access.' Signals federal skepticism toward the 275M-record claim and discourages individual-institution ransom payment.
- →**Australia's OAIC publishes regulator advisory**, first international regulator public statement; advises affected users to escalate to OAIC after 30 days. UK ICO / Dutch AP / Swedish IMY / Danish Datatilsynet / Finnish DPA / Canadian OPC all remain silent despite receiving GDPR-equivalent notifications.
- →**CrowdStrike is the forensic IR partner (not Mandiant)**, May 8 CrowdStrike readout: 'no evidence that the threat actor had system-level access, installed malware nor obtained login credentials, nor that any additional data was extracted during the renewed activity on May 7.' Mandiant's CTO Carmakal provided public commentary only.
- →**Free-For-Teacher accounts confirmed as initial-access vector** (Bitdefender Advisory), April 25 intrusion, April 29 detection (4-day dwell). FFT accounts ran on the same backend as paid institutional tenants but allowed account creation without institutional verification.
- →**Litigation aftermath:** by late May 2026, multiple federal class actions had been filed. Early reporting counted at least seven suits, six in the U.S. District Court for the District of Utah plus one in the S.D.N.Y. naming owner KKR; later reporting cited roughly 18. No JPML consolidation order had issued at the time of this archived writing.
- →**Archived institutional tracker:** the responses below span 50 US states + DC plus international institutions, including 11 HBCUs (Morgan State the only public statement), 8 tribal colleges, and 13 Dutch + 5 Swedish + 1 Danish + 1 Finnish universities tied to a cross-European DPA notification cascade, alongside 50+ K-12 districts. This list is a point-in-time snapshot captured during the incident and is preserved as a historical record.
What we know in 30 seconds
- **ShinyHunters has claimed responsibility**, the same financially motivated group behind concurrent breaches at Vimeo (119K user emails), Salesforce, AT&T, McGraw-Hill, and a prior September 2025 social-engineering breach of Instructure's Salesforce instance.
- **Instructure took Canvas offline globally on May 7** after defacement HTML appeared on roughly 330 login portals reading 'ShinyHunters has breached Instructure (again).' Canvas was restored late the same day. The outage landed in finals week: JMU delayed final exams to May 13, Liberty committed to deadline extensions, and Idaho State outright canceled afternoon finals.
- **Data exposed.** Instructure characterized the exposed data as names, email addresses, student ID numbers, and Canvas in-platform messages, and stated no evidence that passwords, dates of birth, government IDs, or financial information were involved.
- **Scale claims (never corroborated by Instructure):** ShinyHunters claimed 3.65 TB of data covering ~275 million students, teachers and staff across roughly 8,800-9,000 schools (BleepingComputer cited the actor's specific figure of 8,809 institutions). The actor named UC Berkeley (~600,000 records) and Penn (~306,000 affiliates) by name. The FBI publicly cautioned that 'threat actors often exaggerate or fabricate their access,' and Instructure never confirmed these totals.
- **The federal response arrived late.** For the first week after disclosure, no U.S. federal agency issued a Canvas-specific product: no CISA advisory, no FBI Flash, no PTAC FERPA bulletin, no FTC announcement under the April 22 2026 COPPA Rule. The first federal communications came May 8 (an FBI Facebook advisory) and May 12 (a Federal Student Aid Title IV technology-security alert); House Homeland Security opened a formal inquiry May 11.
- **Higher-ed sector consortia were largely silent through the first week.** REN-ISAC (higher-ed analog to MS-ISAC), EDUCAUSE, NACUA, AACRAO, NACUBO, AAU, APLU and AGB issued no public advisories in the days after disclosure. Member-only listserv traffic almost certainly existed, but little was canonical for non-members to cite. K12 SIX was the only sector ISAC voice on the public record (via a newsletter quoted by K-12 Dive).
- **Instructure is privately held, which shaped the litigation.** KKR + Dragoneer closed a $4.8 B take-private at $23.60/share on Nov 13 2024 (Form 15-12G filed Nov 25 2024), so no SEC Item 1.05 8-K applied and no securities class action was viable. The exposure instead landed in consumer class actions: by late May 2026 plaintiffs had filed multiple federal suits, several in D. Utah plus one in the S.D.N.Y. naming owner KKR (later reporting cited roughly 18), with no JPML consolidation order at the time of this writing.
- **Phishing risk was elevated during the outage.** TAMU-CC reported 'already receiving reports of fraudulent messages claiming to be able to get you back into Canvas,' and many institutions warned community members against clicking links in unsolicited messages and to navigate directly to their tenant URL instead.
Public-facing service disruptions affecting tools relying on API keys surfaced on **April 30, 2026** (Instructure's security team had detected the underlying intrusion on April 29; see the dwell-time fact below). Instructure then publicly disclosed the incident on **May 1, 2026** (~4:30 PM Mountain Time / 6:46 PM ET) via a customer letter from CISO Steve Proud describing 'a cybersecurity incident perpetrated by a criminal threat actor.'
↗ BleepingComputerInitial impact: Canvas Data 2 and Canvas Beta were taken offline for maintenance; tools relying on API keys experienced disruption. Canvas itself remained operational at most tenants until May 7.
↗ K-12 Dive**ShinyHunters has claimed responsibility.** The group listed Instructure on its leak site on May 3, 2026 and is the same actor behind a prior September 2025 social-engineering breach of Instructure's Salesforce instance, plus contemporaneous breaches at Vimeo, Salesforce, AT&T, Google, McGraw-Hill, and others.
↗ DataBreaches.net**Compromised data reportedly includes** names, email addresses, student ID numbers, and Canvas in-platform messages between users. Instructure has stated no evidence that passwords, dates of birth, government identifiers, or financial information were involved, though investigation remains ongoing.
↗ U-M Safe Computing**Threat-actor scale claims (unverified by Instructure):** ShinyHunters claims ~3.65 TB / ~275 million students-teachers-staff records / ~9,000 schools. BleepingComputer reported the actor's specific count as 8,809 schools.
↗ BleepingComputerInstructure's containment / response actions: revoking privileged credentials and access tokens, deploying security patches, rotating keys 'even though there is no evidence they were misused', increased monitoring, reissuing application keys with timestamp-based naming, and requiring customer re-authorization of integrations.
↗ K-12 Dive**On May 7, 2026 ~3:30 PM (afternoon CT)**, ShinyHunters defaced Canvas customer login portals via HTML injection, visible for ~30 minutes before takedown. Defacement carried text: 'ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some "security patches."' Demanded schools 'consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.' Set deadline: 'You have till the end of the day by 12 May 2026 before everything is leaked.'
↗ TechCrunch**Three institutional response postures have emerged**: (1) Canvas remained operational locally, UVA, Cornell, UT Austin, CU Boulder; (2) Canvas taken offline by Instructure in response to defacement, Penn State, Baylor, UMD, OSU, OU, UW–Madison, U Missouri, U Iowa, FIU, VCU, Princeton, JMU, Penn, Harvard, ASU, UMass; (3) Some have committed to academic accommodations, JMU delayed exams to May 13, Liberty promised class extensions, Princeton's Dean Gordin asked instructors to download Canvas gradebooks as precaution.
↗ JMU ComputingTwo **class-action investigations** have been announced: Chimicles Schwartz Kriner & Donaldson-Smith LLP and Shamis & Gentile P.A. ClassAction.org is soliciting plaintiffs.
↗ Chimicles Schwartz Kriner & Donaldson-Smith LLP**State-level confirmation:** The North Carolina Department of Public Instruction has confirmed receiving a breach notification from Instructure, implicating K-12 districts as well as higher ed.
↗ WRAL**No CISA advisory, no FBI alert, no Department of Education FERPA notice, no CVE** has been published as of this update. Federal involvement is limited to Instructure's own statement that it 'notified law enforcement.' MS-ISAC and REN-ISAC have not posted public advisories.
↗ SecurityWeek**Instructure is privately held.** KKR and Dragoneer Investment Group completed a $4.8 billion all-cash take-private acquisition at $23.60/share on November 13, 2024. INST common stock ceased trading on NYSE that day, and the company filed Form 15-12G to deregister securities. **Critical implication:** the SEC's 2023 Item 1.05 cyber-disclosure rule (4-business-day clock) does NOT apply, no INST share-price reaction is possible, and no Rule 10b-5 securities class action is viable. Financial-exposure analysis lives in the leveraged-loan secondary market, KKR Americas Fund XIII LP letters, and the consumer/regulatory tracks, not on EDGAR.
↗ KKR / Dragoneer closing announcement (Nov 13 2024)**LBO debt structure provides the post-private 'stock-price' equivalent for credit signal.** Pre-breach baseline: $1.685 B first-lien term loan (rated B-/B2), $365 M second-lien term loan (CCC/Caa2), $225 M revolver due 2029 with a springing first-lien leverage covenant. Corporate family rating B-/B3 stable. Watch secondary-market loan quotes and any S&P / Moody's CreditWatch Negative placement (plausible within 2-4 weeks given two confirmed breaches in <8 months).
↗ PitchBook — Instructure LBO loan package coverage**Federal-government vacuum at day 7+.** Through 168 hours since Instructure's May 1 disclosure, U.S. federal agencies have issued **zero** Canvas-specific products: no CISA advisory, no FBI Flash / IC3 alert, no PTAC FERPA bulletin, no FSA Dear Colleague Letter, no FTC announcement under the updated April 22 2026 COPPA Rule, no White House / ONCD statement, no congressional letter or hearing from any of the seven committees with jurisdiction (Senate HELP, HSGAC, Intel; House Ed & Workforce, Homeland Security, Energy & Commerce). The only federal 'action' is the pre-existing Title IV breach-intake clock that started May 1, a passive obligation on institutions. Most surprising silence: Senators Markey (D-MA) and Cassidy (R-LA), bipartisan COPPA 2.0 sponsors who routinely letter Meta/TikTok within 24-48 hours of children's-data incidents.
↗ CISA Cybersecurity Advisories index (verified silent through May 8, 2026)**Higher-ed sector consortium silence.** As of May 8, 2026, one full week into the incident, there is no public advisory from REN-ISAC (the higher-ed analog to MS-ISAC), EDUCAUSE (no Review article, no community blog), NACUA (no NACUANOTES on FERPA-notification timing), AACRAO, NACUBO, AAU, APLU, AGB, SHEEO, or ACE. Member-only listserv traffic almost certainly exists, but for non-member CIOs / Emergency Managers / general counsel, there is nothing canonical to cite. K12 SIX is the only sector ISAC voice on the public record, quoted via its weekly newsletter saying 'small and medium businesses, including the majority of U.S. K-12 education software businesses, are frequent cybersecurity targets.'
↗ K-12 Dive (quoting K12 SIX) + REN-ISAC News page (verified silent)**Defacement message verbatim** (May 7 mass-defacement HTML overlay on ~330 Canvas tenant login portals, also visible in the Canvas mobile app, observed by TechCrunch on three schools): "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'." The message directs schools to 'contact us privately at TOX to negotiate a settlement' before 'May 12 2026 before everything is leaked', superseding the earlier May 7-8 deadline.
↗ BleepingComputer + TechCrunch**International regulator silence.** No public statement as of May 8 from the UK ICO (UK GDPR Article 33 ICO-notification clock for U Manchester expired May 7), the Australian OAIC (Privacy Act 1988 NDB scheme; 2022 amendments raised maximum penalties to AU$50 M / 30% domestic turnover), the UK NCSC, Canadian OPC, or Australian Signals Directorate / ACSC. Eleven international universities have publicly confirmed impact (USYD, UniMelb, UTS, Auckland, AUT, VUW, Manchester, UBC, SFU, plus UofT confirmed via student paper after declining comment).
↗ UK ICO + OAIC sites (verified silent through May 8, 2026)**Anchor academic-sector quote**, In the absence of EDUCAUSE / REN-ISAC public commentary, Anton Dahbura, Executive Director of the Johns Hopkins University Information Security Institute, has emerged as the most-quoted higher-ed cybersecurity expert: 'The Canvas breach is a reminder that no platform is immune... Educational platforms are particularly rich targets given the concentration of personal, financial and international student data. Even organizations that do the right things can still be exposed through trusted vendors.'
↗ Inside Higher Ed quoting Anton Dahbura, JHUISI**Pre-disclosure timeline anomaly.** Fulton County Schools (GA), the largest district in Georgia (~90K students), posted its initial Canvas-incident security update on **April 27, 2026**, five days BEFORE Instructure's May 1 public disclosure. This implies Instructure quietly notified some K-12 customers under NDA roughly five days early. Combined with ShinyHunters' claimed **April 25** intrusion-onset date (per BleepingComputer reporting), the detection-to-disclosure-to-public timeline is: April 25 intrusion → April 27 confidential customer-notification window opens → April 30 status-page disruption to API tools → May 1 public disclosure → May 2 'contained' claim → May 7 mass-defacement falsifying the contained claim → May 12 leak deadline.
↗ Fox 5 Atlanta + BleepingComputer**Sept 2025 ↔ May 2026 lineage, definitive answer.** Same threat actor (ShinyHunters / Bling Libra / Mandiant UNC6040, now operating inside the August 2025 'Scattered LAPSUS$ Hunters' / 'Trinity of Chaos' alliance with Scattered Spider and LAPSUS$). Two distinct intrusions on different systems: Sept 2025 = vishing-driven social engineering of Instructure's Salesforce CRM (business contact info only; per Instructure no Canvas product data accessed). May 2026 = fresh intrusion into Canvas cloud production environment (names, emails, student IDs, Canvas Inbox messages, different data classes than Sept 2025 footprint). Multiple analysts have publicly questioned whether post-September remediation was sufficient given the same actor returned within 8 months.
↗ gblock — Instructure Canvas Breach: Second Hit in 8 Months**Market-share scale of systemic risk.** Per Spring 2025 Edutechnica data, Canvas controls **39% of N. American higher-ed institutions and ~50% of student enrollment**, more than D2L Brightspace (20%), Anthology Blackboard (12%), and Moodle (9%) combined. Every U.S. News 2026 top-10 national university (Princeton, MIT, Harvard, Stanford, Yale, etc.) runs on Canvas. K-12 footprint is similarly concentrated: ~8,000 institutions / ~200 million learners in 100+ countries per Instructure corporate site. The systemic-risk dimension is therefore even greater than first-look numbers (~28-30%) suggested in early coverage.
↗ Edutechnica — LMS Data Spring 2025**MFA partial-mitigation pattern (highest-signal forensic finding).** Charlottesville City Schools provided the most specific data-scope description in the entire dataset: 'Only parent accounts on Canvas, which contain very limited information, were affected. Student and staff accounts on Canvas do not appear to have been breached because they are protected by multifactor authorization.' This confirms multi-factor authentication worked as a partial mitigation: parent accounts (no MFA enforced) breached, staff/student accounts (MFA-protected) not. Implication for OIT readers: enforcing MFA on parent / observer / less-privileged Canvas roles is a high-yield retroactive control even after the May 12 leak deadline passes.
↗ 29News (CBS-19 Charlottesville)**Comparable-incident lessons-learned: paying ransom does not stop downstream extortion.** PowerSchool's December 2024 SIS breach is the most directly comparable incident: top-tier ed-tech vendor, ~62 M students + 9.5 M educators affected. PowerSchool **paid the ransom** and received a video purportedly showing data deletion, yet by May 2025 attackers were re-extorting individual school districts directly. Perpetrator Matthew D. Lane (19, Mass. college student) was caught, pled guilty June 2025, sentenced to 4 years federal prison. **Implication:** any Instructure ransom payment may not actually protect institutional data; OIT readers should plan for direct-extortion contact attempts even after the May 12 deadline, regardless of vendor payment.
↗ TechCrunch — PowerSchool breach analysis**Most-likely-to-act state AG: NC Jeff Jackson.** Jackson already has an open Civil Investigative Demand against PowerSchool (issued June 2025, still pending) over its 2024 breach affecting nearly 4 million NC students/teachers/parents. With Wake County Schools and Duke both confirmed-affected by Instructure, Jackson is procedurally positioned to expand the existing edtech-vendor probe to Instructure under the same legal theory. Jackson on PowerSchool: 'I'm sending a Civil Investigative Demand to the company because I don't have answers to basic questions about what happened.' If a state AG breaks the silence first, NC is the most probable.
↗ NC Department of Justice**Texas AG Paxton precedent, the operative state-AG playbook.** In September 2025, Paxton sued PowerSchool over its 2024 breach, calling it a "catastrophic data breach that compromised the personal information of over 880,000 Texas school-aged children and teachers." The Paxton-PowerSchool litigation is the single most directly applicable precedent for state-AG action against an LMS/SIS vendor. As of May 8, 2026 Paxton has not announced an Instructure action, but Austin ISD's BLEND, HISD, Katy, Conroe, Pearland, Lamar are all confirmed-affected, and the legal theory is portable.
↗ Texas AG press release (Sept 2025 PowerSchool suit)**Utah AG home-state silence, most material federal-level gap.** Instructure is HQ'd in Salt Lake City. Home-state AGs almost always either issue a 'we are monitoring' confidence statement defending the local employer or file first to claim jurisdictional priority. Neither has occurred from Utah AG Derek Brown (in office since January 2025) as of May 8, 2026. The home-state silence is the single most material gap-fill finding in the senator/AG watch.
↗ Utah AG press releases (verified silent through May 8, 2026)**Senate Commerce Chair Cruz silence, only person who can force testimony.** As Chairman of Senate Commerce in the 119th Congress, Senator Ted Cruz (R-TX) is the sole convening authority who can put Instructure CEO Steve Daly and CISO Steve Proud under oath. Cruz has been actively scheduling executive sessions through 2026 on AI / children's safety topics (S.4407 introduced April 28 on AI chatbot parental consent), but no Canvas hearing announcement by May 8. Most likely to break federal silence: Sen. Richard Blumenthal (D-CT, KOSA co-author, frequent breach-letter author), Sen. Ed Markey (D-MA, COPPA 2.0 sponsor, MA institutions affected), Sen. Elizabeth Warren (D-MA), or a bipartisan Markey-Cassidy-Blumenthal-Blackburn-Hawley letter timed to the May 12 leak deadline.
↗ Senate Commerce Committee**Pre-existing controls that reduced exposure (positive signal).** Pearland ISD confirmed that two specific Canvas-tenant configurations meaningfully reduced their breach impact: (1) Canvas messaging disabled district-wide (so no in-platform message exfiltration possible) and (2) student email accounts restricted to receiving only `.edu` or `.mil` domain mail (meaningfully blunting downstream phishing pivots). These are zero-cost configuration choices that any Canvas-tenant OIT can deploy retroactively. Combined with Charlottesville's MFA-on-parent-accounts finding, the pattern is clear: **default Canvas posture is materially weaker than locked-down configurations**, and locked-down configurations measurably reduced this incident's exposure.
↗ FOX 26 Houston (Pearland ISD statement)**First international regulator confirmed receiving notifications: Dutch DPA.** All seven affected Dutch research universities (UvA, VU Amsterdam, Erasmus Rotterdam, Tilburg, TU Eindhoven, Maastricht, U Twente) filed preliminary GDPR Article 33 data-breach notifications with the Autoriteit Persoonsgegevens in the days following May 1, 2026 disclosure. This breaks the public-silence pattern at ICO, OAIC, NCSC, OPC. Watch for an AP public advisory within 2-4 weeks under GDPR's response cadence. The Dutch sector consortium Universiteiten van Nederland (UNL) is the **first** higher-ed sector body globally to issue a coordinated public statement; SURF (Dutch NREN) is named as coordinator and cites its 2025 privacy audit of Instructure regarding tenant separation. NL Times reports 44 Dutch educational institutions impacted in total when including hogescholen.
↗ Universiteiten van Nederland + Autoriteit Persoonsgegevens**Best single framing of the incident, Doug Thompson, Tanium.** Quoted in Inside Higher Ed: 'This breach follows a clear pattern we've been watching for the last 18 months. Instead of targeting individual campuses, attackers are moving up the data supply chain to the platforms that sit underneath thousands of institutions at once. It's the math of a bank robber who just figured out where the armored truck stops. Why hold up a hundred branches when the truck visits all of them? The real risk now is downstream. With access to real names, email addresses and even teacher-student messages, the next wave of phishing will not be generic. It will reference real courses and real conversations, which makes it far more likely to succeed.'
↗ Inside Higher Ed quoting Doug Thompson, Tanium**Counter-signal: gravitational pull TOWARD Canvas was still strong as the breach landed.** Two procurement-side data points one-to-three weeks pre-breach cut against any 'Canvas in death spiral' narrative: (1) the UNC System Board of Governors voted to standardize all 17 UNC institutions on Canvas as the single system-wide LMS (NC A&T implementing Fall 2026); (2) Instructure announced an exclusive partnership with K16 Solutions on April 29, 2026, one day before the breach, to accelerate migrations TO Canvas, with Sinclair Community College locked in for D2L→Canvas Summer 2026 go-live. Analyst consensus across Dark Reading, Higher Ed Intel, and Phil Hill (On EdTech): no immediate customer loss expected; PowerSchool→Infinite Campus comp is exceptional, not predictive. Watch the WCPSS Board of Education June 2026 agenda for first credible non-renewal candidate.
↗ NC A&T Canvas Implementation Page + Instructure / Dark Reading**Cyber-policy thought-leader silence parallels consortium silence.** Brian Krebs (Krebs On Security) has not blogged the incident as of May 8, 2026. Bruce Schneier (Schneier on Security) has not blogged it. Alex Stamos, Jen Easterly, Chris Krebs (former CISA Director), Anne Neuberger, Dmitri Alperovitch, Rob Joyce, John Hultquist, Kevin Mandia, Lisa Monaco, no public commentary in indexed coverage May 1-8. Most surprising silence: **Brett Callow** (Emsisoft / Coveware), whose career has been built on ransomware/extortion-breach commentary, has not been quoted in any major outlet. The entire **FERPA / privacy-law academic bench** (Solove, Hartzog, Reidenberg, Polonetsky) is also silent, despite the incident potentially being 'the largest FERPA violation in history' (a phrase repeated anonymously in coverage).
↗ Krebs On Security + Schneier on Security (verified silent through May 8, 2026)**Penn-specific May 8 deadline appears to have passed without public dump.** ShinyHunters had specifically warned the University of Pennsylvania that its data, covering ~306,000 Penn users, would be leaked May 8, 2026 absent contact. As of late afternoon May 8 ET, no Penn-specific data dump has surfaced publicly; the deadline has effectively been folded into the omnibus May 12, 2026 ultimatum. Reported record counts have crept upward in May 7-8 coverage: BleepingComputer cites 280 million records (vs. earlier 275 million); some outlets reference 231 million; institution count drifts between 8,800 and 9,000+. ShinyHunters numbers may be inflating intentionally as the deadline approaches.
↗ Daily Pennsylvanian + BleepingComputer**No federal-court class-action complaint filed yet, anti-misclassification note.** As of May 8, 2026 evening ET, no federal-court class-action complaint has been filed specifically over the May 2026 Instructure breach. Multiple plaintiff firms (Chimicles Schwartz Kriner & Donaldson-Smith, Stueve Siegel Hanson, ClassAction.org partners) are in pre-filing investigation stage. **Watch for first complaint Mon May 11 or Tue May 12** in the Northern District of California, District of Delaware, or District of Utah. Note: the 'Hernandez-Silva v. Instructure' case that surfaces in some search results is a SEPARATE March 2025 student-data-monetization case, dismissed August 2025, not a breach lawsuit. Hub maintainers should not cite Hernandez-Silva as a May 2026 breach lawsuit.
↗ ClassAction.org investigation tracker**NEW attack-vector attribution: Free-For-Teacher accounts.** Instructure spokesperson statement to TIME magazine overnight May 7-8: 'Out of an abundance of caution, [Instructure] temporarily took Canvas offline to contain access and further investigate.' The company said the threat actor 'exploited an issue related to Free-For-Teacher accounts' (Canvas's free-tier instance for individual teachers, separate from paid institutional tenants). Those accounts have been shut down to restore access to paid Canvas tenants, the first substantive corporate explanation of the May 7 access vector. This is new attribution detail not present in earlier May 1-3 disclosures and suggests the May 7 'second breach' may have been a different vector than the original April 30-May 1 incident.
↗ TIME Magazine**ShinyHunters appears to have DELISTED Instructure from active extortion blog.** Per Krebs On Security reporting May 8, 'sources close to the investigation report that ShinyHunters' data leak blog no longer lists Instructure among its current extortion victims, suggesting active negotiation may be underway.' The 3.65 TB 'proof' sample posted on May 3 remains the only verified Canvas-derived dataset publicly in circulation. The Penn-specific May 8 deadline appears to have passed without a Penn-specific dump. **Critical interpretation:** delisting + restored Canvas + paid-tenant containment via Free-For-Teacher shutdown is consistent with a backchannel-payment scenario, but Instructure has made no payment statement.
↗ Krebs On Security**CEO Steve Daly continues silence as of May 8.** All Instructure corporate communications about this breach have come from CISO Steve Proud (May 1-2) and unnamed spokespeople (May 7-8 statements to TIME). CEO Steve Daly has issued NO public statement of record, no blog post, no press release, no customer letter signed by his office, no investor letter. The contrast with PowerSchool CEO Hardeep Gulati (who was publicly visible during the December 2024 breach) is notable. CEO silence in a breach of this scale is itself a tracked data point for institutional readers.
↗ Instructure leadership page (no Daly public breach statement located through May 8)**Plaintiff bar field expands to four firms; Wohl & Fruchter publicly soliciting stockholders.** As of May 8, four U.S. plaintiff firms have publicly opened pre-filing investigations of the Instructure breach: Chimicles Schwartz Kriner & Donaldson-Smith, Stueve Siegel Hanson, Zimmerman Reed (consumer.zlk.com), and Bryson Harris Suciu & DeMay PLLC. Separately, Wohl & Fruchter LLP is hosting a public case page soliciting Instructure stockholders for the existing pre-breach Delaware Chancery Section 220 action (C.A. No. 2024-1122) attacking the $4.8 B KKR deal process, that case was filed October 31, 2024 and is the natural vehicle if breach-related fiduciary claims emerge against the pre-close Instructure board. No federal-court complaints have been filed as of May 8 evening; first filings expected May 11-12.
↗ Wohl & Fruchter — Instructure case page**FBI 'declines to comment', first explicit on-record federal posture.** When ABC11 Raleigh-Durham reached out to the FBI for comment on the Canvas breach, the FBI declined to comment. This is the first on-record federal-agency response posture: not 'investigating,' not 'aware,' but explicit refusal to comment. Combined with CISA, FTC, PTAC, FSA, ED, ONCD, and all 13+ congressional committee silences, the federal vacuum has now persisted 168+ hours since Instructure's May 1 disclosure.
↗ ABC11 Raleigh-Durham**Mandiant CTO Charles Carmakal on-record attribution.** TechCrunch quoted Charles Carmakal (CTO, Google-owned Mandiant Consulting) on May 7: 'the attack on Canvas customers was just one of several major cybercrime campaigns being launched by ShinyHunters at the moment.' Mandiant's broader ShinyHunters tradecraft profile: vishing impersonating IT helpdesk, fake company-branded SSO/login pages for credential harvest, OAuth Device Flow abuse via local Salesforce Data Loader instances, generation of 8-character device codes pushed to victims via vishing, slow silent exfiltration via legitimate API surface. **Note:** Mandiant has NOT been confirmed as Instructure's engaged forensics firm of record; Instructure has only said 'outside forensics experts.'
↗ TechCrunch quoting Mandiant CTO Charles Carmakal**Joint CEO Daly + CISO Proud customer communication.** Per 6ABC Philadelphia reporting (relayed Instructure customer letter, May 5): 'We know this incident affects the trust you place in us, and we take that seriously. We are committed to sharing timely, accurate updates as our investigation progresses.' This is the first sourced direct quote attributing language to both CEO Steve Daly and CISO Steve Proud, though Daly has still issued no standalone public statement under his own name, no blog post, no investor letter.
↗ 6ABC Philadelphia (relayed Instructure customer letter)**ShinyHunters defacement payload, full ransom note text.** The HTML defacement payload injected into Canvas login pages on May 7, 2026 (~3:30 PM ET) contained verbatim: "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'. If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by May 12 2026 before everything is leaked." The payload was visible to all users across affected schools simultaneously (suggesting a centrally-injected resource rather than per-tenant config). By ~4:20 PM ET on May 7, the defacement was replaced by 'Canvas is currently undergoing scheduled maintenance' messaging, Instructure's choice of the 'scheduled maintenance' euphemism for an active extortion incident drew sharp criticism (Cloudskope CEO Dipan Mann: '275 Million Users Exposed. 8,809 Schools Down. Instructure Calls It Scheduled Maintenance.').
↗ BleepingComputer (defacement payload text)**MAJOR ATTACK-VECTOR CORRECTION: Salesforce Experience Cloud guest-user-profile misconfiguration, NOT Canvas Login Customization XSS.** Multiple converging sources (Hackread, BleepingComputer, SOCRadar, Rescana) describe the initial-access vector as Salesforce Experience Cloud guest-user-profile misconfiguration, with lateral pivot into Canvas tenancy via OAuth-issued tokens for connected apps. This is the same campaign vector ShinyHunters used against ~300-400 organizations since September 2025 (Salesloft Drift). The September 2025 prior incident at Instructure's Salesforce instance was the targeting-database foothold; April 25-30 2026 saw exploitation of Canvas Data 2 / Beta surface, OAuth Developer Key abuse, and automated paginated API extraction. **No CVE has been assigned** because the failure is configuration-class (likely CWE-732 / CWE-862 / CWE-1390), NOT software-defect class, meaning traditional CVE-driven patch management would not have prevented this.
↗ Hackread + BleepingComputer + SOCRadar + Rescana**MITRE ATT&CK mapping (multi-source consensus).** Sources converge on these techniques for the ShinyHunters Instructure operation: T1671 (abuse of cloud application integrations / connected apps), T1567 (Exfiltration Over Web Service), T1020 (Automated Exfiltration), within the broader ShinyHunters campaign cluster MITRE C0059. For the antecedent vishing tradecraft: T1566.004 (Spearphishing Voice / Vishing), T1078.004 (Valid Accounts: Cloud Accounts), T1550.001 (Use Alternate Authentication Material: Application Access Token), T1098.005 (create malicious connected/OAuth app), T1213.003 (data from cloud SaaS). **OIT-reader implication:** detection guidance is necessarily behavioral, anomalous Canvas Developer Key creation, anomalous OAuth token issuance preceding April 30 2026, unusual Canvas Data 2 / Beta API export volumes, off-hours API access from non-customer-IP-ranges. No CISA, MS-ISAC, REN-ISAC, or commercial CTI vendor has published file hashes, IPs, or domain IoCs as of May 8.
↗ Hackread + SOCRadar synthesis (no formal vendor mapping by Mandiant / CISA yet)**California state budget counter-signal, UC + CSU + CCC tri-system standardizing on Canvas mid-breach.** Per Phil Hill / On EdTech: California's three statewide higher-ed systems are using state budget allocations to STANDARDIZE on Canvas as the common LMS, even as the breach unfolds. Includes a $2M CSU line item to align with the CCC system's existing Canvas footprint. Combined with prior signals (UNC System 17 institutions, Sinclair CC D2L→Canvas Summer 2026, Instructure-K16 Solutions exclusive partnership April 29), the **counter-signal weight is now decisive**: three of the largest public systems in the US are EXPANDING Canvas adoption mid-breach. Procurement consensus: switching cost > breach risk.
↗ Phil Hill, On EdTech**Nordic cluster + multi-DPA notification chain.** Beyond the 7 Dutch research universities + AP, the breach has triggered breach-notification activity across Nordic regulators: University of Copenhagen (Canvas branded as 'Absalon') notified Datatilsynet (Danish DPA) on May 5; Aalto EE Finland notified Tietosuojavaltuutettu (Finnish Data Protection Ombudsman); five Swedish universities (KTH, KI, Lund, Uppsala, SLU) all notified Integritetsskyddsmyndigheten (IMY / Swedish DPA), with Sunet (Swedish NREN) coordinating. Despite seven+ DPAs across NL/SE/DK/FI receiving notifications, none have published a public advisory as of May 8, the regulator-publication gap is consistent globally.
↗ University of Copenhagen + cross-Nordic regulator filings**FEDERAL SILENCE PARTIALLY BROKEN, FBI Facebook advisory May 8.** Late afternoon / evening May 8, the FBI published a public Facebook advisory (referenced by Malwarebytes and Nextgov coverage) telling potential Canvas users: 'do not send payment'; 'receiving a message does not necessarily mean your personal information has been compromised'; 'threat actors often exaggerate or fabricate their access.' This is the **first US federal public communication on the breach**, partially breaking the day-8 federal-vacuum framing. CISA remains engaged but publicly silent. Notable interpretive frame: the FBI's 'threat actors often exaggerate' language signals federal skepticism toward ShinyHunters' 275M-record claim and implicitly discourages individual-institution ransom payment.
↗ FBI public Facebook advisory (referenced by Malwarebytes / Nextgov / EdScoop)**Forensic partner is CrowdStrike, not Mandiant.** Per Instructure's incident-update FAQ, CrowdStrike is Instructure's engaged forensic-IR partner. Mandiant's contribution has been **public commentary only**, CTO Charles Carmakal's TechCrunch quote and Krebs On Security attribution. CrowdStrike's May 8 readout (cited verbatim by Instructure): 'there is no evidence that the threat actor had system-level access, installed malware nor obtained login credentials, nor that any additional data was extracted during the renewed activity on May 7.' This corrects earlier hub speculation that Mandiant might be the forensic firm of record.
↗ Instructure Security Incident Update FAQ**Free-For-Teacher accounts confirmed as initial-access vector.** Per Bitdefender Technical Advisory and Rescana / SOCRadar convergence: ShinyHunters first gained access to Canvas production infrastructure by exploiting the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid institutional tenants. Initial intrusion: April 25, 2026. Detection: April 29, 2026 (4-day dwell). This refines the prior Salesforce Experience Cloud guest-user-profile attribution: BOTH framings are correct, the Salesforce-side foothold harvested in September 2025 enabled targeting, and the FFT-account abuse was the May 2026 production-side entry point. Data classes exposed: usernames, .edu email addresses, course names, enrollment information, Canvas inbox messages.
↗ Bitdefender Technical Advisory + Rescana + SOCRadar**RESOLUTION, Instructure / ShinyHunters settlement May 11-12.** BleepingComputer reports Instructure announced one day before the May 12 leak deadline that it had reached an agreement with ShinyHunters and 'received digital confirmation of data destruction (shred logs).' Vendor statement: 'no Instructure customers will be extorted as a result of this incident, publicly or otherwise.' Ransom dollar amount **undisclosed**. ShinyHunters delisted Instructure from the dark-web leak site. No individual institution has been confirmed to have paid separately. **Interpretation caveat:** shred-log 'destruction' confirmation is unverifiable by external parties; the PowerSchool precedent (Dec 2024, ransom paid but downstream re-extortion of districts still occurred in May 2025) recommends OIT readers continue to plan for direct-extortion contact attempts despite the announced settlement.
↗ BleepingComputer / The Hacker News / Inside Higher Ed (May 11-12 reporting)**CEO Steve Daly breaks silence with May 11 apology blog post.** Per IT Pro / KUTV / Idaho Ed News / Reuters, Daly published a blog-post apology on May 11, opening: 'I'll start where I should: with an apology. Over the past few days, many of you dealt with real disruption. Stress on your teams. Missed moments in the classroom. Questions you couldn't get answered. You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that. ... We focused on fact-finding and went quiet when you needed consistent updates. ... Rebuilding trust takes time. We're going to earn it back through consistent action and honest communication.' This is the first named-CEO statement of record, through May 8 evening, all corporate communication had been from CISO Steve Proud + unnamed spokespeople.
↗ IT Pro quoting CEO Steve Daly's May 11 blog apology**Federal silence officially broken, Garbarino House Homeland Security letter, May 11.** Rep. Andrew Garbarino (R-NY), Chairman of House Homeland Security, sent a formal letter to Instructure CEO Steve Daly on May 11, 2026 demanding a committee briefing by May 21. This is the first Congressional action of record; comes 10 days post-disclosure. Garbarino joins the FBI Facebook advisory + OAIC Australia statement as the only confirmed government-side public actions through the May 11-12 window. Senate HELP / Senate Commerce / Senate HSGAC / Senate Intel / House E&C / House Ed & Workforce / Markey-Cassidy COPPA 2.0 / all state AGs (including UT home-state, CA Bonta, NY James, TX Paxton, NC Jackson) remain silent.
↗ House Homeland Security Committee press release**Australia's OAIC issued the first international regulator public statement.** OAIC media centre advised affected users to lodge complaints directly with Instructure first, then escalate to OAIC after 30 days. The **Norwegian Datatilsynet** has since joined OAIC as the second international regulator with a public statement, citing 'serious' impact across 32 Norwegian institutions / ~250,000 students per Sikt coordination. UK ICO, Dutch AP, Swedish IMY, Danish Datatilsynet, Finnish Ombudsman, Canadian OPC all remain publicly silent despite having received GDPR / equivalent notifications.
↗ OAIC + Norwegian Datatilsynet**ED FSA issues first formal federal advisory May 12, but from financial-aid arm, not FERPA arm.** Federal Student Aid published a 'Technology Security Alert – Ongoing Cybersecurity Incident Involving the Canvas Learning Management System' on the May 12 ransom deadline day. Directed at IHEs participating in Title IV programs, it instructs institutions to review system, authentication, and Canvas integration logs for unusual access patterns between April 25 and May 8, 2026. **Notably from FSA cybersecurity (financial-aid integrity arm), NOT from the Student Privacy Policy Office or PTAC**, which per K-12 Dive reporting has 'requested information from Instructure to ensure compliance with FERPA' but has not issued a formal public advisory.
↗ ED FSA Partners Knowledge Center**Strongest privacy-civil-society voice: Elizabeth Laird, CDT.** Per K-12 Dive May 8 reporting, Center for Democracy & Technology's Director of Equity in Civic Technology Elizabeth Laird issued a public statement: 'Not only did this incident interfere with essential learning activities, it has exposed sensitive data about nearly 300 million users, including messages that could include incredibly personal information. This is an important wakeup call that schools and the companies that work with them have legal and ethical responsibilities to safeguard students and teachers online in the same ways that they are protected in the classroom.' CDT is the **only DC-area privacy think-tank** with a public statement of record. FERPA academic bench (Solove / Hartzog / Polonetsky / Reidenberg's Fordham CLIP / Grimmelmann / Goldman / Kaminski / Lessig) and EPIC / EFF / Common Sense Media / Parent Coalition for Student Privacy all remain silent through May 12.
↗ K-12 Dive quoting Elizabeth Laird, CDT**FIRST CLASS ACTION COMPLAINT FILED, Peterman v. Instructure (D. Utah).** Per Bloomberg Law, Jabon Peterman filed the first federal-court class-action complaint against Instructure on May 5, 2026 in the U.S. District Court for the District of Utah (No. 2:26-cv-00374). Plaintiff firms: Milberg PLLC, KO Lawyers, Carella Byrne Cecchi Brody Agnello PC, Marshall Olson & Hull PC (Utah counsel). A parallel **Hinds v. KKR & Co. Inc.** was filed May 8 in S.D.N.Y. by Yagman PLLC, naming KKR (Instructure's owner since the 2024 $4.8B take-private) on a negligence theory. **At least 7 federal suits filed** as of post-settlement reporting (6 in D. Utah + 1 in S.D.N.Y. naming KKR). No JPML/MDL consolidation order yet. Per State of Surveillance: 'The settlement with ShinyHunters does not resolve Instructure's civil liability to affected users.'
↗ Bloomberg Law**Potential statutory violation: Instructure may not have notified state AGs.** Per ClassAction.org and Inside Higher Ed: 'Instructure has not yet reported either data breach to state attorney general offices, which may have violated federal or state laws.' Most state breach-notification statutes require notification to the state AG within 30-60 days of discovery (some sooner for high-volume breaches). If accurate, this creates additional regulatory exposure beyond civil class-action liability, likely AG-action trigger within 30 days. NC AG Jeff Jackson's standing PowerSchool CID provides the cleanest precedent template.
↗ ClassAction.org + Inside Higher Ed**Three universities formally extended / canceled academic deadlines** (in addition to JMU's May 13 extension already documented): Emory University extended grade submission deadlines by 7 days and notably acknowledged 'Emory can't independently verify Instructure's findings'; East Carolina University moved the grade-submission deadline to 8 AM Wednesday May 13 (Provost Christopher Buddo named); Idaho State University outright canceled all afternoon finals on May 7, the most aggressive academic accommodation in the dataset. Pairs with Birmingham UK (May 13 deadline) and SMU TX (postponed Fri exams to Sun May 10).
↗ Emory News + WCTI ABC 12 + Idaho State Journal**Instructure denial of May 7 data theft contradicted by 330-portal defacement.** Instructure's incident-update FAQ states 'Instructure has not found evidence that data was taken during the May 7 activity.' However, ShinyHunters defaced login portals at ~330 institutions during this second wave, posting ransom messages directly on student/teacher screens. The characterization gap (data theft vs. defacement) remains a point of contention.
↗ Instructure incident-update FAQ vs BleepingComputer/TechCrunchAttack Vector: what OIT readers need to know
Configuration-class, not software-defect class · No CVE assigned
Multiple converging sources (BleepingComputer, SOCRadar, Rescana, Hackread) describe the initial-access vector as a Salesforce Experience Cloud guest-user-profile misconfiguration, with lateral pivot into the Canvas tenancy via OAuth-issued tokens for connected apps. This is the same campaign vector ShinyHunters used against ~300-400 organizations since September 2025 (the Salesloft Drift / UNC6395 wave).
MITRE ATT&CK consensus mapping: T1671 (abuse of cloud application integrations), T1567 (Exfiltration Over Web Service), T1020 (Automated Exfiltration), within campaign cluster C0059. Supplemental: T1566.004 (Vishing), T1098.005 (malicious OAuth app), T1078.004 (Valid Cloud Accounts), T1213.003 (data from cloud SaaS), T1550.001 (token abuse).
Implication for OIT readers: traditional CVE-driven patch management would not have prevented this. Detection guidance is necessarily behavioral: anomalous Canvas Developer Key creation, anomalous OAuth token issuance preceding April 30 2026, unusual Canvas Data 2 / Beta API export volumes, and off-hours API access from non-customer-IP-ranges. Pre-existing controls that measurably reduced exposure: MFA on parent / observer roles (Charlottesville City Schools) and Canvas messaging-disabled + email-domain whitelist (Pearland ISD).
Mid-to-late May 2026 (litigation aftermath)
Consumer class actions proliferate in federal court. Early reporting counted at least seven suits (six in the District of Utah, e.g. Peterman v. Instructure, plus Hinds v. KKR in the S.D.N.Y. naming Instructure's owner); later reporting cited roughly 18. Claims center on negligence, breach of legal obligations, and unjust enrichment. No JPML consolidation order had issued, and no state AG, FTC, or international DPA enforcement action had concluded, at the time this record was archived.
↗ Bloomberg LawMay 12, 2026
Federal Student Aid publishes a 'Technology Security Alert' on the Canvas incident, directing Title IV institutions to review system, authentication, and Canvas integration logs for unusual access between April 25 and May 8, 2026. It is the first formal federal advisory, issued from FSA's financial-aid-integrity arm rather than the Student Privacy Policy Office / PTAC.
↗ ED Federal Student AidMay 12, 2026 · end-of-day MDT
ShinyHunters' 'full leak' deadline passes without a public dump and Canvas remains operational. Instructure considers the incident resolved. Security commentators caution that shred-log destruction cannot be externally verified and that the PowerSchool precedent (a paying vendor did not stop direct district-level re-extortion months later) warrants continued vigilance.
↗ The Hacker NewsMay 11, 2026 · afternoon MDT (~one day before deadline)
Instructure announces it has reached an agreement with ShinyHunters and 'received digital confirmation of data destruction (shred logs).' Vendor states 'no Instructure customers will be extorted as a result of this incident, publicly or otherwise.' Ransom amount undisclosed. ShinyHunters delisted Instructure from the dark-web leak site.
↗ BleepingComputerMay 11, 2026
House Homeland Security Committee Chair Andrew Garbarino (R-NY) sends formal letter to Instructure CEO Steve Daly demanding committee briefing by May 21, 2026, the first Congressional action of record on the breach.
↗ House Homeland Security CommitteeMay 11, 2026 · morning MDT
Instructure CEO Steve Daly publishes a public apology blog post, the FIRST CEO-named statement of record. Opens: 'I'll start where I should: with an apology. You deserved more consistent communication from us, and we didn't deliver it.' Through May 8 evening, all corporate communications had come from CISO Steve Proud or unnamed spokespeople.
↗ IT Pro quoting Steve Daly blog postMay 8, 2026 · evening ET
FBI publishes Facebook public advisory, first US federal public communication on the breach. Key language: 'do not send payment'; 'receiving a message does not necessarily mean your personal information has been compromised'; 'threat actors often exaggerate or fabricate their access.' Bloomberg, TIME, NPR, Reuters wire all enter coverage on May 8; NYT, WSJ, FT, BBC still silent.
↗ FBI Facebook advisory (referenced by Malwarebytes)May 8, 2026
ShinyHunters threatens 'full leak' if no engagement; final payment deadline (per defacement message): end-of-day May 12, 2026. Canvas remains unavailable at most affected US tenants. Two class-action investigations announced.
↗ Harvard CrimsonMay 7, 2026 · evening ET
**JMU formally postpones final exams** scheduled for Friday May 8 to Wednesday May 13, the first US institution documented to have explicitly delayed exams. Liberty publicly commits to 'appropriate class extensions.' TAMU-CC issues 'Code Blue' campus alert about phishing copycats.
↗ JMU ComputingMay 7, 2026 · ~3:00 PM CT, afternoon outage cascade
Mass downstream school outages. UW–Madison (3:10 PM CT), U Iowa, Penn State, Baylor (5:22 PM CT), UMD, OSU, OU, U Missouri System, JMU, Penn (5:19 PM ET), Harvard, FIU (5:33 PM ET), VCU, Princeton, ASU all post advisories or confirm outage. UCCS reports outage at 2:20 PM MT.
↗ UW–Madison DoITMay 7, 2026 · ~3:30 PM ET (mass-defacement event)
**ShinyHunters defacement campaign.** HTML injection alters Canvas login portals across customer schools globally, visible ~30 min before Instructure takes Canvas offline. Defacement message: 'ShinyHunters has breached Instructure (again).' Sets May 12 leak deadline.
↗ BleepingComputerMay 7, 2026 · early MDT
Series of recurrent Instructure status posts: 01:11 'Investigating' → 01:24 'Identified, fix being implemented' → 09:55 'Identified' (recurrent) → 11:37 'Resolved.' Containment claim begins to fray.
↗ Instructure Status — HistoryMay 6, 2026 · evening ET
Princeton's Dean of the College Michael Gordin emails instructors asking them to download Canvas gradebooks 'as a purely precautionary measure.' UPenn confirms ~306,000 affected users (first US institution with specific count). Univ. of Auckland posts first international advisory.
↗ Daily PennsylvanianMay 6, 2026 · 3:13 PM MT / 5:13 PM ET
Instructure marks the incident 'Resolved': 'Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.' Cornell, Columbia, Duke, Oklahoma State, JMU, and others post statements after Instructure formally notifies impacted institutions.
↗ K-12 DiveMay 6, 2026 · 1:17 PM MT
Instructure status update: 'Canvas Data 2 and Beta should now be available for all customers. Canvas Test remains under maintenance.'
↗ Instructure Status — HistoryMay 5, 2026
Inside Higher Ed publishes its 'Pay or Leak' analysis. Boise State, UMass Amherst, UWM, and others post detailed advisories. Canvas Data 2 and Canvas Beta restored to global customers.
↗ Inside Higher EdMay 4, 2026
First wave of US university advisories. Rutgers, CU Boulder, Boise State, UT Austin, the University of California system, Peralta Community College District, College of the Canyons, and others post early statements describing it as 'a nationwide issue affecting thousands of institutions.'
↗ UCnetMay 3, 2026
**ShinyHunters claims responsibility.** Group lists Instructure on Ransomware.Live / Tor leak site, claiming 3.65 TB / 275M individuals / ~9,000 schools and setting an initial May 6 payment deadline (later extended to May 12).
↗ HackreadMay 2, 2026
Saturday update: Instructure says incident 'has been contained' and specifies exposed data categories, names, email addresses, student ID numbers, and Canvas messages between users.
↗ K-12 DiveMay 1, 2026 · 4:30 PM MT / 6:46 PM ET
Public disclosure: CISO Steve Proud's customer letter labels it 'a cybersecurity incident perpetrated by a criminal threat actor.' Instructure engages outside forensic experts and notifies law enforcement.
↗ BleepingComputerMay 1, 2026 · 08:09 MDT
First Instructure status post: 'some customers were experiencing limited disruption to tools relying on API keys', investigating, taking precautionary steps.
↗ Instructure Status — Incident HistoryApril 30, 2026
Public-facing impact surfaces: suspicious activity disrupts Canvas Data 2, Canvas Beta/Test, and tools dependent on API keys. Instructure's status-page investigation begins.
↗ Instructure Status PageApril 29, 2026
Detection (4-day dwell): Instructure's security team detects unauthorized activity in the Canvas production environment, revokes the actor's access, and engages outside forensic specialists (later confirmed as CrowdStrike).
↗ Bitdefender Technical AdvisoryApril 25, 2026
Second ShinyHunters intrusion begins: the actor gains access to Canvas production infrastructure by exploiting the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid tenants. The actor would later claim it 'reached out' but was met only with 'small security patches' rather than negotiation.
↗ Bitdefender Technical AdvisorySept 2025
Prior ShinyHunters social-engineering breach of Instructure's Salesforce instance, reported as business-contact data only. Instructure publicly addressed it [in this blog post](https://www.instructure.com/resources/blog/security-incident-update). Same threat actor; framing: 'first time.'
↗ Instructure 'Update on Security Incident' (Sep 2025)
Key Voices: expert commentary on record
In the absence of EDUCAUSE / REN-ISAC / NACUA public statements, three named experts have carried the analytical commentary on the public record. Their verbatim quotes:
Higher-Ed Cyber Academic
Anton Dahbura
Executive Director, Johns Hopkins University Information Security Institute
“The Canvas breach is a reminder that no platform is immune... Educational platforms are particularly rich targets given the concentration of personal, financial and international student data. Even organizations that do the right things can still be exposed through trusted vendors.”↗ Inside Higher Ed
Supply-Chain Framing
Doug Thompson
Chief Education Architect, Tanium
“Attackers are moving up the data supply chain to the platforms that sit underneath thousands of institutions at once. It’s the math of a bank robber who just figured out where the armored truck stops. Why hold up a hundred branches when the truck visits all of them?”↗ Inside Higher Ed
Threat-Actor Attribution
Charles Carmakal
CTO, Mandiant Consulting (Google)
“The attack on Canvas customers was just one of several major cybercrime campaigns being launched by ShinyHunters at the moment.” Mandiant’s tradecraft profile names vishing-driven IT-helpdesk impersonation + OAuth Device Flow abuse via Salesforce Data Loader.”↗ TechCrunch
Each row below documents a single public action by a single institution, anchored to a primary source. If your institution has issued an alert, posted to an OIT status page, or extended deadlines and it is not yet listed, please send a tip.
62 of 347 entries carry verbatim-confirmed quotes (the rest are paraphrased from primary-source coverage). Use the filters below to slice by response type, US state / country, or full-text search by institution name, then export exactly what you see as CSV or JSON.
Showing 347 of 347 responses
UK Russell Group + Continental Europe (not-Canvas consolidated)
UK-EU-Not-Canvas · UK · Verified-not-using-Canvas as of May 12, 2026
**Critical disambiguation entry**, most UK Russell Group + flagship Continental European universities use Moodle / Blackboard / D2L, NOT Canvas. Prevents reader inference that all major European universities are affected. Oxford / Birmingham / Edinburgh / Liverpool / Manchester are the UK Canvas exceptions; Aalto EE / KTH / KI / Lund / Uppsala / SLU / U Copenhagen / U Oslo / NTNU / UiT / U Iceland are the continental exceptions.
Multiple institutional IT pagesIron County School District
ICSD-UT · UT · May 10, 2026 (MDT)
Cedar City UT (~9K students). Defensive 'not directly attacked' framing reflective of cyber-insurance-counsel guidance.
Iron County TodayNational University of Singapore (active response)
NUS-Active · SG · May 8 statement; May 10 password-reset email; May 11-14 controlled access (SGT)
**Updates earlier silent NUS status.** NUS ordered campus-wide password reset, among the most aggressive responses globally. Migrated to Canvas from LumiNUS December 2023.
MustShareNews + Straits TimesSingapore Institute of Management Global Education
SIM · SG · May 8-10, 2026 (SGT)
Second Singapore institution to order campus-wide password reset. Notable for granular operational accommodations (direct Zoom-link distribution, deadline postponements).
The Star (Malaysia) ASEAN PlusDes Moines Public Schools
DMPS-IA · IA · May 8, 2026 (CDT)
Largest district in Iowa (~31K students).
NewsRadio 1040 WHO Des MoinesHamilton County Schools (TN)
HCS-TN · TN · May 8, 2026 (EDT)
Chattanooga (~44K students). 4th-largest TN district.
NewsChannel 9 ChattanoogaColumbus City Schools
Columbus-CS · OH · May 8, 2026 (EDT)
**Ohio's largest K-12 district.** First K-12 in hub to disclose a specific affected-user count (~19,000).
Spectrum News 1 ColumbusHilliard / Upper Arlington / Cleveland Metro hybrid (OH K-12 cluster)
OH-K12-Cluster · OH · May 8, 2026 (EDT)
OH K-12 cluster expansion. CMSD is the only documented Schoology-primary + Canvas-secondary hybrid.
ABC6 Columbus + Cleveland Metropolitan SDSpringfield Public Schools (Missouri R-XII)
SPS-MO · MO · May 8, 2026 (CDT)
**First Missouri K-12 statement in hub.** Largest accredited district in Missouri (~25K students). SPS is an Instructure case-study customer ('100% of Students Choose Canvas'), awkward for vendor PR.
Springfield Daily CitizenSeminole County Public Schools
SCPS-FL · FL · May 8, 2026 (EDT)
Orlando-area district (~67K students).
ClickOrlando (WKMG)Collier County Public Schools
CCPS-FL · FL · May 8, 2026 (EDT)
Naples-area district (~47K students). **Counter-posture:** kept Canvas student access ON rather than disabling, contrast with Seminole / Duval / Brevard / Cherokee.
WINK NewsHamilton Southeastern Schools
HSE · IN · May 8, 2026 (EDT)
**First INDIANA K-12 in hub.** Fishers / suburban Indianapolis (~22K students). Cyber-insurance-led posture rare in public messaging.
Hamilton County Reporter (IN)Duval County Public Schools
DCPS-FL · FL · May 8, 2026 (EDT)
Largest district in Northeast FL (~127K students). Limited Canvas footprint (PD only) blunts exposure.
News4JaxClay County / Nassau County FL (Jacksonville-area cluster)
JAX-K12-Cluster · FL · May 8, 2026 (EDT)
Jacksonville-area cluster pairing with Duval (already in hub).
News4JaxTexas Woman's University
TWU · TX · May 8, 2026 morning (CDT)
Public doctoral, the only public university focused on women's education. Restored access faster than UNT.
TWU My Courses StatusHawaii State Department of Education / HVLN
HIDOE · HI · As of May 8, 2026 (HST)
Only single-statewide K-12 district in U.S. (~157K students). Canvas is opt-in via HVLN/HOT (not universal). Direct parallel to NCDPI but no HIDOE statement issued, high-priority gap.
Hawaii Virtual Learning NetworkHawai'i Pacific University
HPU · HI · Silent through May 8, 2026 (HST)
**AANAPISI gap-fill, first Hawai'i higher-ed entry in hub.** Private masters (~3,400 students). **Critical disambiguation:** UH Mānoa runs Laulima (Sakai), NOT Canvas.
Hawai'i Pacific UniversityIḷisaġvik College
Iḷisaġvik · AK · Silent through May 8, 2026 (AKDT)
**TCU gap-fill, FIRST ALASKA ENTRY in hub.** AIHEC member, only TCU in Alaska. Northernmost accredited US college.
Iḷisaġvik CollegeMesa Public Schools / Tucson USD / Phoenix Union HSD
AZ-Big-3 · AZ · As of May 8, 2026 (Arizona time, no DST)
Three biggest Arizona K-12 Canvas tenants silent through day 7, gap for follow-up.
Mesa Public Schools Canvas pageMaricopa Community Colleges
MCCCD · AZ · Silent through May 8, 2026
One of the largest CC systems in the US. AZ gap-fill.
Maricopa Community CollegesDiné College
Diné · AZ · Silent through May 8, 2026 (Arizona time)
First confirmed tribal college in hub. Navajo Nation. AIHEC member. ~1,400 students. Tribal-college gap-fill.
Diné CollegeTohono O'odham Community College
TOCC · AZ · Silent through May 8, 2026 (Arizona time)
Tribal community college. AIHEC member.
Tohono O'odham Community CollegeNorthwest Indian College
NWIC · WA · Silent through May 8, 2026 (PDT)
Tribal college, AIHEC member. Pacific NW.
Northwest Indian CollegeEastern Washington University
EWU · WA · May 7-8, 2026 (PDT)
Public masters. Notable headline suggesting EWU had advance notification from Instructure that hasn't yet been publicly characterized.
The Easterner (EWU student paper)Gonzaga University
Gonzaga · WA · May 7-8, 2026 (PDT)
Private doctoral, Jesuit (~7K students).
KREM 2 SpokaneUniversity of Idaho
U Idaho · ID · May 8, 2026 (PDT)
Public R2, land-grant. **Most reassuring/upbeat institutional posture in the dataset**, spokeswoman Jodi Walker on record.
The Spokesman-ReviewAlbuquerque Public Schools
APS-NM · NM · As of May 8, 2026 (MDT)
~73K students; largest district in New Mexico, 31st largest in U.S. Confirmed Canvas user since 2017, silence is high-priority gap for follow-up.
APS Canvas LMS pageTennessee State University
TSU · TN · Silent through May 8, 2026
Public HBCU, land-grant (~7K students). HBCU gap-fill.
Tennessee State UniversitySalish Kootenai College
SKC · MT · Silent through May 8, 2026 (MDT)
First Montana entry in hub. Tribal college, AIHEC member.
Salish Kootenai CollegeSinte Gleska University
SGU · SD · Silent through May 8, 2026
Tribal university. First South Dakota entry in hub.
Sinte Gleska UniversityOglala Lakota College
OLC · SD · Silent through May 8, 2026
Tribal college, AIHEC member.
Oglala Lakota CollegeTecnológico de Monterrey (ITESM)
Tec · MX · Silent through May 8, 2026 (CDT-Mexico)
First Mexico entry in hub. Mexican INAI breach-notification regime applies.
Instructure customer story (Tec de Monterrey)Brigham Young University
BYU · UT · Silent through May 8, 2026 (MDT)
Private R1, religious affiliation (LDS Church). ~34K students. Pairs with U Utah / Davis SD / Granite SD / USBE Utah cluster.
BYU CanvasBrigham Young University-Idaho
BYU-I · ID · Silent through May 8, 2026
Private religious (LDS Church). ~30K students.
BYU-Idaho CanvasUtah Valley University
UVU · UT · Silent through May 8, 2026
Public masters/bachelors (~45K students).
Utah Valley UniversitySalt Lake Community College
SLCC · UT · Silent through May 8, 2026
Public CC (~28K students). Pairs with U Utah / BYU / UVU.
Salt Lake Community CollegeUniversity of Texas at El Paso
UTEP · TX · Silent through May 8, 2026 (MDT)
**HSI gap-fill.** Public R1, HSI (~24K students).
UTEPMexican university cluster (ITAM / Anáhuac / UDEM / UAG)
MX-Cluster · MX · Silent through May 8, 2026 (CST-Mexico)
Mexican cluster pairing with Tec de Monterrey (already in hub).
CyberSegJackson State University
JSU · MS · Silent through May 8, 2026
Public HBCU (~7K students). Pairs with Mississippi State already in hub.
Jackson State UniversityTuskegee University
Tuskegee · AL · Silent through May 8, 2026
Private HBCU, land-grant (~3K students). HBCU gap-fill.
Tuskegee UniversityAuburn University
Auburn · AL · Silent through May 8, 2026
Public R1, SEC, land-grant (~32K students).
Auburn Canvas portalUniversity of Alabama
UA · AL · Silent through May 8, 2026
Public R1, SEC (~39K students).
UA eLearning / CanvasLone Star College System
LSCS · TX · Silent through May 8, 2026
Largest TX community college system. CC gap-fill.
Lone Star College CanvasMemphis-Shelby County Schools
MSCS · TN · Silent through May 8, 2026
Largest TN K-12 district (~107K students). Contrast Knox County TN (already responded).
FOX 13 MemphisHaskell Indian Nations University
Haskell · KS · Silent through May 8, 2026
Federally-operated tribal university. Pairs with KU / K-State / Galena KS already in hub.
Haskell Indian Nations UniversityUniversity of Texas Rio Grande Valley
UTRGV · TX · Silent through May 8, 2026 (CDT)
**HSI gap-fill.** Public R2, HSI (~32K students), border region.
UTRGVTurtle Mountain Community College
TMCC · ND · Silent through May 8, 2026 (CDT)
**First North Dakota entry in hub.** AIHEC member, tribal land-grant.
Turtle Mountain Community CollegeLeech Lake Tribal College
LLTC · MN · Silent through May 8, 2026 (CDT)
**First Minnesota tribal college in hub** (Wayzata K-12 already covered). AIHEC member.
Leech Lake Tribal CollegeNebraska Indian Community College
NICC · NE · Silent through May 8, 2026 (CDT)
**First Nebraska entry in hub.** AIHEC member.
Nebraska Indian Community CollegeStillman / Talladega / Miles / Lawson State (AL HBCU cluster)
AL-HBCU-Cluster · AL · Silent through May 8, 2026 (CDT)
HBCU cluster gap-fill. Alabama HBCUs.
Stillman / Talladega / Miles / Lawson StateMadison Metropolitan School District / Spring Branch ISD / Rockwood R-VI / North Kansas City (Mid-tier silent K-12 cluster)
Mid-Tier-Silent-K12 · USA · Silent through May 8, 2026
K-12 cluster gap-fill across WI / TX / MO. Includes first WI K-12 entry (Madison).
Multiple district Canvas portalsWaukee CSD / Marshalltown CSD / Cedar Rapids CSD (Iowa K-12 cluster)
IA-K12-Cluster · IA · May 7-8, 2026 (CDT)
Iowa K-12 cluster expansion. Pairs with DMPS (already in hub).
We Are Iowa (Local 5) + KYOU-TVTexas A&M University (College Station)
TAMU · TX · Silent through May 8, 2026 (CDT)
Public R1, SEC, land-grant. ~73K students College Station.
Texas A&M CanvasUniversity of Texas at Dallas
UTD · TX · Silent through May 8, 2026 (CDT)
Public R1 (~31K students).
UTD eLearning CanvasUniversity of Texas at San Antonio
UTSA · TX · Silent through May 8, 2026 (CDT)
Public R1, HSI (~34K students).
UTSA CanvasUniversity of Texas at Arlington
UTA · TX · Silent through May 8, 2026 (CDT)
Public R1, HSI (~46K students).
UTA CanvasStephen F. Austin State University
SFA · TX · Silent through May 8, 2026 (CDT)
Public R2 (~12K students).
SFA CanvasSam Houston State University
SHSU · TX · Silent through May 8, 2026 (CDT)
Public R2 (~21K students).
Sam Houston State CanvasUniversity of North Texas
UNT · TX · Silent through May 8, 2026 (CDT)
Public R1 (~46K students).
UNT CanvasMissouri State University
MOState · MO · Silent through May 8, 2026 (CDT)
Public R2 (~24K students). Springfield MO.
Missouri State CanvasDrury University
Drury · MO · Silent through May 8, 2026 (CDT)
Private R2, Disciples of Christ-affiliated. ~3K students.
Springfield Daily CitizenUniversity of Memphis
U Memphis · TN · Silent through May 8, 2026 (CDT)
Public R1 (~21K students). Pairs with Memphis-Shelby County Schools (also silent).
U Memphis CanvasMiddle Tennessee State University
MTSU · TN · Silent through May 8, 2026 (CDT)
Public R2 (~22K students).
MTSU CanvasRice University
Rice · TX · Silent through May 8, 2026 (CDT)
Private R1, AAU (~9K students). Pairs with U Houston / Houston ISD.
Rice CanvasUniversity of Alabama at Birmingham
UAB · AL · May 8, 2026 morning (CDT)
Public R1, AAU. Pairs with U Alabama, Auburn.
AL.com via Yahoo NewsUniversity of Memphis
UMemphis · TN · May 7-8, 2026 (CDT)
Public R1 (~21K students). **Explicitly confirms 'University of Memphis was included in that breach'**, most direct institutional acknowledgment of impact.
U of Memphis ITSUniversity of Nebraska System (UNL / UNO / UNK / UNMC)
NU-System · NE · May 7-8, 2026 (CDT)
Covers all four University of Nebraska campuses (UNL flagship, UNO, UNK, UNMC). Public R1 + medical center.
Nebraska TodayAlabama A&M University
AAMU · AL · May 8, 2026 (CDT)
**HBCU PUBLIC STATEMENT (denial of impact), fourth confirmed HBCU response.** Public R2 HBCU. Notable for being a 'not impacted' framing.
FOX54 / Rocket City Now (Huntsville)Peruvian university cluster (PUCP / USIL / UDEP / UTEC / 5 more)
PE-Cluster · PE · May 8, 2026 (PET)
**First Peru entry in hub, 9 Peruvian universities affected.** Includes PUCP (Peru's top-ranked). Outage fell during finals when 30%-grade assignments were due.
Infobae PerúNYC DOE / LAUSD / CPS / Miami-Dade / Boston PS / Philadelphia SDP
Top-6-Not-Canvas · USA · Verified-not-using-Canvas as of May 8, 2026
Important context entry: prevents readers from incorrectly inferring breach impact at the largest US districts. NYC DOE primary LMS is Google Classroom; LAUSD mandated Schoology district-wide since 2020; Miami-Dade district-wide deploys Schoology (Miami Dade COLLEGE, separate institution, does use Canvas). Additional confirmed Schoology / Google Classroom districts: Dallas ISD, Cypress-Fairbanks, Northside ISD San Antonio, El Paso ISD, Aldine, Round Rock, Klein ISD, Newton PS (MA), Trenton PS (NJ), Red Clay (DE).
Multiple district LMS portalsCincinnati Public SchoolsLeak list
CPS-OH · OH · Silent through May 8, 2026
~36K students. **Named on the ShinyHunters leak list** but silent, high-priority watch.
Cincinnati Public SchoolsHoward University
Howard · DC · Silent through May 8, 2026
Flagship private HBCU. Silence is a tracked data point for HBCU coverage. ~14K students.
Howard University Canvas portalSpelman College
Spelman · GA · Silent through May 8, 2026
Top private HBCU women's college (~2K students). HBCU gap-fill.
Spelman CollegeMorehouse College
Morehouse · GA · Silent through May 8, 2026
Flagship private HBCU men's college. HBCU gap-fill.
Morehouse CollegeFlorida A&M University
FAMU · FL · Silent through May 8, 2026
Largest public HBCU by enrollment (~10K students). HBCU gap-fill.
Florida A&M UniversityNorth Carolina A&T State University
NC A&T · NC · Silent through May 8, 2026
Largest HBCU in the US (~13K students). Connects HBCU gap-fill to UNC System counter-signal already in the hub.
NC A&T Aggie Hub Canvas ImplementationNorth Carolina Central University
NCCU · NC · Silent through May 8, 2026
Public HBCU (~8K students). HBCU gap-fill.
North Carolina Central UniversityHampton University
Hampton · VA · Silent through May 8, 2026
Private HBCU (~3K students). HBCU gap-fill; pairs with VBCPS / Virginia VBCPS / Charlottesville VA already in hub.
Hampton UniversityBowie State University
BSU · MD · Silent through May 8, 2026
Maryland's oldest HBCU (~6K students). HBCU gap-fill.
Bowie State UniversityUniversity of Florida
UF · FL · Silent through May 8, 2026
Public R1, SEC, AAU. ~57K students. R1 flagship gap-fill.
UF e-Learning CanvasUniversity of Georgia
UGA · GA · Silent through May 8, 2026
Public R1, SEC, AAU (~40K students).
UGA e-Learning CommonsUniversity of CincinnatiLeak list
U Cincinnati · OH · Silent through May 8, 2026
Public R1 (~46K students). Pairs with Cincinnati Public Schools (named on ShinyHunters leak list).
University of Cincinnati CanvasWayne State University
Wayne State · MI · Silent through May 8, 2026
Public R1 (~24K students). Pairs with U-M (already in hub).
Wayne State CanvasUniversity of Central Florida
UCF · FL · Silent through May 8, 2026
Public R1, one of the largest US universities by enrollment (~70K students).
UCF Webcourses CanvasWest Virginia University
WVU · WV · Silent through May 8, 2026
Public R1, land-grant (~26K students). West Virginia gap-fill (first WV institution in hub).
WVU eCampus CanvasGeorge Mason University
GMU · VA · Silent through May 8, 2026
Public R1 (~40K students).
George Mason CanvasOld Dominion University
ODU · VA · Silent through May 8, 2026
Public R1 (~24K students).
ODU CanvasUniversity of Connecticut
UConn · CT · Silent through May 8, 2026
Public R1 (~33K students). First Connecticut institution in hub.
UConn CanvasUniversity of Buffalo (SUNY)
UB · NY · Silent through May 8, 2026
Public R1, SUNY flagship, AAU (~32K students). Partial Canvas footprint.
University at BuffaloStony Brook University
Stony Brook · NY · Silent through May 8, 2026
Public R1, AAU (~26K students).
Stony Brook IT CanvasNorthern Virginia Community College
NOVA · VA · Silent through May 8, 2026
Massive DMV-area CC. Federal-employee adjacent demographic.
NOVA CanvasMiami Dade College
MDC · FL · Silent through May 8, 2026
Largest 4-year HSI in US. Important disambiguation: MDC ≠ Miami-Dade County PS.
Miami Dade CollegeAtlanta Public Schools / Cobb County / Gwinnett County
Atlanta-Top-3-Not-Canvas · GA · Verified-not-using-Canvas as of May 8, 2026
Important disambiguation entry: prevents reader inference that all major Atlanta-area districts are affected.
Cobb County Schools CTLSBay Mills Community College
BMCC · MI · Silent through May 8, 2026
Tribal CC, AIHEC. Pairs with Wayne State / U Michigan.
Bay Mills Community CollegeUniversity of New Hampshire
UNH · NH · Silent through May 8, 2026
Public R1, land-grant (~15K students). First NH institution in hub.
UNH myCourses CanvasUniversity of Maine
UMaine · ME · Silent through May 8, 2026
Public R2, land-grant, sea-grant (~12K students). First ME institution in hub.
University of MaineUniversity of Vermont
UVM · VT · Silent through May 8, 2026
Public R1, land-grant (~14K students). First VT institution in hub.
University of VermontUniversity of Delaware
UDel · DE · Silent through May 8, 2026
Public R1 (~23K students). First DE institution in hub. NOTE: Red Clay Consolidated K-12 (already in hub) is Schoology, not Canvas, so UDel is Delaware's sole Canvas presence.
UDel CanvasUniversity of Rhode Island
URI · RI · Silent through May 8, 2026
Public R2 land-grant + sea-grant (~17K students).
URI CanvasHoward County Public School System
HCPSS · MD · Silent through May 8, 2026
Maryland K-12 (~58K students). Affluent DMV-adjacent district.
Howard County Public SchoolsUniversidad de los Andes (Chile)
UAndes · CL · Silent through May 8, 2026 (CLT)
First Chile entry in hub. Chile's updated Ley 19.628 data-protection law (2024 reform) breach-notification obligations effective 2026.
UAndes Chile CanvasFlorida A&M University
FAMU · FL · May 7-8, 2026 (EDT)
**HBCU UPGRADE, second confirmed HBCU public statement (after Morgan State).** Largest public HBCU (~10K students). Calendar-driven 'limited impact' framing is distinctive.
WTXL TallahasseeCheyney University of Pennsylvania
Cheyney · PA · Silent through May 8, 2026 (EDT)
**Oldest HBCU in the US (founded 1837).** Public HBCU, PASSHE member.
Cheyney University of PennsylvaniaFayetteville State University
FSU-NC · NC · Silent through May 8, 2026 (EDT)
HBCU gap-fill. Public HBCU in UNC System (~6,800 students). Vendor-confirmed Canvas tenant via WRAL.
WRALAlbany State / Fort Valley State / Savannah State (GA HBCU cluster)
GA-HBCU-Cluster · GA · Silent through May 8, 2026 (EDT)
HBCU cluster gap-fill. USG member institutions. Pairs with Fulton / Cherokee / Forsyth GA K-12 already in hub.
Albany State / Fort Valley State / Savannah StateBethune-Cookman / Edward Waters / Florida Memorial (FL HBCU cluster)
FL-HBCU-Cluster · FL · Silent through May 8, 2026 (EDT)
HBCU cluster gap-fill. Florida private HBCUs.
Bethune-Cookman / Edward Waters / Florida MemorialLincoln U PA / Langston / Wilberforce / Central State / Kentucky State / WV State / Bluefield State (HBCU silent cluster)
HBCU-Silent-Cluster · HBCU · Silent through May 8, 2026
HBCU cluster gap-fill across PA / OK / OH / KY / WV, completes documented HBCU footprint.
Multiple HBCU institutional pagesPasco / Marion / St. Lucie / Volusia / Hillsborough verify FL (silent FL K-12 Canvas tenants)
FL-K12-Silent-Cluster · FL · Silent through May 8, 2026 (EDT)
FL K-12 cluster expansion. Pasco was featured in an Instructure case study.
Multiple FL K-12 sourcesUNC Chapel Hill
UNC · NC · Silent through May 8, 2026 (EDT)
Public R1, AAU. UNC System has voted to standardize on Canvas.
UNC Chapel HillNC State University
NCSU · NC · Silent through May 8, 2026 (EDT)
Public R1, land-grant (~37K students).
NC State CanvasEast Carolina University
ECU · NC · Silent through May 8, 2026 (EDT)
Public R2 (~28K students).
ECU CanvasAppalachian State University
App State · NC · Silent through May 8, 2026 (EDT)
Public R2 (~21K students).
Appalachian State CanvasUNC Charlotte
UNCC · NC · Silent through May 8, 2026 (EDT)
Public R1 (~30K students).
UNC Charlotte CanvasWestern Carolina University
WCU · NC · Silent through May 8, 2026 (EDT)
Public R2 (~12K students).
WCU CanvasEast Tennessee State University
ETSU · TN · Silent through May 8, 2026 (EDT)
Public R2 (~14K students).
ETSU CanvasUniversity of Maryland, Baltimore County
UMBC · MD · Silent through May 8, 2026 (EDT)
Public R1 (~14K students). USM member.
UMBC CanvasTowson University
Towson · MD · Silent through May 8, 2026 (EDT)
Public masters (~20K students).
Towson CanvasUniversity of Maryland Eastern Shore
UMES · MD · Silent through May 8, 2026 (EDT)
**HBCU gap-fill.** Public HBCU, land-grant (~3K students). USM member.
University of Maryland Eastern ShoreUniversity at Albany (SUNY)
UAlbany · NY · Silent through May 8, 2026 (EDT)
Public R1 (~17K students).
UAlbany CanvasBinghamton University (SUNY)
Binghamton · NY · Silent through May 8, 2026 (EDT)
Public R1, AAU (~18K students).
Binghamton CanvasUMass Boston / Lowell / Dartmouth (UMass System cluster)
UMass-System · MA · Silent through May 8, 2026 (EDT)
UMass System cluster gap-fill. ~13K (Boston) + 18K (Lowell) + 8K (Dartmouth) students.
UMass Dartmouth CanvasDrexel University
Drexel · PA · Silent through May 8, 2026 (EDT)
Private R1 (~22K students). Pairs with Penn (in hub).
Drexel Learn CanvasTemple University
Temple · PA · Silent through May 8, 2026 (EDT)
Public R1 (~30K students). Pairs with Penn / Drexel.
Temple CanvasVillanova University
Villanova · PA · Silent through May 8, 2026 (EDT)
Private R1, Catholic/Augustinian (~10K students).
Villanova CanvasFordham University
Fordham · NY · Silent through May 8, 2026 (EDT)
Private R1, Catholic/Jesuit (~17K students).
Fordham CanvasSyracuse University
Syracuse · NY · Silent through May 8, 2026 (EDT)
Private R1 (~22K students).
Syracuse CanvasRochester Institute of Technology
RIT · NY · Silent through May 8, 2026 (EDT)
Private R2 (~19K students).
RIT myCourses CanvasUniversity of Pittsburgh
Pitt · PA · Silent through May 8, 2026 (EDT)
Public R1, AAU (~33K students).
Pitt CanvasCase Western Reserve University
CWRU · OH · Silent through May 8, 2026 (EDT)
Private R1, AAU (~12K students).
CWRU CanvasEmory University
Emory · GA · Silent through May 8, 2026 (EDT)
Private R1, AAU (~16K students). Pairs with UGA / Georgia Tech.
Emory CanvasWake Forest University
Wake Forest · NC · Silent through May 8, 2026 (EDT)
Private R2 (~9K students).
Wake Forest CanvasCarnegie Mellon University
CMU · PA · Silent through May 8, 2026 (EDT)
Private R1, AAU (~16K students). Pittsburgh.
CMU CanvasMIT (Massachusetts Institute of Technology)
MIT · MA · Silent through May 8, 2026 (EDT)
Private R1, AAU (~12K students). Hybrid LMS environment.
MIT CanvasYale University
Yale · CT · Silent through May 8, 2026 (EDT)
Private R1, AAU (~14K students). Pairs with UConn (in hub).
Yale CanvasDartmouth College
Dartmouth · NH · Silent through May 8, 2026 (EDT)
Private R1, Ivy League (~6K students).
Dartmouth CanvasElizabeth City State University
ECSU · NC · May 8, 2026 (EDT)
**HBCU PUBLIC STATEMENT, third confirmed (after Morgan State + FAMU + Lincoln MO + NCCU).** Public bachelors HBCU (~2K students) in UNC System.
The Daily AdvanceNorth Carolina Central University (reporter-mediated)
NCCU-Statement · NC · May 8, 2026 (EDT)
**HBCU PUBLIC STATEMENT (reporter-mediated).** Updates earlier silent NCCU entry, NCCU statement to ABC11 explicitly mentions FBI/CISA notification.
ABC11 Raleigh-DurhamPUC Chile (Pontificia Universidad Católica de Chile)Leak list
UC Chile · CL · Silent through May 8, 2026 (CLT)
**Second Chile entry in hub (after UAndes).** Top-ranked private R1 in Chile. Named on ShinyHunters leak list per local Chilean financial paper.
Diario FinancieroChilean university cluster (UDP / UNAB / UDD / U Autónoma)
CL-Cluster · CL · Silent through May 8, 2026 (CLT)
Chilean cluster expansion, Chile is the highest-density Canvas adoption country in Latin America.
Diario FinancieroTexas State University
TXST · TX · May 7, 2026 evening CDT
Public R2, HSI. Provost Pranesh Aswath email. CISO Dan Owen noted Texas State was NOT on ShinyHunters' affected list but acted out of caution.
The University Star (TXST)Saint Louis University
SLU · MO · May 7, 2026 · 9:52 PM CDT
Private R1, Catholic/Jesuit.
The University News (SLU)Fayette County Public Schools
FCPS-KY · KY · May 7 · 10 PM EDT through May 8 · 7 AM EDT
Lexington, KY. **9-hour outage window precisely documented**, useful telemetry data point. ~42K students.
FOX 56 LexingtonSouthern Methodist University
SMU · TX · May 7, 2026 · 8:12 PM CDT
Private R1 (Methodist). Specific exam reschedule date, second institution after JMU to publicly commit to a rescheduled finals date.
SMU IT Connect / SMU AwareUniversity of Southern California
USC · CA · May 7, 2026 evening PDT
Private R1, AAU. USC's main LMS is Brightspace for some schools, partial Canvas footprint.
LA Times via DNYUZUniversity of Illinois Urbana-Champaign
UIUC · IL · May 7, 2026 evening CDT
**Most aggressive accommodation posture**, postponed even classes NOT using Canvas. Public R1, Big Ten flagship.
WAND-TV / Chambana TodayUniversity of Oxford
Oxford · UK · May 8, 2026 (BST)
**Only major university observed to fully suspend Canvas access at university level.** Distinctive among UK responses. Replaces WebLearn.
Cherwell (Oxford student newspaper)Yale University
Yale · CT · May 7, 2026 evening ET
Ivy / private R1, AAU. Yale Daily News separately covered the breach noting delayed final grade deadline.
Canvas @ Yale + Yale Daily NewsUniversity of Galway
Galway · IE · May 8, 2026 (IST)
**First Ireland entry in hub.** Migrated Blackboard→Canvas 2023/24. ~19K students.
University of GalwayUniversity College Cork
UCC · IE · May 8, 2026 (IST)
Third Ireland entry. UCC Status Page issued formal 'Major incident' designation.
UCC Status PagePalomar College
Palomar · CA · May 7, 2026 · 3:57 PM PT
North San Diego County community college; precise 3:57 PM PT timestamp.
Palomar College, ATRCBaylor University
Baylor · TX · May 7, 2026 · 5:22 PM CT
Baylor noted Bear ID passwords were not stored on Instructure servers because of DUO MFA.
Baylor ITS NewsHouston Independent School District
HISD · TX · May 7, 2026 · evening CT
First major Texas K-12 district to publicly confirm impact and stand up a Canvas alternative (Google Sites failover for curriculum delivery).
KHOU 11 HoustonSt. Petersburg College
SPC · FL · May 7, 2026 · evening ET
Florida community college, independent confirmation that Instructure took Canvas globally offline May 7 (contradicts vendor 'fully operational' status copy).
St. Petersburg College NewsroomUniversity of California, Santa Cruz
UCSC · CA · May 7, 2026 afternoon PT
ANOMALY: UCSC was NOT on ShinyHunters' named list, yet pre-emptively disabled access. Voluntary precautionary stance.
UC Santa Cruz NewsUniversity of Notre Dame
ND · IN · May 7, 2026 evening EDT
Catholic R1. Cautious 'don't know yet' framing more honest than most peers.
The Observer (Notre Dame)Texas Tech University
TTU · TX · May 7, 2026 evening CDT
Public R1. RaiderCanvas explicitly named as breached.
KCBD LubbockUniversity of Copenhagen (Absalon)
KU-DK · DK · May 8, 2026 (CEST)
Canvas branded locally as 'Absalon'. **Major Nordic finding**, KU is one of Northern Europe's largest universities. Notified Datatilsynet (Danish DPA) on May 5.
Københavns Universitet NyhederUniversity of Witwatersrand (Wits)
Wits · ZA · Silent through May 8, 2026 (SAST)
First South Africa entry in hub. POPIA breach-notification regime applies.
Wits University Ulwazi LMSNTNU (Norwegian University of Science and Technology)
NTNU · NO · Week of May 5, 2026 (CEST)
Mid-Blackboard-to-Canvas migration during breach. 40,000 registered / 11,000 active users, unique numeric disclosure.
Techwatch.noUiT The Arctic University of Norway
UiT · NO · Week of May 5, 2026 (CEST)
Datatilsynet (Norwegian DPA)
Datatilsynet · NO · Week of May 5, 2026 (CEST)
**Second international regulator to issue a public statement** (after OAIC Australia). Provides Norway-wide denominator: 32 institutions / ~250,000 students. Sikt = Norwegian NREN.
DatatilsynetUniversity of Bergen / UiA / USN / Inland / Stavanger / Molde / NIH / HiOf / MF (Norway cluster)
NO-Cluster · NO · Week of May 5, 2026 (CEST)
Consolidated cluster entry covering 9 additional Norwegian institutions. Norway is the most comprehensively documented Nordic response per Sikt's coordination role.
Datatilsynet + multiple Norwegian institutional pagesEötvös Loránd University (ELTE)
ELTE · HU · May 7-8, 2026 (CEST)
**First Hungary entry in hub.** Canvas customer mid-migration to Moodle. ELTE is one of the few institutions to cite the breach as accelerating an LMS migration.
ELTE eLearningWits / University of the Witwatersrand (UPGRADE — public statement)
Wits-Active · ZA · Notified May 7; restored by May 8, 2026 (SAST)
**UPGRADES earlier 'silent' Wits status, now a public-statement entry.** Confirmed defacement victim: ShinyHunters posted extortion message inside Ulwazi itself. POPIA breach-notification regime applies.
ITWeb + The Citizen + News24American University in Cairo
AUC · EG · Silent through May 8, 2026 (EET)
**First Egypt entry in hub.** Mid-migration timing, Spring 2024 pilots, full transition still in progress when breach landed. Egypt has no general data breach notification law as of May 2026.
AUC Digital TransformationFlorida International University
FIU · FL · May 7, 2026 · 5:33 PM ET
University of Pennsylvania
Penn · PA · May 7, 2026 · 5:19 PM ET
Email signed by Vice Provosts Composto & Jordan-Sciutto and CISO Nick Falcone. ShinyHunters claims ~306,000 Penn affiliates affected, Penn's second ShinyHunters incident in 8 months.
The Daily PennsylvanianKean University
Kean · NJ · May 7, 2026 · 5:12 PM ET
Notable for omitting any mention of the hack/breach in the initial email, framed as 'scheduled maintenance.'
The Tower (Kean student paper)University of California, Irvine
UCI · CA · May 7, 2026 · 2 PM PT
UC system-wide takedown affected all 10 UC campuses simultaneously during finals.
New University (UCI)Morgan State University
Morgan · MD · May 7, 2026 evening EDT
**FIRST CONFIRMED HBCU PUBLIC STATEMENT** in the corpus, highest-priority gap-fill (R2 HBCU, Maryland's preeminent public urban research university). Dedicated 'Instructure Incident Communications' page.
Morgan State University Information TechnologyUniversity of California, San Diego
UCSD · CA · May 7, 2026 afternoon PT
Washington State University
WSU · WA · May 7, 2026 afternoon PDT
University of Houston
UH · TX · May 7, 2026 afternoon CDT
Public R1, HSI.
The Daily Cougar (UH)Seton Hall University
SHU · NJ · May 7, 2026 evening EDT (access restored ~11 PM)
Catholic private masters.
The SetonianKent State University
Kent · OH · May 7, 2026 evening EDT
Public R2, Ohio.
AOL / Ohio coverageUniversity of Houston-Downtown / Houston Community College
UH-D · TX · May 7, 2026 afternoon CDT
Public bachelors/masters, HSI. UH-D one of the most diverse 4-years in the US.
ABC13 HoustonOregon State University
OregonSt · OR · May 7, 2026 · 1:40 PM PDT
Public R1, land-grant. Disambiguate from Ohio State (already in hub).
Oregon State University TechnologyUniversity of Oregon
UO · OR · May 7, 2026 afternoon PDT
Public R1, AAU.
University of Oregon Service StatusUniversity of Toronto
UofT · CA · May 7, 2026 · 4:30 PM EDT
U15 leader explicitly declined comment. Quercus is UofT's Canvas brand. PIPEDA + Ontario FIPPA notification likely required despite silence.
The Varsity (UofT)University of Kansas
KU · KS · May 7, 2026 · 3:30 PM CDT
Public R1, AAU, Big 12.
University Daily KansanNorthwestern University
Northwestern · IL · May 7, 2026 afternoon CDT
Private R1, AAU, Big Ten.
The Daily NorthwesternUniversity of Chicago
UChicago · IL · May 7, 2026 afternoon CDT
ANOMALY: minimal public response from a major R1; flagged 'no-response-confirmed' for the public-statement audit.
CBS ChicagoNew Mexico State University
NMSU · NM · May 7, 2026 afternoon MDT
**Most aggressive 'do-not-click' posture** among R1/R2 publics. Public R2, HSI, land-grant.
NMSU Round UpTulane University
Tulane · LA · May 7, 2026 afternoon CDT
Private R1, AAU.
MyTulane / Tulane LMSNorthern Arizona University
NAU · AZ · May 7, 2026 afternoon MST
Public R2.
Arizona's Family / 12 NewsIowa State University
Iowa State · IA · May 7, 2026 afternoon CDT
Public R1, Big 12, land-grant (~30K students).
The Gazette (Cedar Rapids)University of Colorado Colorado Springs
UCCS · CO · May 7, 2026 · ~2:20 PM MT
Direct quote from UCCS OIT Services Professional Brock Stamper.
The Scribe (UCCS)Kansas State University
K-State · KS · May 7, 2026 · 3:20 PM CDT
Sent via K-State Alert system at 3:20 PM CDT, extremely brief 11-word emergency-style alert. Useful contrast to lengthy peer statements.
Kansas State CollegianUniversities of Wisconsin / UW–Madison
UW–Madison · WI · Outage began 3:10 PM CT, May 7, 2026
University of Iowa
Iowa · IA · May 7, 2026 · ~3:00 PM CT
ICON is the Iowa-branded name for Canvas. Outage struck during dead week before finals.
The Daily IowanUniversity of Washington Bothell
UWB · WA · May 7, 2026 · 1:00 PM PT
Branch campus of UW system; published on the Emergency Blog (typically reserved for safety incidents), notable framing.
UW Bothell Emergency BlogHillsborough County Public Schools
HCPS-FL · FL · May 7, 2026
8th-largest school district in the U.S. (~225K students).
WFLA TampaPinellas County Schools
PCS · FL · May 7, 2026
7th-largest district in Florida; Tampa Bay regional pair with HCPS.
Tampa Bay TimesUniversity of California, Los Angeles
UCLA · CA · May 7, 2026 afternoon PT
Public R1 / UC flagship. Bruin Learn = UCLA's Canvas tenant.
UCLA Office of the Chief Information Security OfficerUniversity of California, Davis
UC Davis · CA · May 7, 2026 · 1:00 PM PDT
Mississippi State University
MSU-MS · MS · May 7, 2026 · 3:00 PM CDT
**Most precise timestamp of any institutional statement** (specifies 3 PM detection). Public R1, SEC, land-grant.
Mississippi State University NewsroomUniversity of Tennessee, Knoxville
UTK · TN · May 7, 2026 afternoon EDT
Boston College
BC · MA · May 7, 2026 afternoon EDT
Catholic/Jesuit private R1.
The Heights (BC)University of Kentucky
UKy · KY · May 7, 2026 afternoon EDT
University of Minnesota
UMN · MN · May 7, 2026 afternoon CDT
Public R1, Big Ten/AAU.
Star TribuneUniversity of Washington (Seattle)
UW · WA · May 7, 2026 · 1:00 PM PDT
Public R1, AAU, Pac-12.
The Daily of the University of WashingtonUniversity of South Florida
USF · FL · May 7, 2026 afternoon EDT
Public R1 (Florida preeminent state university).
10 Tampa Bay (WTSP)Brown University
Brown · RI · May 7, 2026 · afternoon ET
Ivy-League impact during reading period; reporting paraphrased rather than direct vendor quote.
Brown Daily HeraldCharlotte-Mecklenburg Schools
CMS · NC · May 7, 2026
2nd-largest district in NC (~140K students).
WCNC CharlotteIndiana University
IU · IN · May 7, 2026 afternoon EDT
Public R1, Big Ten/AAU. Note: nearby Purdue does NOT use Canvas.
Indiana Daily StudentUniversity of New Mexico
UNM · NM · May 7, 2026 afternoon MDT
Public R1, HSI.
UNM IT AlertsWake County Public School System
WCPSS · NC · May 7, 2026
WCPSS, among NC's largest districts (~160K students), took the unusually aggressive step of fully disabling Canvas access rather than waiting for Instructure remediation.
ABC11 Raleigh-DurhamHong Kong University of Science and Technology
HKUST · HK · Silent through May 8, 2026 (HKT)
First Hong Kong entry in hub. HK PCPD breach-notification scheme is voluntary.
HKUST Canvas portalNational University of Singapore
NUS · SG · Silent through May 8, 2026 (SGT)
First Singapore entry in hub. NUS is a major SE Asia tier-1 institution.
NUS Canvas Transition pageCity University of Hong Kong
CityU · HK · Silent through May 8, 2026 (HKT)
Second HK entry.
CityU IT Services LMSHong Kong Polytechnic University
PolyU · HK · Week of May 7-8, 2026 (HKT)
**LARGEST SINGLE-INSTITUTION HONG KONG IMPACT: 42,000 USERS.** PolyU is one of 5 HK institutions PCPD-notified. Ironic timing: Canvas@PolyU soft-launched May 4, just days before the breach went public.
Dim Sum Daily HK + SCMPHong Kong cluster (5+ institutions, 72,571 affected)
HK-Cluster · HK · Week of May 7-8, 2026 (HKT)
**Hong Kong cluster, 72,571 affected total.** Upgrades earlier silent HKUST/CityU entries. PCPD voluntary breach-notification scheme triggered. Single largest non-US/Norway sector impact documented.
South China Morning Post + Hong Kong PCPDUniversiti Brunei Darussalam
UBD · BN · Silent through May 8, 2026 (BNT)
**First Brunei entry in hub.** Canvas adoption was originally a pandemic-era emergency decision.
UBD IT FAQDLSU / UP / UST (Philippines Canvas cluster — silent)
PH-Cluster · PH · Silent through May 8, 2026 (PHT)
Philippines Canvas cluster, Ateneo only one to issue a public advisory. UP is system-wide with 6 campuses.
Manila BulletinKeio University
Keio · JP · Silent through May 8, 2026 (JST)
**First Japan entry in hub.** ~33K students. Japan APPI breach-notification regime applies. All other Japanese tier-1 universities confirmed NOT Canvas.
Keio University ITCHanyang University
Hanyang · KR · Silent through May 8, 2026 (KST)
**First South Korea entry in hub.** PIPA breach-notification regime (one of Asia's strictest, 72h notification for breaches >1,000 records).
CIEE Study AbroadFlinders University (deadline extension)
Flinders-Deadline · AU · Week of May 7-8, 2026 (ACST)
**First South Australia entry in hub.** Joins JMU + Birmingham + SMU + Emory + ECU + ISU in explicit-deadline-extension cohort. New Adelaide University selected Canvas July 2024 but is pre-operational.
ACS Information AgeUniversity of Massachusetts Amherst
UMass Amherst · MA · May 7, 2026 (initial post May 3)
Notes a Turnitin/API key rotation side-effect.
UMass Amherst ITUniversity of Auckland
UoA · NZ · May 8, 2026 (NZST)
Most detailed published international notice. NZ Privacy Act 2020 notification likely triggered.
University of Auckland NewsAuckland University of Technology
AUT · NZ · May 8, 2026 (NZST)
Te Herenga Waka — Victoria University of Wellington
VUW · NZ · May 8, 2026 (NZST)
VUW operates Canvas under its 'Nuku' branding. VC Nic Smith on record.
VUW Digital SolutionsPasadena City College
PCC · CA · May 7, 2026
Mid-size urban California community college; explicit phishing-imposter warning is unique among CC responses.
Pasadena City College, Canvas Outage PageArizona State University
ASU · AZ · May 7, 2026
Clark County School District (Las Vegas)
CCSD · NV · May 7, 2026 (Thursday afternoon)
5th-largest U.S. K-12 district (~300K students). Proactively disabled Canvas access. Confirms April 25 incident-onset date matching NCDPI/Instructure timeline.
Fox 5 Vegas (KVVU)University of British Columbia
UBC · CA · May 7, 2026 (PDT)
Most aggressive 'do-not-login' advisory observed globally. BC PIPA + federal PIPEDA obligations apply.
UBC IT Status PageSimon Fraser University
SFU · CA · May 7, 2026 (PDT)
Portland Public Schools
PPS-OR · OR · May 7, 2026
Largest Oregon district (~44K students).
KGW News (NBC Portland)Beaverton School District
BSD-OR · OR · May 7, 2026
3rd-largest Oregon district (~39K students).
KGW NewsTigard-Tualatin School District
TTSD · OR · May 7, 2026
OR suburban Portland district (~12K students).
KGW NewsStanford University
Stanford · CA · May 7, 2026 (PDT)
Confirms Stanford on the affected list; specific Stanford-IT statement not yet located in indexed coverage.
Stanford DailySouthern California school districts (multiple)
S-CA-K12 · CA · May 7, 2026
Multi-district SoCal K-12 confirmation; LAUSD not impacted (Schoology), so this excludes the largest district.
ABC7 Los AngelesSpokane Public Schools
SPS · WA · May 7, 2026 (PDT)
~30K students. First confirmed Pacific NW K-12 district response.
FOX 28 SpokaneSan José State University
SJSU · CA · Week of May 4, 2026 · restored May 8 (PDT)
**AANAPISI + HSI gap-fill, first AANAPISI + HSI public-response page in the hub.** Public R2 (~36K students).
SJSU University Marketing & CommunicationsSan Francisco State University
SFSU · CA · May 7-8, 2026 (PDT)
AANAPISI + HSI. Public masters (~24K students). Operationally specific support routing (at@sfsu.edu, 415-405-5555).
SFSU Academic Technology CentralCalifornia State University, Northridge
CSUN · CA · May 7-8, 2026 (PDT)
HSI + AANAPISI. Public masters (~38K students). One of the largest HSI institutions in the US.
CSUN Alert, Instructure (Canvas) UpdateCalifornia State University, Long Beach
CSULB · CA · Finals week, May 7-8, 2026 (PDT)
HSI + AANAPISI (~40K students).
Long Beach Post quoting CSULB emailSonoma State University
SSU-CA · CA · Early May 2026 (PDT)
Public masters, HSI federally-designated (~6K students). 6th CSU campus public statement in hub.
Sonoma State NewsUtah State Board of Education
USBE · UT · May 7, 2026
State board response. Notable because Instructure is HQ'd in Salt Lake City. Utah AG silent on home-state vendor.
KUTV 2News (Katy Challis, USBE Director of Privacy)Granite School District
Granite-UT · UT · May 7, 2026
3rd-largest Utah district (~62K students).
ABC4 UtahDavis School District
Davis-UT · UT · May 7, 2026
2nd-largest Utah district (~73K students). Notable for vendor-data-minimization framing.
ABC4 UtahIdaho State University
ISU · ID · May 7, 2026 (MDT)
**Most aggressive academic accommodation** in the dataset, outright canceled all afternoon finals on May 7 rather than rescheduling.
Idaho State JournalNorman Public Schools
NPS-OK · OK · May 7, 2026
Only district to explicitly invoke a state student-privacy framework ('Oklahoma student data privacy standards'), a possible template for districts in the 38 states with student-privacy statutes. Replaces earlier shorter NPS entry.
OU DailyAustin Independent School District (BLEND)
AISD · TX · May 7, 2026 (CDT)
~73K students. Uses Canvas under brand 'BLEND.' Defacement HTML reportedly visible to parents and faculty before global takedown.
KUT News (Austin NPR)Conroe Independent School District
Conroe-ISD · TX · May 7, 2026 (CDT)
~70K students, Houston-area suburban.
FOX 26 HoustonPearland Independent School District
Pearland-ISD · TX · May 7, 2026 (CDT)
~21K students. **Notable for technical risk-mitigation detail**, Canvas messaging disabled and email-domain whitelist (.edu / .mil only), example of pre-existing controls that reduced exposure.
FOX 26 HoustonKaty Independent School District
Katy-ISD · TX · May 7, 2026 (CDT)
~95K students. Houston-area suburban; Canvas as primary LMS.
FOX 26 HoustonWichita Public Schools (USD 259)
USD 259 · KS · May 7, 2026 (CDT)
Largest KS K-12 district (~46K students). Cautious wait-and-see posture; contrast Galena KS (already in hub).
KSN WichitaIowa City Community School District
ICCSD · IA · May 7, 2026 (CDT)
Iowa K-12 (~14K students). Pairs with U Iowa / Iowa State.
The Gazette (Cedar Rapids)Oklahoma City Public Schools
OKCPS · OK · May 7, 2026 (CDT)
~33K students. Oklahoma's largest K-12 district. Tightens OK cluster (Norman PS + Galena KS already in hub).
News9 Oklahoma CityLincoln University of Missouri
Lincoln MO · MO · May 7, 2026 (CDT)
**HBCU gap-fill, first HBCU in Missouri.** Public HBCU, land-grant (~1,800 students). Differentiate from Lincoln U Pennsylvania.
KCURStephens College
Stephens · MO · May 7, 2026 (CDT)
Private women's-focused liberal arts college (~700 students). One of the smallest US private institutions to publicly acknowledge impact.
KCURUniversity of North Texas
UNT · TX · May 7, 2026 (CDT)
Public R1 (~46K students). Proactively disabled Canvas. Pairs with TWU response.
KERA NewsJames Madison University
JMU · VA · May 7, 2026
First documented US institution to formally postpone final exams (May 8 → May 13).
JMU Computing, Canvas OutageOrange County Public Schools
OCPS · FL · May 7, 2026
9th-largest U.S. district (~210K students).
Click Orlando (WKMG)Montgomery County Public Schools
MCPS-MD · MD · May 7, 2026
Largest Maryland district (~160K students). Among the first major Atlantic-coast districts to proactively disable Canvas.
The MoCo ShowVirginia Beach City Public Schools
VBCPS · VA · May 7, 2026
Largest Virginia district (~64K students). **Only known district to publicly cite state Fusion Center engagement**, only public hint of intel-community coordination.
WTKR News 3Charlottesville City Schools
CCS-VA · VA · May 7, 2026
**Most specific data-scope description in entire dataset**, confirms MFA worked as a partial mitigation: parent accounts (no MFA enforced) breached, staff/student accounts (MFA-protected) not breached.
29News (CBS-19 Charlottesville)York County School District 1 (Clover)
YCSD-1 · SC · May 7, 2026
Strongest 'data-minimization' defensive claim in the dataset. Possible model for parent-pacification messaging.
WCNC CharlotteRock Hill School District
RHSD · SC · May 7, 2026
Largest district in York County, SC (~17K students). One of only two SC K-12 districts publicly responding.
WCNC CharlottePort Byron Central School District
Port-Byron-NY · NY · May 7, 2026
Tiny upstate NY rural district (~700 students). **Only confirmed New York State K-12 district** to formally notify families, NYC DOE silence is correctly explained: NYC DOE uses Google Classroom, not Canvas.
Fingerlakes1.comIndiana colleges (multi-institution)
IN-Multi · IN · May 7, 2026
Multi-institution Indiana confirmation; IU and Purdue likely subset but not individually quoted.
WTHR IndianapolisAnne Arundel County Public Schools
AACPS · MD · May 7, 2026 (EDT)
5th-largest district in Maryland (~83K students). **Aggressive proactive Canvas shutdown**, joins WCPSS / Cherokee GA / Brevard FL pattern.
Fox News (citing AACPS)Cherokee County School District
CCSD-GA · GA · May 7, 2026
~42K students in GA exurbs. Took unusual aggressive step of fully stopping Canvas access. Explicit assurance grades, SSNs, financials not in Canvas, useful template for parent communications.
Cherokee County School District board postBrevard Public SchoolsLeak list
BPS-FL · FL · May 7, 2026
~73K students on FL Space Coast. **Named on ShinyHunters leak list** alongside Princeton, Cincinnati Public Schools, UC Berkeley, implies record exfiltration claim, not just LMS access disruption.
The Space Coast RocketKnox County Schools
KCS-TN · TN · May 7, 2026 (EDT)
94-school district (~60.5K students). Confirms unauthorized message visible to students/staff at login on May 7 (defacement event).
WBIR KnoxvilleForsyth County Schools
FCS-Forsyth · GA · May 7, 2026
~55K students fast-growing exurban district north of Atlanta. Tightens Atlanta-region cluster: Fulton + Cherokee + Forsyth all named.
Forsyth County SchoolsDartmouth College (Canvas down)
Dartmouth-Down · NH · May 7-8, 2026
Updates earlier Dartmouth silent entry, Canvas confirmed-down. Ivy League private R1.
The DartmouthUniversity of Miami
U Miami · FL · May 7-8, 2026 (EDT)
Private R1, AAU. Minimal statement, directed community to Instructure's status page rather than issuing UM-specific narrative.
The Miami HurricaneFlorida Gulf Coast University
FGCU · FL · May 7, 2026 (EDT)
Public R2 (~16K students). **Only institution listing 'home addresses' as potentially compromised**, most institutions list only names/emails/IDs/messages.
FGCU InsidePUC Minas (Pontifícia Universidade Católica de Minas Gerais)
PUC-Minas · BR · May 7, 2026 (BRT)
**FIRST BRAZIL ENTRY IN HUB, one of two Brazilian PUCs to issue public Canvas-breach statement.** Private R2 Catholic. Explicit phishing-warning framing.
PUC Minas Sala de ImprensaPUCPR (Pontifícia Universidade Católica do Paraná)
PUCPR · BR · May 7, 2026 (BRT)
**Second Brazilian Canvas tenant in hub.** Private R2 Catholic. Notably explicit 'no evidence of compromise of University data identified to date.'
PUCPR Nota OficialUniversity of Birmingham
Birmingham · UK · May 7-8, 2026 (BST)
**Most detailed UK Russell Group response.** Full institutional Canvas tenant. Issued explicit May 13 5 PM deadline extension, a deadline-change action like JMU + SMU.
University of Birmingham student intranetUniversity of Edinburgh
Edinburgh · UK · Week of May 7, 2026 (BST)
Hybrid LMS environment, Learn (Blackboard) is the primary VLE; Canvas powers Short Courses Platform only. Blast radius narrower than Oxford / Birmingham.
University of Edinburgh Information ServicesMunster Technological University
MTU · IE · May 7, 2026 (IST)
Second Ireland entry. Canvas across all 6 Cork/Kerry campuses (~18K students).
MTU Student Canvas + RTÉ News + Irish ExaminerUniversity of Oslo
UiO · NO · Notified May 5; confirmed affected May 7, 2026 (CEST)
First Norwegian entry in hub. Full Canvas tenant. Notified Datatilsynet (Norwegian DPA).
UiO For ansatteCornell University
Cornell · NY · May 6, 2026 · 4:20 PM ET
Posted by Weill Cornell ITS. Cornell reported Canvas remained operational locally.
Cornell ITS, Security AlertTechnische Universiteit Eindhoven
TU/e · NL · May 6, 2026 evening (CEST)
Ateneo de Manila University
Ateneo · PH · Week of May 5-7, 2026 (PHT)
**First Philippines entry in hub.** AteneoBlueCloud Canvas (Sept 2020 acquisition). Notable for explicit legal-counsel + data-protection-officer activation language. NPC (Philippine National Privacy Commission) breach-notification applies.
Ateneo de Manila University AdvisoriesUniversiteit van Amsterdam
UvA · NL · May 6, 2026 (CEST)
GDPR Art. 33 notification to Autoriteit Persoonsgegevens (Dutch DPA) confirmed. UvA among 7 Dutch research universities individually named by Instructure. Coordinated response routed via SURF and Universiteiten van Nederland (UNL).
UvA NieuwsberichtUniversity of Nevada, Reno
UNR · NV · May 6, 2026
Most prominent president-level public warning tied to the incident. Brian Sandoval (former NV Governor) named on record.
UNR President's Messages (Brian Sandoval)Texas A&M University System (System-level CISO advisory)
TAMUS · TX · May 6, 2026 (CDT)
**System-level advisory** covering all 11 TAMUS member institutions including TAMU College Station. Separate from TAMU-Corpus Christi's individual statement (already in hub). Deflective framing: 'not directed at TAMUS' or any of its institutions.
Texas A&M System Cybersecurity OfficeNew Hanover County Schools
NHCS · NC · May 6, 2026
Coastal NC district (~25K students). Most thorough superintendent-signed statement; references federal law enforcement.
WECT (Superintendent Christopher Barnes)Wake Forest University
WFU · NC · May 5-6, 2026 (EDT)
Private R2. Measured update notes Canvas 'remains available' rather than offline.
Inside WFUEmory University
Emory · GA · May 6, 2026 (EDT)
Private R1, AAU. **Rare 'we cannot independently verify vendor claims' framing.** 7-day grade-deadline extension. Distinctive among private R1 responses.
Emory News CenterUniversity of Iceland (Háskóli Íslands)
HÍ · IS · May 6, 2026 (GMT)
**First Iceland entry in hub.** Full Canvas tenant since fall 2020. Icelandic press characterized incident as 'attack at the worst possible time' (exam period).
Morgunblaðið (mbl.is)University of Liverpool
Liverpool · UK · May 6, 2026 (BST)
Russell Group university; second confirmed UK Russell Group response (after Manchester). UK GDPR Art. 33 ICO notification confirmed.
University of Liverpool NewsVrije Universiteit Amsterdam
VU · NL · May 6, 2026 (CEST)
Erasmus Universiteit Rotterdam
EUR · NL · May 6, 2026 (CEST)
Tilburg University
TiU · NL · May 6, 2026 (CEST)
Universiteit Maastricht
UM-NL · NL · May 6, 2026 (CEST)
Universiteiten van Nederland (UNL collective)
UNL · NL · May 6, 2026 (CEST)
Dutch sector-level (NL) collective statement. NL Times reports 44 Dutch educational institutions (incl. hogescholen and a small number of secondary schools) impacted in total. SURF coordinating role explicit.
Universiteiten van NederlandAutoriteit Persoonsgegevens (Dutch DPA)
AP-NL · NL · Notifications filed week of May 4-6, 2026
**Dutch DPA is the FIRST regulator in our archive confirmed to have received breach notifications**, breaking the ICO/OAIC/NCSC public-silence pattern. Under GDPR a controller-side breach affecting 7+ institutions will likely produce a public AP statement within 2-4 weeks.
Universiteiten van Nederland (confirms AP notifications)Swedish University of Agricultural Sciences
SLU · SE · Approximately May 6, 2026 (CEST)
Specialized agricultural / forestry / veterinary research university.
SLU NewsAalto University Executive Education
Aalto EE · FI · May 6, 2026 (EEST)
First Finnish institution. Notified Tietosuojavaltuutettu (Finnish Data Protection Ombudsman). Confirms April 25 intrusion onset / April 29 detection / containment timeline.
Aalto EE NewsroomUniversity of Sydney
USYD · AU · May 6, 2026 (AEST)
Australia's NDB scheme under Privacy Act 1988 likely triggers OAIC notification; 2022 amendments raised maximum penalties to AU$50M / 30% domestic turnover.
University of Sydney NewsFresno State (California State University, Fresno)
Fresno State · CA · May 5, 2026 (PDT), earliest confirmed CSU campus disclosure
**HSI** (federally-designated). Public masters (~24K students). **Earliest CSU campus-specific disclosure (May 5)**, earlier than the system-wide May 7 message.
Fresno State Canvas Incident pageBoise State University
BSU · ID · May 5, 2026
University of Wisconsin–Milwaukee
UWM · WI · May 5, 2026
Unique reassurance: 'UWM does not collect student ID numbers... in Canvas.'
UWM Information TechnologyUniversiteit Twente
UT-NL · NL · May 5, 2026 (CEST)
Most operationally specific Dutch statement: discloses key-rotation, monitoring uplift, explicit data minimisation.
University of Twente newsWindesheim University of Applied Sciences (NL hogeschool)
Windesheim · NL · Week of May 5, 2026 (CEST)
Represents the broader 44-institution Dutch impact figure. Other named hogescholen: Hague University of Applied Sciences, Deltion College, Grafisch Lyceum Haarlem.
NL TimesKTH Royal Institute of Technology
KTH · SE · Approximately May 5, 2026 (CEST)
Sweden's premier technical university. IMY (Swedish DPA) notification confirmed via Sunet (Swedish NREN). Cross-Nordic notification cascade includes KI, Lund, Uppsala, SLU.
KTH Student NewsLund University
Lund · SE · Approximately May 5, 2026 (CEST)
Sweden's oldest university (~46K students). IMY notification confirmed via Sunet.
Lund University MedarbetarwebbenKarolinska Institutet
KI · SE · Approximately May 5, 2026 (CEST)
Top European medical research university.
Karolinska Institutet Operating InfoUppsala University
Uppsala · SE · Approximately May 5, 2026 (CEST)
Sweden's oldest university by founding date (1477). Reconstructed from Cybernews/IDM cross-reference.
Uppsala University Student PagesWayzata Public Schools
Wayzata · MN · May 4, 2026
12,000-student district in western Minneapolis suburbs; reportedly one of the first U.S. K-12 districts to formally notify parents, three days before mass-defacement event.
FOX 9 Minneapolis-St. PaulClemson University
Clemson · SC · May 4, 2026 (EDT)
**Earliest US public university notice**, May 4, three days before the May 7 defacement. Public R1, ACC, land-grant.
Clemson CCIT NewsUniversity of Technology Sydney
UTS · AU · May 5, 2026 (AEST)
Notably names 'relevant Australian authorities', implies OAIC and ACSC engagement.
UTS NewsRutgers University
Rutgers · NJ · May 4, 2026
University of Manchester
UoM · UK · May 4, 2026 (BST)
Earliest dated UK Russell Group acknowledgement. UK GDPR Article 33 ICO notification clock expired ~May 7.
University of Manchester Student NewsUniversity of Melbourne
UniMelb · AU · Week of May 4, 2026 (AEST)
Migrated from Blackboard to Canvas in 2023, high exposure.
University of Melbourne CybersecurityFulton County Schools
FCS-GA · GA · Initial security update April 27, 2026 · families notification May 7
Largest Georgia district (~90K students). **Critical timeline anomaly:** Fulton's initial security update was posted April 27, five days BEFORE Instructure's May 1 public disclosure, suggesting Instructure quietly notified some K-12 customers under NDA early.
Fox 5 AtlantaHarvard University
Harvard · MA · May 7-8, 2026
HUIT spokesperson Tim Bailey to The Harvard Crimson; bracketed text reflects how the Crimson stitched the verbatim phrases into a sentence.
Harvard CrimsonPrinceton University
Princeton · NJ · May 6-7, 2026
Dean of the College Michael Gordin separately emailed instructors with the gradebook-download guidance (per Daily Princetonian).
Princeton OIT, Instructure Security Incident UpdateColumbia University
Columbia · NY · May 6, 2026 or later
Columbia brands Canvas as 'CourseWorks.'
Columbia Office of Public AffairsDuke University
Duke · NC · May 6, 2026 · Wednesday evening ET
Email from CISO Nick Tripp to Duke faculty and students.
The Duke ChroniclePennsylvania State University
Penn State · PA · May 7, 2026, finals week
Outage hit during finals week as faculty tried to enter grades before commencement. The login page reportedly displayed: 'ShinyHunters has breached Instructure (again).'
Penn State NewsLiberty University
Liberty · VA · May 7, 2026
Explicitly committed to deadline extensions.
WSLS-10Virginia Tech
VT · VA · May 7, 2026
University of Virginia
UVA · VA · May 5-7, 2026
Unlike many peers, UVA reported Canvas remained operational locally throughout the incident.
UVACanvasVirginia Commonwealth University
VCU · VA · May 7, 2026
University of Maryland, College Park
UMD · MD · May 7, 2026 · Thursday afternoon
Attributed to UMD's Division of Information Technology by The Diamondback.
The DiamondbackUniversity of Michigan
U-M · MI · May 7, 2026
Texas A&M University–Corpus Christi
TAMU-CC · TX · May 7, 2026
Notably escalated to 'CODE BLUE', campus emergency-tier alert classification, unusual for an LMS outage.
TAMU-CC Campus AnnouncementsUniversity of Texas at Austin
UT Austin · TX · May 5-7, 2026
UT Austin reported Canvas was operating normally locally.
UT Austin Enterprise TechnologyUniversity of Missouri System
UM System · MO · May 7, 2026
Direct quote from UM spokesman Christopher Ave. Affected all four UM System campuses (MU, UMKC, UMSL, Missouri S&T).
KBIA / KCUROklahoma State University
OSU · OK · May 6, 2026 · afternoon CT
Outage hit during OSU finals week.
The O'CollyUniversity of Oklahoma
OU · OK · May 7, 2026 · Thursday afternoon CT
Email co-signed by Senior VP and Provost André-Denis Wright and Senior VP/OU Health Provost Gary Raskob.
OU DailyUniversity of California (system-wide)
UC · CA · May 6, 2026
System-wide statement covering all 10 UC campuses. ShinyHunters specifically claimed 600,000+ UC Berkeley records.
UCnetUC Berkeley
Berkeley · CA · Early May 2026
Berkeley brands Canvas as 'bCourses.' ShinyHunters specifically claimed 'more than 600,000' Berkeley records.
UC Berkeley Information Security OfficeCalifornia State University Chancellor's Office
CSU · CA · Early May 2026
23-campus regional public system response. Names six campuses confirmed affected: Humboldt, Long Beach, East Bay, Dominguez Hills, Bakersfield, Channel Islands.
CSU Learning Technology ServicesCalifornia Community Colleges Chancellor's Office
CCCCO · CA · Early May 2026
System-wide statement covering 116 California community colleges.
Contra Costa Advocate (quoting Chancellor Sonya Christian email)Peralta Community College District
Peralta · CA · May 4-5, 2026
Bay Area 4-college district. Among the earliest CCD responses.
Peralta CCDLong Beach City College
LBCC · CA · Early May 2026
LBCC stood up a dedicated /securityincident page with toll-free hotline.
LBCC Security Incident NoticeOrange Coast College
OCC · CA · May 7, 2026
Notable for downplaying as a hosting issue rather than a cyberattack.
Coast Report Online (OCC student paper)College of the Canyons
COC · CA · Reported May 6, 2026
Direct quote from COC spokesperson Eric Harnish.
Hometown StationSacramento State University
Sac State · CA · May 7, 2026
Sac State IRT relayed the CSU Chancellor's Office message to students.
The State HornetUniversity of Utah
Utah · UT · May 7, 2026
Utah explicitly distinguished its own systems from Instructure's.
@theUUniversity of Colorado Boulder
CU Boulder · CO · May 4, 2026
Colorado State University System
CSU System · CO · May 6, 2026 (updated May 7)
Mt. San Antonio College
Mt. SAC · CA · May 7, 2026
Union County Public Schools (NC)
UCPS-NC · NC · May 7, 2026
Largest of the Charlotte suburban NC districts named alongside CMS, Cabarrus, Catawba, Kannapolis.
WCNC CharlotteDurham Public Schools
DPS-NC · NC · May 7, 2026
Major Triangle-area NC district (~32K students).
CBS17 RaleighChapel Hill-Carrboro City Schools
CHCCS · NC · May 7, 2026
NC Triangle K-12 district adjacent to UNC Chapel Hill.
CBS17 RaleighCumberland County Schools
CCS-NC · NC · May 7, 2026
Fayetteville-area NC district (~50K students).
CBS17 RaleighNorman Public Schools
NPS-OK · OK · May 7, 2026
Oklahoma K-12 district, tight geographic clustering with OU's R1 disclosure.
OU DailyGalena USD 499
USD 499 · KS · May 7, 2026
Small Kansas K-12 district, example of mid-/small-tier district notifying parents proactively.
Galena USD 499Broward County Public Schools
BCPS · FL · As of May 8, 2026
6th-largest U.S. district (~260K students); on the list but no formal district statement located.
BleepingComputer (named in leak list)Federal & Sector-Consortium Silence Tracker
The defining federal-response feature of this incident has been near-total silence from every agency, congressional committee, and sector consortium with jurisdiction. The list below is the verified-silent set as of May 8, 2026. Each row will be promoted to a confirmed response the moment a public product is issued.
CISA
no advisory / KEV addition
FBI
declined to comment (ABC11)
FTC
no COPPA enforcement filing
ED PTAC
no FERPA breach bulletin
FSA (Title IV)
no Dear Colleague Letter
ONCD / White House
no statement
Senate HELP
no Cassidy/Sanders letter
Senate Commerce
no Cruz hearing notice
Senate HSGAC
no Peters letter
House Ed & Workforce
no Walberg statement
House Homeland Sec.
no Garbarino statement
House E&C
no Pallone statement
Markey-Cassidy COPPA 2.0
no joint letter
Utah AG (home state)
no statement
California AG Bonta
no Instructure investigation
NY AG James
no Instructure investigation
EDUCAUSE / HEISC
no public bulletin
REN-ISAC
no public advisory
NACUA
no NACUANOTES on FERPA timing
AAU
no joint statement (8 Ivies affected)
AAUP
no faculty-side commentary
UK ICO
no public advisory
Australian OAIC
no public statement
Dutch AP
received 7 notifications; no public advisory yet
Swedish IMY
received Sunet notifications; silent
Danish Datatilsynet
received KU notification; silent
Finnish DPA
received Aalto EE notification; silent
Cutoff timestamp: May 8, 2026 · end of day ET. The first agency or committee to break silence resets this panel.
Decision-Maker Checklist
For OIT, Emergency Management, Provost, Registrar
- 1Subscribe to component-level alerts at status.instructure.com and confirm at least two staff members are subscribed.
- 2Independently verify your tenant URL (canvas.<institution>.edu) and check it against the vendor status page, local availability has varied.
- 3**Rotate any API keys** shared with Canvas integrations (Turnitin, Pearson, Top Hat, Zoom). UMass Amherst publicly noted a Turnitin key-rotation side-effect.
- 4**Communicate to faculty about phishing risk.** TAMU-CC reports already receiving fraudulent messages claiming to restore Canvas access. Multiple institutions warn against clicking links in unsolicited messages.
- 5If Canvas is offline, **publish a customer-facing summary on your OIT status page** even if Instructure has not, your community looks to you first.
- 6**Coordinate with the registrar BEFORE announcing exam postponements** that affect grade-submission deadlines (JMU model: explicit new exam date; Liberty model: open-ended commitment to extensions).
- 7**Ask instructors to download Canvas gradebook copies** as a precaution (Princeton's Dean Gordin model). Quizzes and submissions may also be exportable from the API while available.
- 8Consider a faculty-facing FAQ: how to extend Canvas due dates, accept email submissions, run paper-based exam protocols.
- 9Capture screenshots of vendor status messages and your own communications for post-incident review and any FERPA breach-notification documentation.
- 10If your institution is in active legal review for FERPA notification: the data exposed reportedly includes names, email addresses, student ID numbers, and Canvas messages, discuss with general counsel.
- 11**Track the litigation.** Multiple federal class actions were filed by late May 2026 (several in the District of Utah, plus an S.D.N.Y. case naming owner KKR); affected institutions should preserve incident records and coordinate with general counsel on potential discovery and state breach-notification obligations.
Primary Sources
vendor-status
Instructure Status Page
Authoritative incident timeline from Instructure. Subscribe to component-level updates.
vendor-status
Instructure Status — Incident History
Archive of every status post; primary timestamp source for vendor-side timeline.
vendor-trust
Instructure Trust Center
Security, compliance, and incident-response posture.
vendor-blog
Instructure 'Update on Security Incident'
Instructure's blog post (originally about September 2025 Salesforce incident; same threat actor).
vendor-social
Canvas LMS on X (@CanvasLMS)
Vendor's public X handle for service announcements.
vendor-social
Instructure on X (@Instructure)
Corporate X handle.
vendor-press
Instructure News & Press
Official statements and press releases.
News Coverage
- ↗BleepingComputer — Instructure confirms data breach, ShinyHunters claims attackAnchor confirmation piece.
- ↗BleepingComputer — Canvas login portals hacked in mass ShinyHunters extortion campaignDefacement campaign technical details (HTML injection, ~30-min visibility).
- ↗BleepingComputer — Hacker claims data theft from 8,800 schoolsShinyHunters claim quantification.
- ↗DataBreaches.net — ShinyHunters Hacks Instructure Again
- ↗TechCrunch — Hackers deface school login pages after claiming another Instructure hackDefacement coverage with verbatim ShinyHunters message.
- ↗TechCrunch — Hackers steal students' data during breach
- ↗The Record — Educational company Instructure reports cyber incident
- ↗SecurityWeek — Instructure discloses data breachCISO Steve Proud verbatim.
- ↗Inside Higher Ed — 'PAY OR LEAK': Hackers Target Big Higher Ed Vendor
- ↗K-12 Dive — Instructure confirms cybersecurity incidentExplicitly lists Instructure response actions.
- ↗CNN — Canvas hack strands college students during finals week
- ↗Government Technology — Instructure investigating cyber attack
- ↗Times Higher Education — Personalised phishing attacks likely after global Canvas hack
- ↗Hackread — ShinyHunters Instructure Canvas LMS and Vimeo BreachesLinks the Vimeo + Instructure campaign.
- ↗The Register — ShinyHunters claims dump puts 119K Vimeo emails in the wildConcurrent campaign analog (Snowflake/BigQuery via stolen tokens).
- ↗TechRadar — Top universities among victims named in Canvas data breach
- ↗Malwarebytes — Millions of students' personal data stolen
- ↗WRAL — Hacker group disables Canvas for NC students, demands ransomNCDPI confirmed receipt of breach notification.
- ↗Daily Californian — UC Berkeley Canvas 600K records claim
- ↗Daily Pennsylvanian — Over 300,000 Penn users affected
- ↗Duke Chronicle — Duke among 9,000 schools affected
- ↗Harvard Crimson — Harvard Canvas Site Goes Down
- ↗KBIA / KCUR — UM System and ~9,000 Canvas schools
- ↗TheNextWeb — Largest education data breach was an attack on a vendor
- ↗Chimicles Schwartz Kriner & Donaldson-Smith — class-action investigationFirst publicly announced class-action investigation.
Open Questions
Items the maintainer cannot independently confirm against a primary source. Promoted to Confirmed Facts only when verified.
- ?**Resolved: initial access vector.** The May 2026 production-side entry point was the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid tenants; the September 2025 Salesforce-side compromise provided the targeting foothold. CrowdStrike (not Mandiant) served as the forensic IR partner and reported no evidence of system-level access, malware, or credential theft. No CVE was assigned because the failure was configuration-class, not a software defect.
- ?**Resolved: did ShinyHunters publish after the May 12 deadline?** No. The May 12, 2026 deadline passed without a public data dump; ShinyHunters delisted Instructure from its leak site after the May 11-12 settlement and 'shred log' destruction claim. External verification of actual deletion remains impossible.
- ?**Resolved: exam/deadline accommodations cascaded.** Numerous institutions adjusted finals, including JMU (exams to May 13), Emory (+7 days on grade submission), East Carolina (grade deadline to May 13), Idaho State (afternoon finals canceled May 7), Liberty (open-ended extensions), and SMU (Friday exams to Sunday May 10).
- ?**Open: the ransom amount and whether Instructure paid.** Instructure has not disclosed any dollar figure and has not explicitly stated it 'paid a ransom,' framing the outcome as an 'agreement' yielding 'digital confirmation of data destruction.' Some outlets reported an unconfirmed ~$10 million figure. The exact terms remain undisclosed.
- ?**Open: no IOCs published.** No CISA, MS-ISAC, REN-ISAC, or commercial CTI vendor published file hashes, IPs, or domain indicators of compromise. Detection guidance remained behavioral (anomalous Developer Key creation, OAuth token issuance, and Canvas Data 2 / Beta export volumes).
- ?**Open: whether SSO / IdP endpoints were compromised.** Multiple universities (Boise State, Baylor) emphasized that Canvas does not hold primary credentials due to institutional SSO/SAML, and no evidence of IdP compromise was reported. Not affirmatively closed by a vendor statement.
- ?**Open: CIRCIA and state breach-notification compliance.** It remains unclear whether Instructure or downstream districts filed under the 72-hour CIRCIA disruptive-incident rule, and ClassAction.org/Inside Higher Ed reported Instructure may not have notified state AGs within statutory windows, a potential additional regulatory exposure.
- ?**Open: FERPA breach-notification outcome.** The Department of Education's Student Privacy Policy Office / PTAC requested information from Instructure but had not issued a public finding; whether Canvas messages and student ID numbers trigger formal FERPA breach obligations across affected institutions is unresolved.
- ?**Open: litigation and regulatory outcomes.** Well over a dozen federal class actions were pending (with KKR named in at least one S.D.N.Y. case) with no JPML consolidation order, and no state AG, FTC, or international DPA enforcement action had concluded at the time of this archived writing.
Methodology
- Primary Source First
- Every claim on this page links to a primary source. Vendor status posts, university OIT pages, official emails, press releases, and verified social-media posts qualify. Secondary news coverage is welcome but tagged separately.
- Honest About Gaps
- Items that the maintainer cannot independently verify against a single source are kept in the Open Questions section rather than promoted to Confirmed Facts. Where a quote was reconstructed from search-result snippets rather than a fetched archive page, isVerbatimConfirmed is set to false.
- Update Cadence
- This record was maintained continuously while the incident was active and is now an archived retrospective. It will be updated only if litigation, regulatory, or Congressional outcomes are confirmed. Last-updated timestamps reflect actual maintenance activity, not auto-generated build times.
- Scope
- US colleges and universities only, consistent with the National Campus Alert Archive's mission. International institutions affected by the same vendor incident are out of scope here but may be linked.
- Submit Tip
- If your institution has issued an alert, posted to an OIT status page, or extended deadlines and is not yet listed below, please send a tip to the maintainer.
Hub maintained as part of the Campus Alert Archive. Page rebuilt continuously as primary sources are confirmed. Last data update: June 2026.