Skip to content
Campus Alert Archive
RESOLVED · Resolved (archived retrospective). Instructure / ShinyHunters settlement confirmed May 11-12, 2026; Canvas restored; litigation and a Congressional inquiry continue.

This is a concluded retrospective. ShinyHunters breached Instructure via the Free-For-Teacher (FFT) account program, first intruding April 25, 2026. Instructure detected the intrusion April 29 (a 4-day dwell), disclosed it publicly May 1, and declared the incident 'contained' on May 2. That containment claim was invalidated on May 7, when ShinyHunters defaced roughly 330 Canvas login portals via HTML injection and reset its leak deadline to May 12; Instructure took Canvas offline globally and then restored it late on May 7. On May 11-12 Instructure announced it had reached an agreement with the threat actor and 'received digital confirmation of data destruction (shred logs),' stating that no customers would be extorted as a result of the incident. The ransom amount was never officially disclosed (some outlets cited an unconfirmed ~$10 million figure); ShinyHunters delisted Instructure from its leak site, and the May 12 deadline passed with no public data dump. ShinyHunters had claimed ~3.65 TB covering ~275 million students, teachers and staff across roughly 8,800-9,000 institutions worldwide; Instructure never corroborated those totals and characterized the exposed data as names, email addresses, student ID numbers and Canvas Inbox messages, with no evidence that passwords, government IDs or financial data were taken. CEO Steve Daly published the first CEO-named apology on May 11. House Homeland Security Chair Andrew Garbarino opened a Congressional inquiry the same day, demanding a briefing by May 21. Federal Student Aid issued a Title IV technology-security alert on May 12. By late May, plaintiffs had filed well over a dozen federal class actions (early reporting counted at least seven in D. Utah plus one in S.D.N.Y. naming owner KKR; later reporting cited roughly 18 suits), with no JPML consolidation order at the time of this writing. Security experts caution that shred-log 'destruction' cannot be externally verified and that the PowerSchool precedent shows paying does not guarantee against later district-level re-extortion.

Last updated

June 2026

Incident Retrospective

Canvas / Instructure Cybersecurity Incident

A finalized retrospective on the April-May 2026 ShinyHunters breach of Instructure (Canvas LMS): primary sources, a closed vendor timeline, the settlement and Congressional aftermath, and an archived tracker of how US colleges and universities responded during finals week.

How it concluded · key developments

  • **Settlement, Instructure announces agreement with ShinyHunters May 11-12**, one day before the threat actor's May 12 leak deadline. Vendor received 'digital confirmation of data destruction (shred logs)' and states 'no Instructure customers will be extorted as a result of this incident.' Ransom amount undisclosed. ShinyHunters delisted Instructure from its dark-web leak site.
  • **CEO Steve Daly publishes apology blog post May 11**, first CEO-named statement of record. 'I'll start where I should: with an apology... You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that.' Through May 8 evening, all corporate communication had been from CISO Steve Proud or unnamed spokespeople.
  • **House Homeland Security opens inquiry May 11**, Chair Andrew Garbarino sends letter to CEO Daly demanding briefing by May 21. First Congressional action of record. Senate HELP, Commerce, HSGAC, Intel; House E&C, Ed & Workforce; Markey-Cassidy COPPA 2.0; all state AGs remain silent.
  • **FBI Facebook advisory May 8**, first US federal public communication on the breach. 'Threat actors often exaggerate or fabricate their access.' Signals federal skepticism toward the 275M-record claim and discourages individual-institution ransom payment.
  • **Australia's OAIC publishes regulator advisory**, first international regulator public statement; advises affected users to escalate to OAIC after 30 days. UK ICO / Dutch AP / Swedish IMY / Danish Datatilsynet / Finnish DPA / Canadian OPC all remain silent despite receiving GDPR-equivalent notifications.
  • **CrowdStrike is the forensic IR partner (not Mandiant)**, May 8 CrowdStrike readout: 'no evidence that the threat actor had system-level access, installed malware nor obtained login credentials, nor that any additional data was extracted during the renewed activity on May 7.' Mandiant's CTO Carmakal provided public commentary only.
  • **Free-For-Teacher accounts confirmed as initial-access vector** (Bitdefender Advisory), April 25 intrusion, April 29 detection (4-day dwell). FFT accounts ran on the same backend as paid institutional tenants but allowed account creation without institutional verification.
  • **Litigation aftermath:** by late May 2026, multiple federal class actions had been filed. Early reporting counted at least seven suits, six in the U.S. District Court for the District of Utah plus one in the S.D.N.Y. naming owner KKR; later reporting cited roughly 18. No JPML consolidation order had issued at the time of this archived writing.
  • **Archived institutional tracker:** the responses below span 50 US states + DC plus international institutions, including 11 HBCUs (Morgan State the only public statement), 8 tribal colleges, and 13 Dutch + 5 Swedish + 1 Danish + 1 Finnish universities tied to a cross-European DPA notification cascade, alongside 50+ K-12 districts. This list is a point-in-time snapshot captured during the incident and is preserved as a historical record.

What we know in 30 seconds

  • **ShinyHunters has claimed responsibility**, the same financially motivated group behind concurrent breaches at Vimeo (119K user emails), Salesforce, AT&T, McGraw-Hill, and a prior September 2025 social-engineering breach of Instructure's Salesforce instance.
  • **Instructure took Canvas offline globally on May 7** after defacement HTML appeared on roughly 330 login portals reading 'ShinyHunters has breached Instructure (again).' Canvas was restored late the same day. The outage landed in finals week: JMU delayed final exams to May 13, Liberty committed to deadline extensions, and Idaho State outright canceled afternoon finals.
  • **Data exposed.** Instructure characterized the exposed data as names, email addresses, student ID numbers, and Canvas in-platform messages, and stated no evidence that passwords, dates of birth, government IDs, or financial information were involved.
  • **Scale claims (never corroborated by Instructure):** ShinyHunters claimed 3.65 TB of data covering ~275 million students, teachers and staff across roughly 8,800-9,000 schools (BleepingComputer cited the actor's specific figure of 8,809 institutions). The actor named UC Berkeley (~600,000 records) and Penn (~306,000 affiliates) by name. The FBI publicly cautioned that 'threat actors often exaggerate or fabricate their access,' and Instructure never confirmed these totals.
  • **The federal response arrived late.** For the first week after disclosure, no U.S. federal agency issued a Canvas-specific product: no CISA advisory, no FBI Flash, no PTAC FERPA bulletin, no FTC announcement under the April 22 2026 COPPA Rule. The first federal communications came May 8 (an FBI Facebook advisory) and May 12 (a Federal Student Aid Title IV technology-security alert); House Homeland Security opened a formal inquiry May 11.
  • **Higher-ed sector consortia were largely silent through the first week.** REN-ISAC (higher-ed analog to MS-ISAC), EDUCAUSE, NACUA, AACRAO, NACUBO, AAU, APLU and AGB issued no public advisories in the days after disclosure. Member-only listserv traffic almost certainly existed, but little was canonical for non-members to cite. K12 SIX was the only sector ISAC voice on the public record (via a newsletter quoted by K-12 Dive).
  • **Instructure is privately held, which shaped the litigation.** KKR + Dragoneer closed a $4.8 B take-private at $23.60/share on Nov 13 2024 (Form 15-12G filed Nov 25 2024), so no SEC Item 1.05 8-K applied and no securities class action was viable. The exposure instead landed in consumer class actions: by late May 2026 plaintiffs had filed multiple federal suits, several in D. Utah plus one in the S.D.N.Y. naming owner KKR (later reporting cited roughly 18), with no JPML consolidation order at the time of this writing.
  • **Phishing risk was elevated during the outage.** TAMU-CC reported 'already receiving reports of fraudulent messages claiming to be able to get you back into Canvas,' and many institutions warned community members against clicking links in unsolicited messages and to navigate directly to their tenant URL instead.

Confirmed Facts

59 verified

Public-facing service disruptions affecting tools relying on API keys surfaced on **April 30, 2026** (Instructure's security team had detected the underlying intrusion on April 29; see the dwell-time fact below). Instructure then publicly disclosed the incident on **May 1, 2026** (~4:30 PM Mountain Time / 6:46 PM ET) via a customer letter from CISO Steve Proud describing 'a cybersecurity incident perpetrated by a criminal threat actor.'

BleepingComputer

Initial impact: Canvas Data 2 and Canvas Beta were taken offline for maintenance; tools relying on API keys experienced disruption. Canvas itself remained operational at most tenants until May 7.

K-12 Dive

**ShinyHunters has claimed responsibility.** The group listed Instructure on its leak site on May 3, 2026 and is the same actor behind a prior September 2025 social-engineering breach of Instructure's Salesforce instance, plus contemporaneous breaches at Vimeo, Salesforce, AT&T, Google, McGraw-Hill, and others.

DataBreaches.net

**Compromised data reportedly includes** names, email addresses, student ID numbers, and Canvas in-platform messages between users. Instructure has stated no evidence that passwords, dates of birth, government identifiers, or financial information were involved, though investigation remains ongoing.

U-M Safe Computing

**Threat-actor scale claims (unverified by Instructure):** ShinyHunters claims ~3.65 TB / ~275 million students-teachers-staff records / ~9,000 schools. BleepingComputer reported the actor's specific count as 8,809 schools.

BleepingComputer

Instructure's containment / response actions: revoking privileged credentials and access tokens, deploying security patches, rotating keys 'even though there is no evidence they were misused', increased monitoring, reissuing application keys with timestamp-based naming, and requiring customer re-authorization of integrations.

K-12 Dive

**On May 7, 2026 ~3:30 PM (afternoon CT)**, ShinyHunters defaced Canvas customer login portals via HTML injection, visible for ~30 minutes before takedown. Defacement carried text: 'ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some "security patches."' Demanded schools 'consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.' Set deadline: 'You have till the end of the day by 12 May 2026 before everything is leaked.'

TechCrunch

**Three institutional response postures have emerged**: (1) Canvas remained operational locally, UVA, Cornell, UT Austin, CU Boulder; (2) Canvas taken offline by Instructure in response to defacement, Penn State, Baylor, UMD, OSU, OU, UW–Madison, U Missouri, U Iowa, FIU, VCU, Princeton, JMU, Penn, Harvard, ASU, UMass; (3) Some have committed to academic accommodations, JMU delayed exams to May 13, Liberty promised class extensions, Princeton's Dean Gordin asked instructors to download Canvas gradebooks as precaution.

JMU Computing

Two **class-action investigations** have been announced: Chimicles Schwartz Kriner & Donaldson-Smith LLP and Shamis & Gentile P.A. ClassAction.org is soliciting plaintiffs.

Chimicles Schwartz Kriner & Donaldson-Smith LLP

**State-level confirmation:** The North Carolina Department of Public Instruction has confirmed receiving a breach notification from Instructure, implicating K-12 districts as well as higher ed.

WRAL

**No CISA advisory, no FBI alert, no Department of Education FERPA notice, no CVE** has been published as of this update. Federal involvement is limited to Instructure's own statement that it 'notified law enforcement.' MS-ISAC and REN-ISAC have not posted public advisories.

SecurityWeek

**Instructure is privately held.** KKR and Dragoneer Investment Group completed a $4.8 billion all-cash take-private acquisition at $23.60/share on November 13, 2024. INST common stock ceased trading on NYSE that day, and the company filed Form 15-12G to deregister securities. **Critical implication:** the SEC's 2023 Item 1.05 cyber-disclosure rule (4-business-day clock) does NOT apply, no INST share-price reaction is possible, and no Rule 10b-5 securities class action is viable. Financial-exposure analysis lives in the leveraged-loan secondary market, KKR Americas Fund XIII LP letters, and the consumer/regulatory tracks, not on EDGAR.

KKR / Dragoneer closing announcement (Nov 13 2024)

**LBO debt structure provides the post-private 'stock-price' equivalent for credit signal.** Pre-breach baseline: $1.685 B first-lien term loan (rated B-/B2), $365 M second-lien term loan (CCC/Caa2), $225 M revolver due 2029 with a springing first-lien leverage covenant. Corporate family rating B-/B3 stable. Watch secondary-market loan quotes and any S&P / Moody's CreditWatch Negative placement (plausible within 2-4 weeks given two confirmed breaches in <8 months).

PitchBook — Instructure LBO loan package coverage

**Federal-government vacuum at day 7+.** Through 168 hours since Instructure's May 1 disclosure, U.S. federal agencies have issued **zero** Canvas-specific products: no CISA advisory, no FBI Flash / IC3 alert, no PTAC FERPA bulletin, no FSA Dear Colleague Letter, no FTC announcement under the updated April 22 2026 COPPA Rule, no White House / ONCD statement, no congressional letter or hearing from any of the seven committees with jurisdiction (Senate HELP, HSGAC, Intel; House Ed & Workforce, Homeland Security, Energy & Commerce). The only federal 'action' is the pre-existing Title IV breach-intake clock that started May 1, a passive obligation on institutions. Most surprising silence: Senators Markey (D-MA) and Cassidy (R-LA), bipartisan COPPA 2.0 sponsors who routinely letter Meta/TikTok within 24-48 hours of children's-data incidents.

CISA Cybersecurity Advisories index (verified silent through May 8, 2026)

**Higher-ed sector consortium silence.** As of May 8, 2026, one full week into the incident, there is no public advisory from REN-ISAC (the higher-ed analog to MS-ISAC), EDUCAUSE (no Review article, no community blog), NACUA (no NACUANOTES on FERPA-notification timing), AACRAO, NACUBO, AAU, APLU, AGB, SHEEO, or ACE. Member-only listserv traffic almost certainly exists, but for non-member CIOs / Emergency Managers / general counsel, there is nothing canonical to cite. K12 SIX is the only sector ISAC voice on the public record, quoted via its weekly newsletter saying 'small and medium businesses, including the majority of U.S. K-12 education software businesses, are frequent cybersecurity targets.'

K-12 Dive (quoting K12 SIX) + REN-ISAC News page (verified silent)

**Defacement message verbatim** (May 7 mass-defacement HTML overlay on ~330 Canvas tenant login portals, also visible in the Canvas mobile app, observed by TechCrunch on three schools): "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'." The message directs schools to 'contact us privately at TOX to negotiate a settlement' before 'May 12 2026 before everything is leaked', superseding the earlier May 7-8 deadline.

BleepingComputer + TechCrunch

**International regulator silence.** No public statement as of May 8 from the UK ICO (UK GDPR Article 33 ICO-notification clock for U Manchester expired May 7), the Australian OAIC (Privacy Act 1988 NDB scheme; 2022 amendments raised maximum penalties to AU$50 M / 30% domestic turnover), the UK NCSC, Canadian OPC, or Australian Signals Directorate / ACSC. Eleven international universities have publicly confirmed impact (USYD, UniMelb, UTS, Auckland, AUT, VUW, Manchester, UBC, SFU, plus UofT confirmed via student paper after declining comment).

UK ICO + OAIC sites (verified silent through May 8, 2026)

**Anchor academic-sector quote**, In the absence of EDUCAUSE / REN-ISAC public commentary, Anton Dahbura, Executive Director of the Johns Hopkins University Information Security Institute, has emerged as the most-quoted higher-ed cybersecurity expert: 'The Canvas breach is a reminder that no platform is immune... Educational platforms are particularly rich targets given the concentration of personal, financial and international student data. Even organizations that do the right things can still be exposed through trusted vendors.'

Inside Higher Ed quoting Anton Dahbura, JHUISI

**Pre-disclosure timeline anomaly.** Fulton County Schools (GA), the largest district in Georgia (~90K students), posted its initial Canvas-incident security update on **April 27, 2026**, five days BEFORE Instructure's May 1 public disclosure. This implies Instructure quietly notified some K-12 customers under NDA roughly five days early. Combined with ShinyHunters' claimed **April 25** intrusion-onset date (per BleepingComputer reporting), the detection-to-disclosure-to-public timeline is: April 25 intrusion → April 27 confidential customer-notification window opens → April 30 status-page disruption to API tools → May 1 public disclosure → May 2 'contained' claim → May 7 mass-defacement falsifying the contained claim → May 12 leak deadline.

Fox 5 Atlanta + BleepingComputer

**Sept 2025 ↔ May 2026 lineage, definitive answer.** Same threat actor (ShinyHunters / Bling Libra / Mandiant UNC6040, now operating inside the August 2025 'Scattered LAPSUS$ Hunters' / 'Trinity of Chaos' alliance with Scattered Spider and LAPSUS$). Two distinct intrusions on different systems: Sept 2025 = vishing-driven social engineering of Instructure's Salesforce CRM (business contact info only; per Instructure no Canvas product data accessed). May 2026 = fresh intrusion into Canvas cloud production environment (names, emails, student IDs, Canvas Inbox messages, different data classes than Sept 2025 footprint). Multiple analysts have publicly questioned whether post-September remediation was sufficient given the same actor returned within 8 months.

gblock — Instructure Canvas Breach: Second Hit in 8 Months

**Market-share scale of systemic risk.** Per Spring 2025 Edutechnica data, Canvas controls **39% of N. American higher-ed institutions and ~50% of student enrollment**, more than D2L Brightspace (20%), Anthology Blackboard (12%), and Moodle (9%) combined. Every U.S. News 2026 top-10 national university (Princeton, MIT, Harvard, Stanford, Yale, etc.) runs on Canvas. K-12 footprint is similarly concentrated: ~8,000 institutions / ~200 million learners in 100+ countries per Instructure corporate site. The systemic-risk dimension is therefore even greater than first-look numbers (~28-30%) suggested in early coverage.

Edutechnica — LMS Data Spring 2025

**MFA partial-mitigation pattern (highest-signal forensic finding).** Charlottesville City Schools provided the most specific data-scope description in the entire dataset: 'Only parent accounts on Canvas, which contain very limited information, were affected. Student and staff accounts on Canvas do not appear to have been breached because they are protected by multifactor authorization.' This confirms multi-factor authentication worked as a partial mitigation: parent accounts (no MFA enforced) breached, staff/student accounts (MFA-protected) not. Implication for OIT readers: enforcing MFA on parent / observer / less-privileged Canvas roles is a high-yield retroactive control even after the May 12 leak deadline passes.

29News (CBS-19 Charlottesville)

**Comparable-incident lessons-learned: paying ransom does not stop downstream extortion.** PowerSchool's December 2024 SIS breach is the most directly comparable incident: top-tier ed-tech vendor, ~62 M students + 9.5 M educators affected. PowerSchool **paid the ransom** and received a video purportedly showing data deletion, yet by May 2025 attackers were re-extorting individual school districts directly. Perpetrator Matthew D. Lane (19, Mass. college student) was caught, pled guilty June 2025, sentenced to 4 years federal prison. **Implication:** any Instructure ransom payment may not actually protect institutional data; OIT readers should plan for direct-extortion contact attempts even after the May 12 deadline, regardless of vendor payment.

TechCrunch — PowerSchool breach analysis

**Most-likely-to-act state AG: NC Jeff Jackson.** Jackson already has an open Civil Investigative Demand against PowerSchool (issued June 2025, still pending) over its 2024 breach affecting nearly 4 million NC students/teachers/parents. With Wake County Schools and Duke both confirmed-affected by Instructure, Jackson is procedurally positioned to expand the existing edtech-vendor probe to Instructure under the same legal theory. Jackson on PowerSchool: 'I'm sending a Civil Investigative Demand to the company because I don't have answers to basic questions about what happened.' If a state AG breaks the silence first, NC is the most probable.

NC Department of Justice

**Texas AG Paxton precedent, the operative state-AG playbook.** In September 2025, Paxton sued PowerSchool over its 2024 breach, calling it a "catastrophic data breach that compromised the personal information of over 880,000 Texas school-aged children and teachers." The Paxton-PowerSchool litigation is the single most directly applicable precedent for state-AG action against an LMS/SIS vendor. As of May 8, 2026 Paxton has not announced an Instructure action, but Austin ISD's BLEND, HISD, Katy, Conroe, Pearland, Lamar are all confirmed-affected, and the legal theory is portable.

Texas AG press release (Sept 2025 PowerSchool suit)

**Utah AG home-state silence, most material federal-level gap.** Instructure is HQ'd in Salt Lake City. Home-state AGs almost always either issue a 'we are monitoring' confidence statement defending the local employer or file first to claim jurisdictional priority. Neither has occurred from Utah AG Derek Brown (in office since January 2025) as of May 8, 2026. The home-state silence is the single most material gap-fill finding in the senator/AG watch.

Utah AG press releases (verified silent through May 8, 2026)

**Senate Commerce Chair Cruz silence, only person who can force testimony.** As Chairman of Senate Commerce in the 119th Congress, Senator Ted Cruz (R-TX) is the sole convening authority who can put Instructure CEO Steve Daly and CISO Steve Proud under oath. Cruz has been actively scheduling executive sessions through 2026 on AI / children's safety topics (S.4407 introduced April 28 on AI chatbot parental consent), but no Canvas hearing announcement by May 8. Most likely to break federal silence: Sen. Richard Blumenthal (D-CT, KOSA co-author, frequent breach-letter author), Sen. Ed Markey (D-MA, COPPA 2.0 sponsor, MA institutions affected), Sen. Elizabeth Warren (D-MA), or a bipartisan Markey-Cassidy-Blumenthal-Blackburn-Hawley letter timed to the May 12 leak deadline.

Senate Commerce Committee

**Pre-existing controls that reduced exposure (positive signal).** Pearland ISD confirmed that two specific Canvas-tenant configurations meaningfully reduced their breach impact: (1) Canvas messaging disabled district-wide (so no in-platform message exfiltration possible) and (2) student email accounts restricted to receiving only `.edu` or `.mil` domain mail (meaningfully blunting downstream phishing pivots). These are zero-cost configuration choices that any Canvas-tenant OIT can deploy retroactively. Combined with Charlottesville's MFA-on-parent-accounts finding, the pattern is clear: **default Canvas posture is materially weaker than locked-down configurations**, and locked-down configurations measurably reduced this incident's exposure.

FOX 26 Houston (Pearland ISD statement)

**First international regulator confirmed receiving notifications: Dutch DPA.** All seven affected Dutch research universities (UvA, VU Amsterdam, Erasmus Rotterdam, Tilburg, TU Eindhoven, Maastricht, U Twente) filed preliminary GDPR Article 33 data-breach notifications with the Autoriteit Persoonsgegevens in the days following May 1, 2026 disclosure. This breaks the public-silence pattern at ICO, OAIC, NCSC, OPC. Watch for an AP public advisory within 2-4 weeks under GDPR's response cadence. The Dutch sector consortium Universiteiten van Nederland (UNL) is the **first** higher-ed sector body globally to issue a coordinated public statement; SURF (Dutch NREN) is named as coordinator and cites its 2025 privacy audit of Instructure regarding tenant separation. NL Times reports 44 Dutch educational institutions impacted in total when including hogescholen.

Universiteiten van Nederland + Autoriteit Persoonsgegevens

**Best single framing of the incident, Doug Thompson, Tanium.** Quoted in Inside Higher Ed: 'This breach follows a clear pattern we've been watching for the last 18 months. Instead of targeting individual campuses, attackers are moving up the data supply chain to the platforms that sit underneath thousands of institutions at once. It's the math of a bank robber who just figured out where the armored truck stops. Why hold up a hundred branches when the truck visits all of them? The real risk now is downstream. With access to real names, email addresses and even teacher-student messages, the next wave of phishing will not be generic. It will reference real courses and real conversations, which makes it far more likely to succeed.'

Inside Higher Ed quoting Doug Thompson, Tanium

**Counter-signal: gravitational pull TOWARD Canvas was still strong as the breach landed.** Two procurement-side data points one-to-three weeks pre-breach cut against any 'Canvas in death spiral' narrative: (1) the UNC System Board of Governors voted to standardize all 17 UNC institutions on Canvas as the single system-wide LMS (NC A&T implementing Fall 2026); (2) Instructure announced an exclusive partnership with K16 Solutions on April 29, 2026, one day before the breach, to accelerate migrations TO Canvas, with Sinclair Community College locked in for D2L→Canvas Summer 2026 go-live. Analyst consensus across Dark Reading, Higher Ed Intel, and Phil Hill (On EdTech): no immediate customer loss expected; PowerSchool→Infinite Campus comp is exceptional, not predictive. Watch the WCPSS Board of Education June 2026 agenda for first credible non-renewal candidate.

NC A&T Canvas Implementation Page + Instructure / Dark Reading

**Cyber-policy thought-leader silence parallels consortium silence.** Brian Krebs (Krebs On Security) has not blogged the incident as of May 8, 2026. Bruce Schneier (Schneier on Security) has not blogged it. Alex Stamos, Jen Easterly, Chris Krebs (former CISA Director), Anne Neuberger, Dmitri Alperovitch, Rob Joyce, John Hultquist, Kevin Mandia, Lisa Monaco, no public commentary in indexed coverage May 1-8. Most surprising silence: **Brett Callow** (Emsisoft / Coveware), whose career has been built on ransomware/extortion-breach commentary, has not been quoted in any major outlet. The entire **FERPA / privacy-law academic bench** (Solove, Hartzog, Reidenberg, Polonetsky) is also silent, despite the incident potentially being 'the largest FERPA violation in history' (a phrase repeated anonymously in coverage).

Krebs On Security + Schneier on Security (verified silent through May 8, 2026)

**Penn-specific May 8 deadline appears to have passed without public dump.** ShinyHunters had specifically warned the University of Pennsylvania that its data, covering ~306,000 Penn users, would be leaked May 8, 2026 absent contact. As of late afternoon May 8 ET, no Penn-specific data dump has surfaced publicly; the deadline has effectively been folded into the omnibus May 12, 2026 ultimatum. Reported record counts have crept upward in May 7-8 coverage: BleepingComputer cites 280 million records (vs. earlier 275 million); some outlets reference 231 million; institution count drifts between 8,800 and 9,000+. ShinyHunters numbers may be inflating intentionally as the deadline approaches.

Daily Pennsylvanian + BleepingComputer

**No federal-court class-action complaint filed yet, anti-misclassification note.** As of May 8, 2026 evening ET, no federal-court class-action complaint has been filed specifically over the May 2026 Instructure breach. Multiple plaintiff firms (Chimicles Schwartz Kriner & Donaldson-Smith, Stueve Siegel Hanson, ClassAction.org partners) are in pre-filing investigation stage. **Watch for first complaint Mon May 11 or Tue May 12** in the Northern District of California, District of Delaware, or District of Utah. Note: the 'Hernandez-Silva v. Instructure' case that surfaces in some search results is a SEPARATE March 2025 student-data-monetization case, dismissed August 2025, not a breach lawsuit. Hub maintainers should not cite Hernandez-Silva as a May 2026 breach lawsuit.

ClassAction.org investigation tracker

**NEW attack-vector attribution: Free-For-Teacher accounts.** Instructure spokesperson statement to TIME magazine overnight May 7-8: 'Out of an abundance of caution, [Instructure] temporarily took Canvas offline to contain access and further investigate.' The company said the threat actor 'exploited an issue related to Free-For-Teacher accounts' (Canvas's free-tier instance for individual teachers, separate from paid institutional tenants). Those accounts have been shut down to restore access to paid Canvas tenants, the first substantive corporate explanation of the May 7 access vector. This is new attribution detail not present in earlier May 1-3 disclosures and suggests the May 7 'second breach' may have been a different vector than the original April 30-May 1 incident.

TIME Magazine

**ShinyHunters appears to have DELISTED Instructure from active extortion blog.** Per Krebs On Security reporting May 8, 'sources close to the investigation report that ShinyHunters' data leak blog no longer lists Instructure among its current extortion victims, suggesting active negotiation may be underway.' The 3.65 TB 'proof' sample posted on May 3 remains the only verified Canvas-derived dataset publicly in circulation. The Penn-specific May 8 deadline appears to have passed without a Penn-specific dump. **Critical interpretation:** delisting + restored Canvas + paid-tenant containment via Free-For-Teacher shutdown is consistent with a backchannel-payment scenario, but Instructure has made no payment statement.

Krebs On Security

**CEO Steve Daly continues silence as of May 8.** All Instructure corporate communications about this breach have come from CISO Steve Proud (May 1-2) and unnamed spokespeople (May 7-8 statements to TIME). CEO Steve Daly has issued NO public statement of record, no blog post, no press release, no customer letter signed by his office, no investor letter. The contrast with PowerSchool CEO Hardeep Gulati (who was publicly visible during the December 2024 breach) is notable. CEO silence in a breach of this scale is itself a tracked data point for institutional readers.

Instructure leadership page (no Daly public breach statement located through May 8)

**Plaintiff bar field expands to four firms; Wohl & Fruchter publicly soliciting stockholders.** As of May 8, four U.S. plaintiff firms have publicly opened pre-filing investigations of the Instructure breach: Chimicles Schwartz Kriner & Donaldson-Smith, Stueve Siegel Hanson, Zimmerman Reed (consumer.zlk.com), and Bryson Harris Suciu & DeMay PLLC. Separately, Wohl & Fruchter LLP is hosting a public case page soliciting Instructure stockholders for the existing pre-breach Delaware Chancery Section 220 action (C.A. No. 2024-1122) attacking the $4.8 B KKR deal process, that case was filed October 31, 2024 and is the natural vehicle if breach-related fiduciary claims emerge against the pre-close Instructure board. No federal-court complaints have been filed as of May 8 evening; first filings expected May 11-12.

Wohl & Fruchter — Instructure case page

**FBI 'declines to comment', first explicit on-record federal posture.** When ABC11 Raleigh-Durham reached out to the FBI for comment on the Canvas breach, the FBI declined to comment. This is the first on-record federal-agency response posture: not 'investigating,' not 'aware,' but explicit refusal to comment. Combined with CISA, FTC, PTAC, FSA, ED, ONCD, and all 13+ congressional committee silences, the federal vacuum has now persisted 168+ hours since Instructure's May 1 disclosure.

ABC11 Raleigh-Durham

**Mandiant CTO Charles Carmakal on-record attribution.** TechCrunch quoted Charles Carmakal (CTO, Google-owned Mandiant Consulting) on May 7: 'the attack on Canvas customers was just one of several major cybercrime campaigns being launched by ShinyHunters at the moment.' Mandiant's broader ShinyHunters tradecraft profile: vishing impersonating IT helpdesk, fake company-branded SSO/login pages for credential harvest, OAuth Device Flow abuse via local Salesforce Data Loader instances, generation of 8-character device codes pushed to victims via vishing, slow silent exfiltration via legitimate API surface. **Note:** Mandiant has NOT been confirmed as Instructure's engaged forensics firm of record; Instructure has only said 'outside forensics experts.'

TechCrunch quoting Mandiant CTO Charles Carmakal

**Joint CEO Daly + CISO Proud customer communication.** Per 6ABC Philadelphia reporting (relayed Instructure customer letter, May 5): 'We know this incident affects the trust you place in us, and we take that seriously. We are committed to sharing timely, accurate updates as our investigation progresses.' This is the first sourced direct quote attributing language to both CEO Steve Daly and CISO Steve Proud, though Daly has still issued no standalone public statement under his own name, no blog post, no investor letter.

6ABC Philadelphia (relayed Instructure customer letter)

**ShinyHunters defacement payload, full ransom note text.** The HTML defacement payload injected into Canvas login pages on May 7, 2026 (~3:30 PM ET) contained verbatim: "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'. If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by May 12 2026 before everything is leaked." The payload was visible to all users across affected schools simultaneously (suggesting a centrally-injected resource rather than per-tenant config). By ~4:20 PM ET on May 7, the defacement was replaced by 'Canvas is currently undergoing scheduled maintenance' messaging, Instructure's choice of the 'scheduled maintenance' euphemism for an active extortion incident drew sharp criticism (Cloudskope CEO Dipan Mann: '275 Million Users Exposed. 8,809 Schools Down. Instructure Calls It Scheduled Maintenance.').

BleepingComputer (defacement payload text)

**MAJOR ATTACK-VECTOR CORRECTION: Salesforce Experience Cloud guest-user-profile misconfiguration, NOT Canvas Login Customization XSS.** Multiple converging sources (Hackread, BleepingComputer, SOCRadar, Rescana) describe the initial-access vector as Salesforce Experience Cloud guest-user-profile misconfiguration, with lateral pivot into Canvas tenancy via OAuth-issued tokens for connected apps. This is the same campaign vector ShinyHunters used against ~300-400 organizations since September 2025 (Salesloft Drift). The September 2025 prior incident at Instructure's Salesforce instance was the targeting-database foothold; April 25-30 2026 saw exploitation of Canvas Data 2 / Beta surface, OAuth Developer Key abuse, and automated paginated API extraction. **No CVE has been assigned** because the failure is configuration-class (likely CWE-732 / CWE-862 / CWE-1390), NOT software-defect class, meaning traditional CVE-driven patch management would not have prevented this.

Hackread + BleepingComputer + SOCRadar + Rescana

**MITRE ATT&CK mapping (multi-source consensus).** Sources converge on these techniques for the ShinyHunters Instructure operation: T1671 (abuse of cloud application integrations / connected apps), T1567 (Exfiltration Over Web Service), T1020 (Automated Exfiltration), within the broader ShinyHunters campaign cluster MITRE C0059. For the antecedent vishing tradecraft: T1566.004 (Spearphishing Voice / Vishing), T1078.004 (Valid Accounts: Cloud Accounts), T1550.001 (Use Alternate Authentication Material: Application Access Token), T1098.005 (create malicious connected/OAuth app), T1213.003 (data from cloud SaaS). **OIT-reader implication:** detection guidance is necessarily behavioral, anomalous Canvas Developer Key creation, anomalous OAuth token issuance preceding April 30 2026, unusual Canvas Data 2 / Beta API export volumes, off-hours API access from non-customer-IP-ranges. No CISA, MS-ISAC, REN-ISAC, or commercial CTI vendor has published file hashes, IPs, or domain IoCs as of May 8.

Hackread + SOCRadar synthesis (no formal vendor mapping by Mandiant / CISA yet)

**California state budget counter-signal, UC + CSU + CCC tri-system standardizing on Canvas mid-breach.** Per Phil Hill / On EdTech: California's three statewide higher-ed systems are using state budget allocations to STANDARDIZE on Canvas as the common LMS, even as the breach unfolds. Includes a $2M CSU line item to align with the CCC system's existing Canvas footprint. Combined with prior signals (UNC System 17 institutions, Sinclair CC D2L→Canvas Summer 2026, Instructure-K16 Solutions exclusive partnership April 29), the **counter-signal weight is now decisive**: three of the largest public systems in the US are EXPANDING Canvas adoption mid-breach. Procurement consensus: switching cost > breach risk.

Phil Hill, On EdTech

**Nordic cluster + multi-DPA notification chain.** Beyond the 7 Dutch research universities + AP, the breach has triggered breach-notification activity across Nordic regulators: University of Copenhagen (Canvas branded as 'Absalon') notified Datatilsynet (Danish DPA) on May 5; Aalto EE Finland notified Tietosuojavaltuutettu (Finnish Data Protection Ombudsman); five Swedish universities (KTH, KI, Lund, Uppsala, SLU) all notified Integritetsskyddsmyndigheten (IMY / Swedish DPA), with Sunet (Swedish NREN) coordinating. Despite seven+ DPAs across NL/SE/DK/FI receiving notifications, none have published a public advisory as of May 8, the regulator-publication gap is consistent globally.

University of Copenhagen + cross-Nordic regulator filings

**FEDERAL SILENCE PARTIALLY BROKEN, FBI Facebook advisory May 8.** Late afternoon / evening May 8, the FBI published a public Facebook advisory (referenced by Malwarebytes and Nextgov coverage) telling potential Canvas users: 'do not send payment'; 'receiving a message does not necessarily mean your personal information has been compromised'; 'threat actors often exaggerate or fabricate their access.' This is the **first US federal public communication on the breach**, partially breaking the day-8 federal-vacuum framing. CISA remains engaged but publicly silent. Notable interpretive frame: the FBI's 'threat actors often exaggerate' language signals federal skepticism toward ShinyHunters' 275M-record claim and implicitly discourages individual-institution ransom payment.

FBI public Facebook advisory (referenced by Malwarebytes / Nextgov / EdScoop)

**Forensic partner is CrowdStrike, not Mandiant.** Per Instructure's incident-update FAQ, CrowdStrike is Instructure's engaged forensic-IR partner. Mandiant's contribution has been **public commentary only**, CTO Charles Carmakal's TechCrunch quote and Krebs On Security attribution. CrowdStrike's May 8 readout (cited verbatim by Instructure): 'there is no evidence that the threat actor had system-level access, installed malware nor obtained login credentials, nor that any additional data was extracted during the renewed activity on May 7.' This corrects earlier hub speculation that Mandiant might be the forensic firm of record.

Instructure Security Incident Update FAQ

**Free-For-Teacher accounts confirmed as initial-access vector.** Per Bitdefender Technical Advisory and Rescana / SOCRadar convergence: ShinyHunters first gained access to Canvas production infrastructure by exploiting the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid institutional tenants. Initial intrusion: April 25, 2026. Detection: April 29, 2026 (4-day dwell). This refines the prior Salesforce Experience Cloud guest-user-profile attribution: BOTH framings are correct, the Salesforce-side foothold harvested in September 2025 enabled targeting, and the FFT-account abuse was the May 2026 production-side entry point. Data classes exposed: usernames, .edu email addresses, course names, enrollment information, Canvas inbox messages.

Bitdefender Technical Advisory + Rescana + SOCRadar

**RESOLUTION, Instructure / ShinyHunters settlement May 11-12.** BleepingComputer reports Instructure announced one day before the May 12 leak deadline that it had reached an agreement with ShinyHunters and 'received digital confirmation of data destruction (shred logs).' Vendor statement: 'no Instructure customers will be extorted as a result of this incident, publicly or otherwise.' Ransom dollar amount **undisclosed**. ShinyHunters delisted Instructure from the dark-web leak site. No individual institution has been confirmed to have paid separately. **Interpretation caveat:** shred-log 'destruction' confirmation is unverifiable by external parties; the PowerSchool precedent (Dec 2024, ransom paid but downstream re-extortion of districts still occurred in May 2025) recommends OIT readers continue to plan for direct-extortion contact attempts despite the announced settlement.

BleepingComputer / The Hacker News / Inside Higher Ed (May 11-12 reporting)

**CEO Steve Daly breaks silence with May 11 apology blog post.** Per IT Pro / KUTV / Idaho Ed News / Reuters, Daly published a blog-post apology on May 11, opening: 'I'll start where I should: with an apology. Over the past few days, many of you dealt with real disruption. Stress on your teams. Missed moments in the classroom. Questions you couldn't get answered. You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that. ... We focused on fact-finding and went quiet when you needed consistent updates. ... Rebuilding trust takes time. We're going to earn it back through consistent action and honest communication.' This is the first named-CEO statement of record, through May 8 evening, all corporate communication had been from CISO Steve Proud + unnamed spokespeople.

IT Pro quoting CEO Steve Daly's May 11 blog apology

**Federal silence officially broken, Garbarino House Homeland Security letter, May 11.** Rep. Andrew Garbarino (R-NY), Chairman of House Homeland Security, sent a formal letter to Instructure CEO Steve Daly on May 11, 2026 demanding a committee briefing by May 21. This is the first Congressional action of record; comes 10 days post-disclosure. Garbarino joins the FBI Facebook advisory + OAIC Australia statement as the only confirmed government-side public actions through the May 11-12 window. Senate HELP / Senate Commerce / Senate HSGAC / Senate Intel / House E&C / House Ed & Workforce / Markey-Cassidy COPPA 2.0 / all state AGs (including UT home-state, CA Bonta, NY James, TX Paxton, NC Jackson) remain silent.

House Homeland Security Committee press release

**Australia's OAIC issued the first international regulator public statement.** OAIC media centre advised affected users to lodge complaints directly with Instructure first, then escalate to OAIC after 30 days. The **Norwegian Datatilsynet** has since joined OAIC as the second international regulator with a public statement, citing 'serious' impact across 32 Norwegian institutions / ~250,000 students per Sikt coordination. UK ICO, Dutch AP, Swedish IMY, Danish Datatilsynet, Finnish Ombudsman, Canadian OPC all remain publicly silent despite having received GDPR / equivalent notifications.

OAIC + Norwegian Datatilsynet

**ED FSA issues first formal federal advisory May 12, but from financial-aid arm, not FERPA arm.** Federal Student Aid published a 'Technology Security Alert – Ongoing Cybersecurity Incident Involving the Canvas Learning Management System' on the May 12 ransom deadline day. Directed at IHEs participating in Title IV programs, it instructs institutions to review system, authentication, and Canvas integration logs for unusual access patterns between April 25 and May 8, 2026. **Notably from FSA cybersecurity (financial-aid integrity arm), NOT from the Student Privacy Policy Office or PTAC**, which per K-12 Dive reporting has 'requested information from Instructure to ensure compliance with FERPA' but has not issued a formal public advisory.

ED FSA Partners Knowledge Center

**Strongest privacy-civil-society voice: Elizabeth Laird, CDT.** Per K-12 Dive May 8 reporting, Center for Democracy & Technology's Director of Equity in Civic Technology Elizabeth Laird issued a public statement: 'Not only did this incident interfere with essential learning activities, it has exposed sensitive data about nearly 300 million users, including messages that could include incredibly personal information. This is an important wakeup call that schools and the companies that work with them have legal and ethical responsibilities to safeguard students and teachers online in the same ways that they are protected in the classroom.' CDT is the **only DC-area privacy think-tank** with a public statement of record. FERPA academic bench (Solove / Hartzog / Polonetsky / Reidenberg's Fordham CLIP / Grimmelmann / Goldman / Kaminski / Lessig) and EPIC / EFF / Common Sense Media / Parent Coalition for Student Privacy all remain silent through May 12.

K-12 Dive quoting Elizabeth Laird, CDT

**FIRST CLASS ACTION COMPLAINT FILED, Peterman v. Instructure (D. Utah).** Per Bloomberg Law, Jabon Peterman filed the first federal-court class-action complaint against Instructure on May 5, 2026 in the U.S. District Court for the District of Utah (No. 2:26-cv-00374). Plaintiff firms: Milberg PLLC, KO Lawyers, Carella Byrne Cecchi Brody Agnello PC, Marshall Olson & Hull PC (Utah counsel). A parallel **Hinds v. KKR & Co. Inc.** was filed May 8 in S.D.N.Y. by Yagman PLLC, naming KKR (Instructure's owner since the 2024 $4.8B take-private) on a negligence theory. **At least 7 federal suits filed** as of post-settlement reporting (6 in D. Utah + 1 in S.D.N.Y. naming KKR). No JPML/MDL consolidation order yet. Per State of Surveillance: 'The settlement with ShinyHunters does not resolve Instructure's civil liability to affected users.'

Bloomberg Law

**Potential statutory violation: Instructure may not have notified state AGs.** Per ClassAction.org and Inside Higher Ed: 'Instructure has not yet reported either data breach to state attorney general offices, which may have violated federal or state laws.' Most state breach-notification statutes require notification to the state AG within 30-60 days of discovery (some sooner for high-volume breaches). If accurate, this creates additional regulatory exposure beyond civil class-action liability, likely AG-action trigger within 30 days. NC AG Jeff Jackson's standing PowerSchool CID provides the cleanest precedent template.

ClassAction.org + Inside Higher Ed

**Three universities formally extended / canceled academic deadlines** (in addition to JMU's May 13 extension already documented): Emory University extended grade submission deadlines by 7 days and notably acknowledged 'Emory can't independently verify Instructure's findings'; East Carolina University moved the grade-submission deadline to 8 AM Wednesday May 13 (Provost Christopher Buddo named); Idaho State University outright canceled all afternoon finals on May 7, the most aggressive academic accommodation in the dataset. Pairs with Birmingham UK (May 13 deadline) and SMU TX (postponed Fri exams to Sun May 10).

Emory News + WCTI ABC 12 + Idaho State Journal

**Instructure denial of May 7 data theft contradicted by 330-portal defacement.** Instructure's incident-update FAQ states 'Instructure has not found evidence that data was taken during the May 7 activity.' However, ShinyHunters defaced login portals at ~330 institutions during this second wave, posting ransom messages directly on student/teacher screens. The characterization gap (data theft vs. defacement) remains a point of contention.

Instructure incident-update FAQ vs BleepingComputer/TechCrunch

Attack Vector: what OIT readers need to know

Configuration-class, not software-defect class · No CVE assigned

Multiple converging sources (BleepingComputer, SOCRadar, Rescana, Hackread) describe the initial-access vector as a Salesforce Experience Cloud guest-user-profile misconfiguration, with lateral pivot into the Canvas tenancy via OAuth-issued tokens for connected apps. This is the same campaign vector ShinyHunters used against ~300-400 organizations since September 2025 (the Salesloft Drift / UNC6395 wave).

MITRE ATT&CK consensus mapping: T1671 (abuse of cloud application integrations), T1567 (Exfiltration Over Web Service), T1020 (Automated Exfiltration), within campaign cluster C0059. Supplemental: T1566.004 (Vishing), T1098.005 (malicious OAuth app), T1078.004 (Valid Cloud Accounts), T1213.003 (data from cloud SaaS), T1550.001 (token abuse).

Implication for OIT readers: traditional CVE-driven patch management would not have prevented this. Detection guidance is necessarily behavioral: anomalous Canvas Developer Key creation, anomalous OAuth token issuance preceding April 30 2026, unusual Canvas Data 2 / Beta API export volumes, and off-hours API access from non-customer-IP-ranges. Pre-existing controls that measurably reduced exposure: MFA on parent / observer roles (Charlottesville City Schools) and Canvas messaging-disabled + email-domain whitelist (Pearland ISD).

Incident Timeline

25 events · newest first
  1. Mid-to-late May 2026 (litigation aftermath)

    Consumer class actions proliferate in federal court. Early reporting counted at least seven suits (six in the District of Utah, e.g. Peterman v. Instructure, plus Hinds v. KKR in the S.D.N.Y. naming Instructure's owner); later reporting cited roughly 18. Claims center on negligence, breach of legal obligations, and unjust enrichment. No JPML consolidation order had issued, and no state AG, FTC, or international DPA enforcement action had concluded, at the time this record was archived.

    Bloomberg Law
  2. May 12, 2026

    Federal Student Aid publishes a 'Technology Security Alert' on the Canvas incident, directing Title IV institutions to review system, authentication, and Canvas integration logs for unusual access between April 25 and May 8, 2026. It is the first formal federal advisory, issued from FSA's financial-aid-integrity arm rather than the Student Privacy Policy Office / PTAC.

    ED Federal Student Aid
  3. May 12, 2026 · end-of-day MDT

    ShinyHunters' 'full leak' deadline passes without a public dump and Canvas remains operational. Instructure considers the incident resolved. Security commentators caution that shred-log destruction cannot be externally verified and that the PowerSchool precedent (a paying vendor did not stop direct district-level re-extortion months later) warrants continued vigilance.

    The Hacker News
  4. May 11, 2026 · afternoon MDT (~one day before deadline)

    Instructure announces it has reached an agreement with ShinyHunters and 'received digital confirmation of data destruction (shred logs).' Vendor states 'no Instructure customers will be extorted as a result of this incident, publicly or otherwise.' Ransom amount undisclosed. ShinyHunters delisted Instructure from the dark-web leak site.

    BleepingComputer
  5. May 11, 2026

    House Homeland Security Committee Chair Andrew Garbarino (R-NY) sends formal letter to Instructure CEO Steve Daly demanding committee briefing by May 21, 2026, the first Congressional action of record on the breach.

    House Homeland Security Committee
  6. May 11, 2026 · morning MDT

    Instructure CEO Steve Daly publishes a public apology blog post, the FIRST CEO-named statement of record. Opens: 'I'll start where I should: with an apology. You deserved more consistent communication from us, and we didn't deliver it.' Through May 8 evening, all corporate communications had come from CISO Steve Proud or unnamed spokespeople.

    IT Pro quoting Steve Daly blog post
  7. May 8, 2026 · evening ET

    FBI publishes Facebook public advisory, first US federal public communication on the breach. Key language: 'do not send payment'; 'receiving a message does not necessarily mean your personal information has been compromised'; 'threat actors often exaggerate or fabricate their access.' Bloomberg, TIME, NPR, Reuters wire all enter coverage on May 8; NYT, WSJ, FT, BBC still silent.

    FBI Facebook advisory (referenced by Malwarebytes)
  8. May 8, 2026

    ShinyHunters threatens 'full leak' if no engagement; final payment deadline (per defacement message): end-of-day May 12, 2026. Canvas remains unavailable at most affected US tenants. Two class-action investigations announced.

    Harvard Crimson
  9. May 7, 2026 · evening ET

    **JMU formally postpones final exams** scheduled for Friday May 8 to Wednesday May 13, the first US institution documented to have explicitly delayed exams. Liberty publicly commits to 'appropriate class extensions.' TAMU-CC issues 'Code Blue' campus alert about phishing copycats.

    JMU Computing
  10. May 7, 2026 · ~3:00 PM CT, afternoon outage cascade

    Mass downstream school outages. UW–Madison (3:10 PM CT), U Iowa, Penn State, Baylor (5:22 PM CT), UMD, OSU, OU, U Missouri System, JMU, Penn (5:19 PM ET), Harvard, FIU (5:33 PM ET), VCU, Princeton, ASU all post advisories or confirm outage. UCCS reports outage at 2:20 PM MT.

    UW–Madison DoIT
  11. May 7, 2026 · ~3:30 PM ET (mass-defacement event)

    **ShinyHunters defacement campaign.** HTML injection alters Canvas login portals across customer schools globally, visible ~30 min before Instructure takes Canvas offline. Defacement message: 'ShinyHunters has breached Instructure (again).' Sets May 12 leak deadline.

    BleepingComputer
  12. May 7, 2026 · early MDT

    Series of recurrent Instructure status posts: 01:11 'Investigating' → 01:24 'Identified, fix being implemented' → 09:55 'Identified' (recurrent) → 11:37 'Resolved.' Containment claim begins to fray.

    Instructure Status — History
  13. May 6, 2026 · evening ET

    Princeton's Dean of the College Michael Gordin emails instructors asking them to download Canvas gradebooks 'as a purely precautionary measure.' UPenn confirms ~306,000 affected users (first US institution with specific count). Univ. of Auckland posts first international advisory.

    Daily Pennsylvanian
  14. May 6, 2026 · 3:13 PM MT / 5:13 PM ET

    Instructure marks the incident 'Resolved': 'Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.' Cornell, Columbia, Duke, Oklahoma State, JMU, and others post statements after Instructure formally notifies impacted institutions.

    K-12 Dive
  15. May 6, 2026 · 1:17 PM MT

    Instructure status update: 'Canvas Data 2 and Beta should now be available for all customers. Canvas Test remains under maintenance.'

    Instructure Status — History
  16. May 5, 2026

    Inside Higher Ed publishes its 'Pay or Leak' analysis. Boise State, UMass Amherst, UWM, and others post detailed advisories. Canvas Data 2 and Canvas Beta restored to global customers.

    Inside Higher Ed
  17. May 4, 2026

    First wave of US university advisories. Rutgers, CU Boulder, Boise State, UT Austin, the University of California system, Peralta Community College District, College of the Canyons, and others post early statements describing it as 'a nationwide issue affecting thousands of institutions.'

    UCnet
  18. May 3, 2026

    **ShinyHunters claims responsibility.** Group lists Instructure on Ransomware.Live / Tor leak site, claiming 3.65 TB / 275M individuals / ~9,000 schools and setting an initial May 6 payment deadline (later extended to May 12).

    Hackread
  19. May 2, 2026

    Saturday update: Instructure says incident 'has been contained' and specifies exposed data categories, names, email addresses, student ID numbers, and Canvas messages between users.

    K-12 Dive
  20. May 1, 2026 · 4:30 PM MT / 6:46 PM ET

    Public disclosure: CISO Steve Proud's customer letter labels it 'a cybersecurity incident perpetrated by a criminal threat actor.' Instructure engages outside forensic experts and notifies law enforcement.

    BleepingComputer
  21. May 1, 2026 · 08:09 MDT

    First Instructure status post: 'some customers were experiencing limited disruption to tools relying on API keys', investigating, taking precautionary steps.

    Instructure Status — Incident History
  22. April 30, 2026

    Public-facing impact surfaces: suspicious activity disrupts Canvas Data 2, Canvas Beta/Test, and tools dependent on API keys. Instructure's status-page investigation begins.

    Instructure Status Page
  23. April 29, 2026

    Detection (4-day dwell): Instructure's security team detects unauthorized activity in the Canvas production environment, revokes the actor's access, and engages outside forensic specialists (later confirmed as CrowdStrike).

    Bitdefender Technical Advisory
  24. April 25, 2026

    Second ShinyHunters intrusion begins: the actor gains access to Canvas production infrastructure by exploiting the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid tenants. The actor would later claim it 'reached out' but was met only with 'small security patches' rather than negotiation.

    Bitdefender Technical Advisory
  25. Sept 2025

    Prior ShinyHunters social-engineering breach of Instructure's Salesforce instance, reported as business-contact data only. Instructure publicly addressed it [in this blog post](https://www.instructure.com/resources/blog/security-incident-update). Same threat actor; framing: 'first time.'

    Instructure 'Update on Security Incident' (Sep 2025)

Key Voices: expert commentary on record

In the absence of EDUCAUSE / REN-ISAC / NACUA public statements, three named experts have carried the analytical commentary on the public record. Their verbatim quotes:

Higher-Ed Cyber Academic

Anton Dahbura

Executive Director, Johns Hopkins University Information Security Institute

The Canvas breach is a reminder that no platform is immune... Educational platforms are particularly rich targets given the concentration of personal, financial and international student data. Even organizations that do the right things can still be exposed through trusted vendors.
Inside Higher Ed

Supply-Chain Framing

Doug Thompson

Chief Education Architect, Tanium

Attackers are moving up the data supply chain to the platforms that sit underneath thousands of institutions at once. It’s the math of a bank robber who just figured out where the armored truck stops. Why hold up a hundred branches when the truck visits all of them?
Inside Higher Ed

Threat-Actor Attribution

Charles Carmakal

CTO, Mandiant Consulting (Google)

The attack on Canvas customers was just one of several major cybercrime campaigns being launched by ShinyHunters at the moment.” Mandiant’s tradecraft profile names vishing-driven IT-helpdesk impersonation + OAuth Device Flow abuse via Salesforce Data Loader.
TechCrunch

University & College Response Tracker

347 institutions logged

Each row below documents a single public action by a single institution, anchored to a primary source. If your institution has issued an alert, posted to an OIT status page, or extended deadlines and it is not yet listed, please send a tip.

347
Total tracked
288
Higher-ed
59
K-12 / state DOE
251
US-based
96
International
72
States / countries

62 of 347 entries carry verbatim-confirmed quotes (the rest are paraphrased from primary-source coverage). Use the filters below to slice by response type, US state / country, or full-text search by institution name, then export exactly what you see as CSV or JSON.

Showing 347 of 347 responses

UK Russell Group + Continental Europe (not-Canvas consolidated)

UK-EU-Not-Canvas · UK · Verified-not-using-Canvas as of May 12, 2026

No Public Response
Confirmed NON-Canvas tenants across UK Russell Group + continental Europe: Cambridge (Moodle), UCL (Moodle), LSE (Moodle), Warwick (Moodle), KCL (KEATS/Moodle), Nottingham (Moodle), Exeter (Moodle/ELE), Glasgow (Moodle), Loughborough (Moodle), Lancaster (Moodle), Bath (Moodle), Bristol (Blackboard), Leeds (Minerva/Blackboard), Sheffield (Blackboard), Cardiff (Learning Central/Blackboard), Durham (Blackboard Ultra), Southampton (Blackboard), Aberdeen (MyAberdeen/Blackboard), Strathclyde (Myplace/Moodle), Surrey (SurreyLearn/Brightspace); plus Sorbonne / Sciences Po (Moodle), TUM / LMU / Heidelberg (Moodle), ETH / EPFL (Moodle), Bocconi (Blackboard), Trinity College Dublin (Blackboard Ultra), KU Leuven (Toledo/Blackboard), University of Helsinki (Moodle), University of Tartu / Tallinn U / Vilnius U (Moodle). None affected by the Instructure breach.

**Critical disambiguation entry**, most UK Russell Group + flagship Continental European universities use Moodle / Blackboard / D2L, NOT Canvas. Prevents reader inference that all major European universities are affected. Oxford / Birmingham / Edinburgh / Liverpool / Manchester are the UK Canvas exceptions; Aalto EE / KTH / KI / Lund / Uppsala / SLU / U Copenhagen / U Oslo / NTNU / UiT / U Iceland are the continental exceptions.

Multiple institutional IT pages

Iron County School District

ICSD-UT · UT · May 10, 2026 (MDT)

Faculty / Student Email
Canvas is not hosted on our servers, which means Iron County School District was not directly attacked. Instructure told districts it has found no evidence that the unauthorized actor established persistence, obtained credentials for accounts within (our district), or exfiltrated any additional data. The district also noted that sensitive information such as Social Security numbers, passwords, financial information and dates of birth are not provided to Canvas.

Cedar City UT (~9K students). Defensive 'not directly attacked' framing reflective of cyber-insurance-counsel guidance.

Iron County Today

National University of Singapore (active response)

NUS-Active · SG · May 8 statement; May 10 password-reset email; May 11-14 controlled access (SGT)

Faculty / Student Email
An NUS spokesperson said the university was aware of the breach: 'Data protection and security are our priority, and we are in touch with Instructure to assess the impact.' The data involved comprises names, email addresses and matriculation numbers; no other sensitive personal information, including login credentials, is compromised. In an email sent on May 10, NUS instructed staff and students who had previously logged in to Canvas to reset their NUS passwords. Canvas was placed under controlled access from May 11-14, with only selected users granted access for critical academic or operational purposes.

**Updates earlier silent NUS status.** NUS ordered campus-wide password reset, among the most aggressive responses globally. Migrated to Canvas from LumiNUS December 2023.

MustShareNews + Straits Times

Singapore Institute of Management Global Education

SIM · SG · May 8-10, 2026 (SGT)

Faculty / Student Email
SIM said it is closely monitoring the disruption affecting access to the Canvas learning platform together with Instructure. Alternative arrangements were implemented for affected students, including sending Zoom meeting links directly for online lessons, postponing deadlines for affected quizzes and assignments, and providing information on the retrieval of course materials. SIM asked staff and students to reset their passwords as an added precaution following the global data breach.

Second Singapore institution to order campus-wide password reset. Notable for granular operational accommodations (direct Zoom-link distribution, deadline postponements).

The Star (Malaysia) ASEAN Plus

Des Moines Public Schools

DMPS-IA · IA · May 8, 2026 (CDT)

Faculty / Student Email
Des Moines Public Schools confirmed that Canvas holds data limited to names, email addresses, internal student ID numbers, course information, and messages between users. An email from DMPS to parents stated that Canvas was back online and that no private information was compromised.

Largest district in Iowa (~31K students).

NewsRadio 1040 WHO Des Moines

Hamilton County Schools (TN)

HCS-TN · TN · May 8, 2026 (EDT)

Press Release
Hamilton County Schools officials reassured families after the Canvas data breach. The breach is believed to have involved names, email addresses and student ID numbers from HCS users. After ransom-deadline negotiations, Instructure announced hackers agreed to delete data.

Chattanooga (~44K students). 4th-largest TN district.

NewsChannel 9 Chattanooga

Columbus City Schools

Columbus-CS · OH · May 8, 2026 (EDT)

Press Release
Columbus City Schools, Ohio's largest school district, said Instructure alerted CCS to unauthorized activity. The impact for Columbus City Schools is believed to be limited to basic directory information of approximately 19,000 students and staff, and some internal communications.

**Ohio's largest K-12 district.** First K-12 in hub to disclose a specific affected-user count (~19,000).

Spectrum News 1 Columbus

Hilliard / Upper Arlington / Cleveland Metro hybrid (OH K-12 cluster)

OH-K12-Cluster · OH · May 8, 2026 (EDT)

Press Release
Three additional Ohio K-12 districts in the Canvas affected set: Hilliard City Schools (~16K, Columbus suburb, hilliard.instructure.com), Upper Arlington Schools (~6K, Columbus suburb; 'names, email addresses, messages sent through Canvas, and student identification numbers' per ABC6), and Cleveland Metropolitan School District (~36K, hybrid LMS — Schoology primary; Canvas secondary for younger learners only).

OH K-12 cluster expansion. CMSD is the only documented Schoology-primary + Canvas-secondary hybrid.

ABC6 Columbus + Cleveland Metropolitan SD

Springfield Public Schools (Missouri R-XII)

SPS-MO · MO · May 8, 2026 (CDT)

Press Release
Springfield Public Schools is monitoring the breach and awaiting more details from Instructure. SPS chief communications officer Stephen Hall stated that 'Instructure ... is continuing to assess the situation.' It was not immediately clear Friday if any student records were compromised, but the service was running for students and parents. Both SPS and Drury utilize Canvas.

**First Missouri K-12 statement in hub.** Largest accredited district in Missouri (~25K students). SPS is an Instructure case-study customer ('100% of Students Choose Canvas'), awkward for vendor PR.

Springfield Daily Citizen

Seminole County Public Schools

SCPS-FL · FL · May 8, 2026 (EDT)

Press Release
Seminole County schools in Central Florida disabled access to Canvas in response to the Instructure breach and warned families not to click links from suspicious sources purporting to be Canvas. The district uses Canvas for teacher learning and web-based student learning.

Orlando-area district (~67K students).

ClickOrlando (WKMG)

Collier County Public Schools

CCPS-FL · FL · May 8, 2026 (EDT)

Press Release
Collier County Schools received confirmation from Instructure that the District was impacted. However, according to Instructure, no sensitive information was obtained, and student access to Canvas remains available.

Naples-area district (~47K students). **Counter-posture:** kept Canvas student access ON rather than disabling, contrast with Seminole / Duval / Brevard / Cherokee.

WINK News

Hamilton Southeastern Schools

HSE · IN · May 8, 2026 (EDT)

Press Release
Hamilton Southeastern Schools warned parents that hackers gained access to limited user information including names, email addresses, student IDs and Canvas messages. HSE is working with its cyber insurance carrier, other school districts and the Indiana Department of Education. The district noted Instructure connected the issue to Free-For-Teacher accounts, 'which we do not utilize.'

**First INDIANA K-12 in hub.** Fishers / suburban Indianapolis (~22K students). Cyber-insurance-led posture rare in public messaging.

Hamilton County Reporter (IN)

Duval County Public Schools

DCPS-FL · FL · May 8, 2026 (EDT)

Press Release
Duval County Schools confirmed that the nationwide Canvas breach had minimal impact on district operations since Canvas is primarily used for employee professional development. As a precaution, the district temporarily disabled the platform until the issue was resolved. Clay County and Nassau County schools, which also use Canvas, were similarly affected.

Largest district in Northeast FL (~127K students). Limited Canvas footprint (PD only) blunts exposure.

News4Jax

Clay County / Nassau County FL (Jacksonville-area cluster)

JAX-K12-Cluster · FL · May 8, 2026 (EDT)

Press Release
Two NE Florida K-12 districts confirmed Canvas-affected alongside Duval County: Clay County District Schools (~38K students) and Nassau County School District (~12K), per News4Jax regional reporting. Both confirmed Canvas users impacted by the breach.

Jacksonville-area cluster pairing with Duval (already in hub).

News4Jax

Texas Woman's University

TWU · TX · May 8, 2026 morning (CDT)

OIT / Status Page
Access to the Canvas platform has been restored. Faculty will offer guidance to students regarding assignments and exams, allowing for reasonable accommodations because of the outage.

Public doctoral, the only public university focused on women's education. Restored access faster than UNT.

TWU My Courses Status

Hawaii State Department of Education / HVLN

HIDOE · HI · As of May 8, 2026 (HST)

No Public Response
The Hawaii Office of Curriculum and Instructional Design provides interested HIDOE schools, charter schools, complex areas and state offices with access to Canvas through the Hawaii Virtual Learning Network (HVLN) Hawaii Online Teaching (HOT) program. No public HIDOE breach statement located as of May 8, 2026.

Only single-statewide K-12 district in U.S. (~157K students). Canvas is opt-in via HVLN/HOT (not universal). Direct parallel to NCDPI but no HIDOE statement issued, high-priority gap.

Hawaii Virtual Learning Network

Hawai'i Pacific University

HPU · HI · Silent through May 8, 2026 (HST)

No Public Response
Hawai'i Pacific University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026. **Notable: UH System (including UH Mānoa) is NOT a Canvas tenant** — UH uses Laulima (Sakai-based), so the Hawai'i higher-ed Canvas blast radius is concentrated at private institutions like HPU.

**AANAPISI gap-fill, first Hawai'i higher-ed entry in hub.** Private masters (~3,400 students). **Critical disambiguation:** UH Mānoa runs Laulima (Sakai), NOT Canvas.

Hawai'i Pacific University

Iḷisaġvik College

Iḷisaġvik · AK · Silent through May 8, 2026 (AKDT)

No Public Response
Iḷisaġvik College in Utqiaġvik (Barrow), Alaska — the only tribal college in Alaska and the northernmost accredited college in the US — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**TCU gap-fill, FIRST ALASKA ENTRY in hub.** AIHEC member, only TCU in Alaska. Northernmost accredited US college.

Iḷisaġvik College

Mesa Public Schools / Tucson USD / Phoenix Union HSD

AZ-Big-3 · AZ · As of May 8, 2026 (Arizona time, no DST)

No Public Response
Mesa Public Schools (largest AZ district, ~58K students), Tucson Unified School District (~42K, oldest and largest in S. AZ), and Phoenix Union HSD (~28K, partial Canvas user) are all confirmed Canvas users. No public breach statements located as of May 8, 2026.

Three biggest Arizona K-12 Canvas tenants silent through day 7, gap for follow-up.

Mesa Public Schools Canvas page

Maricopa Community Colleges

MCCCD · AZ · Silent through May 8, 2026

No Public Response
Maricopa Community Colleges District (10 colleges, ~200K students across the system) is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — pairs with ASU (already in hub).

One of the largest CC systems in the US. AZ gap-fill.

Maricopa Community Colleges

Diné College

Diné · AZ · Silent through May 8, 2026 (Arizona time)

No Public Response
Diné College — the first tribally controlled and accredited collegiate institution in the United States, located on the Navajo Nation — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — tribal college category previously had zero coverage.

First confirmed tribal college in hub. Navajo Nation. AIHEC member. ~1,400 students. Tribal-college gap-fill.

Diné College

Tohono O'odham Community College

TOCC · AZ · Silent through May 8, 2026 (Arizona time)

No Public Response
Tohono O'odham Community College on the Tohono O'odham Nation reservation is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Tribal community college. AIHEC member.

Tohono O'odham Community College

Northwest Indian College

NWIC · WA · Silent through May 8, 2026 (PDT)

No Public Response
Northwest Indian College on the Lummi Indian Reservation is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Tribal college, AIHEC member. Pacific NW.

Northwest Indian College

Eastern Washington University

EWU · WA · May 7-8, 2026 (PDT)

Press Release
The compromised data does not include passwords, dates of birth, government identifiers or financial information. EWU was warned by Instructure before the public breach disclosure.

Public masters. Notable headline suggesting EWU had advance notification from Instructure that hasn't yet been publicly characterized.

The Easterner (EWU student paper)

Gonzaga University

Gonzaga · WA · May 7-8, 2026 (PDT)

Press Release
Gonzaga shared that its students were impacted by the cybersecurity attack on Canvas.

Private doctoral, Jesuit (~7K students).

KREM 2 Spokane

University of Idaho

U Idaho · ID · May 8, 2026 (PDT)

Press Release
The school is optimistic about the security of Canvas moving forward, though administration is encouraging students to download and protect current and future course materials just to be on the safe side. The outage lasted only a few hours on Thursday, and final exams at U of I are proceeding as scheduled.

Public R2, land-grant. **Most reassuring/upbeat institutional posture in the dataset**, spokeswoman Jodi Walker on record.

The Spokesman-Review

Albuquerque Public Schools

APS-NM · NM · As of May 8, 2026 (MDT)

No Public Response
Albuquerque Public Schools rolled out Canvas LMS in 2017 to its more than 100,000 constituents. As of May 8, 2026, no public APS breach statement has been located.

~73K students; largest district in New Mexico, 31st largest in U.S. Confirmed Canvas user since 2017, silence is high-priority gap for follow-up.

APS Canvas LMS page

Tennessee State University

TSU · TN · Silent through May 8, 2026

No Public Response
Tennessee State University is a confirmed Canvas tenant (TSU Canvas). No public Canvas-breach statement located through May 8, 2026.

Public HBCU, land-grant (~7K students). HBCU gap-fill.

Tennessee State University

Salish Kootenai College

SKC · MT · Silent through May 8, 2026 (MDT)

No Public Response
Salish Kootenai College on the Flathead Indian Reservation is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

First Montana entry in hub. Tribal college, AIHEC member.

Salish Kootenai College

Sinte Gleska University

SGU · SD · Silent through May 8, 2026

No Public Response
Sinte Gleska University on the Rosebud Indian Reservation is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — first South Dakota entry in hub.

Tribal university. First South Dakota entry in hub.

Sinte Gleska University

Oglala Lakota College

OLC · SD · Silent through May 8, 2026

No Public Response
Oglala Lakota College on the Pine Ridge Indian Reservation is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Tribal college, AIHEC member.

Oglala Lakota College

Tecnológico de Monterrey (ITESM)

Tec · MX · Silent through May 8, 2026 (CDT-Mexico)

No Public Response
ITESM / Tec de Monterrey is the largest Spanish-speaking Canvas tenant in scope (~80K students). Tec selected Canvas in 2017 as foundation for its Tec21 educational model. No public Canvas-breach statement located through May 8, 2026.

First Mexico entry in hub. Mexican INAI breach-notification regime applies.

Instructure customer story (Tec de Monterrey)

Brigham Young University

BYU · UT · Silent through May 8, 2026 (MDT)

No Public Response
Brigham Young University is the institution whose graduate-student founders (Brian Whitmer and Devlin Daley) created Canvas in 2008. BYU is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — silence notable given BYU's historical and home-state connection to Instructure (also based in Salt Lake City).

Private R1, religious affiliation (LDS Church). ~34K students. Pairs with U Utah / Davis SD / Granite SD / USBE Utah cluster.

BYU Canvas

Brigham Young University-Idaho

BYU-I · ID · Silent through May 8, 2026

No Public Response
BYU-Idaho is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private religious (LDS Church). ~30K students.

BYU-Idaho Canvas

Utah Valley University

UVU · UT · Silent through May 8, 2026

No Public Response
Utah Valley University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — pairs with U Utah / BYU / USBE Utah cluster.

Public masters/bachelors (~45K students).

Utah Valley University

Salt Lake Community College

SLCC · UT · Silent through May 8, 2026

No Public Response
Salt Lake Community College is a confirmed Canvas tenant, located in Instructure's home metro. No public Canvas-breach statement located through May 8, 2026.

Public CC (~28K students). Pairs with U Utah / BYU / UVU.

Salt Lake Community College

University of Texas at El Paso

UTEP · TX · Silent through May 8, 2026 (MDT)

No Public Response
UTEP — designated R1 HSI on the US-Mexico border — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**HSI gap-fill.** Public R1, HSI (~24K students).

UTEP

Mexican university cluster (ITAM / Anáhuac / UDEM / UAG)

MX-Cluster · MX · Silent through May 8, 2026 (CST-Mexico)

No Public Response
Mexican Canvas tenants named on the ShinyHunters affected_schools list per CyberSeg coverage: ITAM (Canvas since 2020), Universidad Anáhuac (uvanahuac.instructure.com hybrid with Brightspace), UDEM (Universidad de Monterrey), and Universidad Autónoma de Guadalajara (UAG). All silent through May 8, 2026.

Mexican cluster pairing with Tec de Monterrey (already in hub).

CyberSeg

Jackson State University

JSU · MS · Silent through May 8, 2026

No Public Response
Jackson State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public HBCU (~7K students). Pairs with Mississippi State already in hub.

Jackson State University

Tuskegee University

Tuskegee · AL · Silent through May 8, 2026

No Public Response
Tuskegee University is a confirmed Canvas tenant (Tuskegee Canvas). No public Canvas-breach statement located through May 8, 2026.

Private HBCU, land-grant (~3K students). HBCU gap-fill.

Tuskegee University

Auburn University

Auburn · AL · Silent through May 8, 2026

No Public Response
Auburn University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1, SEC, land-grant (~32K students).

Auburn Canvas portal

University of Alabama

UA · AL · Silent through May 8, 2026

No Public Response
University of Alabama is a confirmed Canvas tenant (Blackboard Learn was replaced by Canvas circa 2019). No public Canvas-breach statement located through May 8, 2026.

Public R1, SEC (~39K students).

UA eLearning / Canvas

Lone Star College System

LSCS · TX · Silent through May 8, 2026

No Public Response
Lone Star College is the largest community college system in Texas (~80K students) and a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — silence notable in the Houston-area Texas cluster (HISD, Conroe, Pearland, Katy already in hub).

Largest TX community college system. CC gap-fill.

Lone Star College Canvas

Memphis-Shelby County Schools

MSCS · TN · Silent through May 8, 2026

No Public Response
Memphis-Shelby County Schools confirmed by news reports that the district uses Canvas and is among Mid-South districts affected by the Instructure incident. As of May 8, 2026, no public statement located on the district website or social media.

Largest TN K-12 district (~107K students). Contrast Knox County TN (already responded).

FOX 13 Memphis

Haskell Indian Nations University

Haskell · KS · Silent through May 8, 2026

No Public Response
Haskell Indian Nations University — one of two BIE-operated tribal universities — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Federally-operated tribal university. Pairs with KU / K-State / Galena KS already in hub.

Haskell Indian Nations University

University of Texas Rio Grande Valley

UTRGV · TX · Silent through May 8, 2026 (CDT)

No Public Response
UTRGV — one of the largest HSIs in the United States — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**HSI gap-fill.** Public R2, HSI (~32K students), border region.

UTRGV

Turtle Mountain Community College

TMCC · ND · Silent through May 8, 2026 (CDT)

No Public Response
Turtle Mountain Community College on the Turtle Mountain Indian Reservation — a tribal land-grant — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**First North Dakota entry in hub.** AIHEC member, tribal land-grant.

Turtle Mountain Community College

Leech Lake Tribal College

LLTC · MN · Silent through May 8, 2026 (CDT)

No Public Response
Leech Lake Tribal College — a tribal land-grant on the Leech Lake Indian Reservation — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**First Minnesota tribal college in hub** (Wayzata K-12 already covered). AIHEC member.

Leech Lake Tribal College

Nebraska Indian Community College

NICC · NE · Silent through May 8, 2026 (CDT)

No Public Response
Nebraska Indian Community College — serving the Santee Sioux, Omaha, and Ho-Chunk nations — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**First Nebraska entry in hub.** AIHEC member.

Nebraska Indian Community College

Stillman / Talladega / Miles / Lawson State (AL HBCU cluster)

AL-HBCU-Cluster · AL · Silent through May 8, 2026 (CDT)

No Public Response
Four Alabama HBCUs — Stillman College (~600 students, Presbyterian-affiliated), Talladega College (~1K students; oldest private HBCU in AL, founded 1867), Miles College (~1,500 students, CME Church), and Lawson State Community College (~3K students; one of the few HBCU community colleges) — are confirmed Canvas tenants. No public Canvas-breach statements located through May 8, 2026 (Tuskegee covered separately).

HBCU cluster gap-fill. Alabama HBCUs.

Stillman / Talladega / Miles / Lawson State

Madison Metropolitan School District / Spring Branch ISD / Rockwood R-VI / North Kansas City (Mid-tier silent K-12 cluster)

Mid-Tier-Silent-K12 · USA · Silent through May 8, 2026

No Public Response
Four additional silent K-12 Canvas tenants: Madison Metropolitan School District WI (~27K, first WI K-12), Spring Branch ISD TX (~33K, Houston-area, Canvas since Aug 2022), Rockwood R-VI MO (~20K, St. Louis County; Canvas sole LMS grades 6-12 from 2024-25), and North Kansas City Schools MO (~21K, canvas.nkcschools.org).

K-12 cluster gap-fill across WI / TX / MO. Includes first WI K-12 entry (Madison).

Multiple district Canvas portals

Waukee CSD / Marshalltown CSD / Cedar Rapids CSD (Iowa K-12 cluster)

IA-K12-Cluster · IA · May 7-8, 2026 (CDT)

Press Release
Three additional Iowa K-12 districts in the Canvas-affected set: Waukee Community School District (~14K, Des Moines suburb; family notification via ParentSquare May 7), Marshalltown Community School District (~5K rural, named in statewide IA coverage), and Cedar Rapids Community School District (~16K — note: CRCSD transitioned away from Canvas to Infinite Campus before breach window, so technically NOT-Canvas during incident but historically a tenant).

Iowa K-12 cluster expansion. Pairs with DMPS (already in hub).

We Are Iowa (Local 5) + KYOU-TV

Texas A&M University (College Station)

TAMU · TX · Silent through May 8, 2026 (CDT)

No Public Response
Texas A&M University (College Station main campus) is a confirmed Canvas tenant (Howdy / Canvas). Separately, TAMU-Corpus Christi (Code Blue alert) is already documented. No public Canvas-breach statement located through May 8, 2026 for the main College Station campus.

Public R1, SEC, land-grant. ~73K students College Station.

Texas A&M Canvas

University of Texas at Dallas

UTD · TX · Silent through May 8, 2026 (CDT)

No Public Response
UT Dallas is a confirmed Canvas tenant (eLearning / Canvas). No public Canvas-breach statement located through May 8, 2026.

Public R1 (~31K students).

UTD eLearning Canvas

University of Texas at San Antonio

UTSA · TX · Silent through May 8, 2026 (CDT)

No Public Response
UTSA is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1, HSI (~34K students).

UTSA Canvas

University of Texas at Arlington

UTA · TX · Silent through May 8, 2026 (CDT)

No Public Response
UT Arlington is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1, HSI (~46K students).

UTA Canvas

Stephen F. Austin State University

SFA · TX · Silent through May 8, 2026 (CDT)

No Public Response
Stephen F. Austin State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~12K students).

SFA Canvas

Sam Houston State University

SHSU · TX · Silent through May 8, 2026 (CDT)

No Public Response
Sam Houston State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~21K students).

Sam Houston State Canvas

University of North Texas

UNT · TX · Silent through May 8, 2026 (CDT)

No Public Response
University of North Texas is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~46K students).

UNT Canvas

Missouri State University

MOState · MO · Silent through May 8, 2026 (CDT)

No Public Response
Missouri State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~24K students). Springfield MO.

Missouri State Canvas

Drury University

Drury · MO · Silent through May 8, 2026 (CDT)

No Public Response
Drury University is a confirmed Canvas tenant per Springfield Daily Citizen reporting alongside Springfield Public Schools (both confirmed-affected Canvas users in Springfield MO).

Private R2, Disciples of Christ-affiliated. ~3K students.

Springfield Daily Citizen

University of Memphis

U Memphis · TN · Silent through May 8, 2026 (CDT)

No Public Response
University of Memphis is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~21K students). Pairs with Memphis-Shelby County Schools (also silent).

U Memphis Canvas

Middle Tennessee State University

MTSU · TN · Silent through May 8, 2026 (CDT)

No Public Response
Middle Tennessee State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~22K students).

MTSU Canvas

Rice University

Rice · TX · Silent through May 8, 2026 (CDT)

No Public Response
Rice University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, AAU (~9K students). Pairs with U Houston / Houston ISD.

Rice Canvas

University of Alabama at Birmingham

UAB · AL · May 8, 2026 morning (CDT)

Press Release
UAB appears to be among the thousands of Instructure Canvas clients affected by its recent cyber security incident. Compromised information includes names, email addresses, student ID numbers, and messages among users. We have found no indication that passwords, dates of birth, government identifiers, or financial information were involved. UAB Information Technology has taken steps to protect UAB data.

Public R1, AAU. Pairs with U Alabama, Auburn.

AL.com via Yahoo News

University of Memphis

UMemphis · TN · May 7-8, 2026 (CDT)

OIT / Status Page
On May 1, 2026, Instructure disclosed a security incident resulting in a data breach. The University of Memphis was included in that breach. The incident occurred on April 25, 2026, when a criminal threat actor attacked Instructure. The attacker was detected on April 29 and access was immediately revoked. The information involved consisted of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users.

Public R1 (~21K students). **Explicitly confirms 'University of Memphis was included in that breach'**, most direct institutional acknowledgment of impact.

U of Memphis ITS

University of Nebraska System (UNL / UNO / UNK / UNMC)

NU-System · NE · May 7-8, 2026 (CDT)

Press Release
Canvas users around the world, including all four NU campuses, experienced interruptions to access on May 7. The information involved in the attack included names, student ID numbers, messages between users and email addresses. No evidence was found that passwords, dates of birth, government identifiers, or financial information were involved.

Covers all four University of Nebraska campuses (UNL flagship, UNO, UNK, UNMC). Public R1 + medical center.

Nebraska Today

Alabama A&M University

AAMU · AL · May 8, 2026 (CDT)

Press Release
Alabama A&M University told FOX54 it was not impacted by the outage.

**HBCU PUBLIC STATEMENT (denial of impact), fourth confirmed HBCU response.** Public R2 HBCU. Notable for being a 'not impacted' framing.

FOX54 / Rocket City Now (Huntsville)

Peruvian university cluster (PUCP / USIL / UDEP / UTEC / 5 more)

PE-Cluster · PE · May 8, 2026 (PET)

Press Release
Nine Peruvian universities affected by the Canvas outage during finals week per Infobae Perú May 8 reporting: PUCP, USIL, Universidad de Piura (UDEP), Universidad Norbert Wiener, Universidad Científica del Sur, USMP, UTP, UPAO, and UTEC. The outage fell during exam week when partial assignments representing 30% of the semester grade were due.

**First Peru entry in hub, 9 Peruvian universities affected.** Includes PUCP (Peru's top-ranked). Outage fell during finals when 30%-grade assignments were due.

Infobae Perú

NYC DOE / LAUSD / CPS / Miami-Dade / Boston PS / Philadelphia SDP

Top-6-Not-Canvas · USA · Verified-not-using-Canvas as of May 8, 2026

No Public Response
The largest U.S. K-12 districts NYC DOE (~900K students), LAUSD (~540K), Chicago Public Schools (~325K), Miami-Dade (~330K), Boston Public Schools (~46K), and the School District of Philadelphia (~115K) have NOT publicly responded to the Canvas incident — silence correctly explained: these districts use Schoology (LAUSD, Miami-Dade) or Google Classroom (NYC DOE, CPS, BPS, SDP) as their primary LMS, not Canvas.

Important context entry: prevents readers from incorrectly inferring breach impact at the largest US districts. NYC DOE primary LMS is Google Classroom; LAUSD mandated Schoology district-wide since 2020; Miami-Dade district-wide deploys Schoology (Miami Dade COLLEGE, separate institution, does use Canvas). Additional confirmed Schoology / Google Classroom districts: Dallas ISD, Cypress-Fairbanks, Northside ISD San Antonio, El Paso ISD, Aldine, Round Rock, Klein ISD, Newton PS (MA), Trenton PS (NJ), Red Clay (DE).

Multiple district LMS portals

Cincinnati Public SchoolsLeak list

CPS-OH · OH · Silent through May 8, 2026

No Public Response
Cincinnati Public Schools confirmed Canvas user (district LMS). Named on ShinyHunters' published affected-schools list alongside Princeton, UC Berkeley, and Brevard Public Schools (FL). No district-issued public statement located through May 8, 2026.

~36K students. **Named on the ShinyHunters leak list** but silent, high-priority watch.

Cincinnati Public Schools

Howard University

Howard · DC · Silent through May 8, 2026

No Public Response
Howard University is a confirmed Canvas tenant (Howard's Canvas portal is the institutional LMS). No public Canvas-breach statement located through May 8, 2026 — silence is notable given Howard's flagship-HBCU status and DC location.

Flagship private HBCU. Silence is a tracked data point for HBCU coverage. ~14K students.

Howard University Canvas portal

Spelman College

Spelman · GA · Silent through May 8, 2026

No Public Response
Spelman College is a confirmed Canvas tenant via its Atlanta University Center participation (AUC schools share LMS infrastructure). No public Canvas-breach statement located through May 8, 2026.

Top private HBCU women's college (~2K students). HBCU gap-fill.

Spelman College

Morehouse College

Morehouse · GA · Silent through May 8, 2026

No Public Response
Morehouse College participates in the Atlanta University Center Consortium that includes Canvas as a shared LMS. No public Canvas-breach statement located through May 8, 2026.

Flagship private HBCU men's college. HBCU gap-fill.

Morehouse College

Florida A&M University

FAMU · FL · Silent through May 8, 2026

No Public Response
Florida A&M University is a confirmed Canvas tenant (FAMU iRattler / Canvas). No public Canvas-breach statement located through May 8, 2026.

Largest public HBCU by enrollment (~10K students). HBCU gap-fill.

Florida A&M University

North Carolina A&T State University

NC A&T · NC · Silent through May 8, 2026

No Public Response
NC A&T is in the middle of its Canvas standardization rollout (Fall 2026 go-live) as part of the UNC System Board of Governors' system-wide Canvas standardization vote. No Canvas-breach statement located through May 8, 2026 — partial Canvas footprint reduces immediate exposure but the system-level standardization decision adds long-term relevance.

Largest HBCU in the US (~13K students). Connects HBCU gap-fill to UNC System counter-signal already in the hub.

NC A&T Aggie Hub Canvas Implementation

North Carolina Central University

NCCU · NC · Silent through May 8, 2026

No Public Response
NCCU is part of the UNC System and a confirmed Canvas tenant via the system-wide standardization. Pairs with Wake County / Durham PS / Chapel Hill-Carrboro NC K-12 cluster. No public Canvas-breach statement located through May 8, 2026.

Public HBCU (~8K students). HBCU gap-fill.

North Carolina Central University

Hampton University

Hampton · VA · Silent through May 8, 2026

No Public Response
Hampton University is a confirmed Canvas tenant (HU Online / Canvas). No public Canvas-breach statement located through May 8, 2026.

Private HBCU (~3K students). HBCU gap-fill; pairs with VBCPS / Virginia VBCPS / Charlottesville VA already in hub.

Hampton University

Bowie State University

BSU · MD · Silent through May 8, 2026

No Public Response
Bowie State is a confirmed Canvas tenant within the University System of Maryland (USM). No public Canvas-breach statement located through May 8, 2026.

Maryland's oldest HBCU (~6K students). HBCU gap-fill.

Bowie State University

University of Florida

UF · FL · Silent through May 8, 2026

No Public Response
University of Florida is a confirmed Canvas tenant (e-Learning / Canvas) — UF was an early major Canvas adopter. No public Canvas-breach statement located through May 8, 2026 — silence notable for the state of Florida's preeminent public R1 alongside USF and FIU (which did respond).

Public R1, SEC, AAU. ~57K students. R1 flagship gap-fill.

UF e-Learning Canvas

University of Georgia

UGA · GA · Silent through May 8, 2026

No Public Response
University of Georgia is a confirmed Canvas tenant (eLC = e-Learning Commons / Canvas). No public Canvas-breach statement located through May 8, 2026 — pairs with Georgia Tech / Auburn / U Alabama SEC cluster silence.

Public R1, SEC, AAU (~40K students).

UGA e-Learning Commons

University of CincinnatiLeak list

U Cincinnati · OH · Silent through May 8, 2026

No Public Response
University of Cincinnati is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~46K students). Pairs with Cincinnati Public Schools (named on ShinyHunters leak list).

University of Cincinnati Canvas

Wayne State University

Wayne State · MI · Silent through May 8, 2026

No Public Response
Wayne State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~24K students). Pairs with U-M (already in hub).

Wayne State Canvas

University of Central Florida

UCF · FL · Silent through May 8, 2026

No Public Response
University of Central Florida is a confirmed Canvas tenant (Webcourses@UCF / Canvas). No public Canvas-breach statement located through May 8, 2026 — silence notable given UCF's ~70K student enrollment.

Public R1, one of the largest US universities by enrollment (~70K students).

UCF Webcourses Canvas

West Virginia University

WVU · WV · Silent through May 8, 2026

No Public Response
West Virginia University is a confirmed Canvas tenant (WVU eCampus / Canvas). No public Canvas-breach statement located through May 8, 2026.

Public R1, land-grant (~26K students). West Virginia gap-fill (first WV institution in hub).

WVU eCampus Canvas

George Mason University

GMU · VA · Silent through May 8, 2026

No Public Response
George Mason University is a confirmed Canvas tenant (Mason Canvas / Canvas). No public Canvas-breach statement located through May 8, 2026 — pairs with UVA / VT / VCU / James Madison Virginia cluster already in hub.

Public R1 (~40K students).

George Mason Canvas

Old Dominion University

ODU · VA · Silent through May 8, 2026

No Public Response
Old Dominion University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~24K students).

ODU Canvas

University of Connecticut

UConn · CT · Silent through May 8, 2026

No Public Response
University of Connecticut is a confirmed Canvas tenant (HuskyCT was Blackboard; UConn migrated to Canvas circa 2024). No public Canvas-breach statement located through May 8, 2026.

Public R1 (~33K students). First Connecticut institution in hub.

UConn Canvas

University of Buffalo (SUNY)

UB · NY · Silent through May 8, 2026

No Public Response
University at Buffalo (SUNY) is a confirmed Canvas tenant; UB Learns transitioned from Blackboard to Brightspace, but graduate programs use Canvas in some schools. No public Canvas-breach statement located through May 8, 2026.

Public R1, SUNY flagship, AAU (~32K students). Partial Canvas footprint.

University at Buffalo

Stony Brook University

Stony Brook · NY · Silent through May 8, 2026

No Public Response
Stony Brook University (SUNY) is a confirmed Canvas tenant via SUNY's system-wide Canvas migration. No public Canvas-breach statement located through May 8, 2026.

Public R1, AAU (~26K students).

Stony Brook IT Canvas

Northern Virginia Community College

NOVA · VA · Silent through May 8, 2026

No Public Response
Northern Virginia Community College is one of the largest CCs in the US (~75K students) and a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Massive DMV-area CC. Federal-employee adjacent demographic.

NOVA Canvas

Miami Dade College

MDC · FL · Silent through May 8, 2026

No Public Response
Miami Dade College is the largest US college / community college by enrollment (~100K students) and a confirmed Canvas tenant. Distinct from Miami-Dade County Public Schools (which use Schoology, NOT Canvas). No public Canvas-breach statement located through May 8, 2026.

Largest 4-year HSI in US. Important disambiguation: MDC ≠ Miami-Dade County PS.

Miami Dade College

Atlanta Public Schools / Cobb County / Gwinnett County

Atlanta-Top-3-Not-Canvas · GA · Verified-not-using-Canvas as of May 8, 2026

No Public Response
The three largest metro-Atlanta school districts — Atlanta Public Schools (~50K), Cobb County School District (~106K), and Gwinnett County Public Schools (~180K) — are NOT confirmed Canvas users. APS uses Schoology + Infinite Campus. Cobb uses CTLS (proprietary district-built). Gwinnett uses eCLASS / MYeCLASS (proprietary). None impacted by the Instructure breach. Contrast with Fulton, Cherokee, Forsyth GA (all Canvas, all responded).

Important disambiguation entry: prevents reader inference that all major Atlanta-area districts are affected.

Cobb County Schools CTLS

Bay Mills Community College

BMCC · MI · Silent through May 8, 2026

No Public Response
Bay Mills Community College — the first tribally controlled community college in Michigan — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Tribal CC, AIHEC. Pairs with Wayne State / U Michigan.

Bay Mills Community College

University of New Hampshire

UNH · NH · Silent through May 8, 2026

No Public Response
University of New Hampshire is a confirmed Canvas tenant (myCourses / Canvas). No public Canvas-breach statement located through May 8, 2026 — first New Hampshire entry in hub.

Public R1, land-grant (~15K students). First NH institution in hub.

UNH myCourses Canvas

University of Maine

UMaine · ME · Silent through May 8, 2026

No Public Response
University of Maine is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — first Maine entry in hub.

Public R2, land-grant, sea-grant (~12K students). First ME institution in hub.

University of Maine

University of Vermont

UVM · VT · Silent through May 8, 2026

No Public Response
University of Vermont is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — first Vermont entry in hub.

Public R1, land-grant (~14K students). First VT institution in hub.

University of Vermont

University of Delaware

UDel · DE · Silent through May 8, 2026

No Public Response
University of Delaware is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — first Delaware entry in hub.

Public R1 (~23K students). First DE institution in hub. NOTE: Red Clay Consolidated K-12 (already in hub) is Schoology, not Canvas, so UDel is Delaware's sole Canvas presence.

UDel Canvas

University of Rhode Island

URI · RI · Silent through May 8, 2026

No Public Response
University of Rhode Island is a confirmed Canvas tenant (Brightspace was deprecated in favor of Canvas circa 2023). No public Canvas-breach statement located through May 8, 2026 — pairs with Brown already in hub.

Public R2 land-grant + sea-grant (~17K students).

URI Canvas

Howard County Public School System

HCPSS · MD · Silent through May 8, 2026

No Public Response
Howard County Public School System (Maryland) is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — pairs with Anne Arundel (proactive shutdown) and Montgomery County MD (already in hub).

Maryland K-12 (~58K students). Affluent DMV-adjacent district.

Howard County Public Schools

Universidad de los Andes (Chile)

UAndes · CL · Silent through May 8, 2026 (CLT)

No Public Response
UAndes Chile was Canvas's first higher-education customer in Chile (adopted 2017). All undergraduate programs run on Canvas across in-person, hybrid, and distance modalities. No public Canvas-breach statement located through May 8, 2026.

First Chile entry in hub. Chile's updated Ley 19.628 data-protection law (2024 reform) breach-notification obligations effective 2026.

UAndes Chile Canvas

Florida A&M University

FAMU · FL · May 7-8, 2026 (EDT)

Press Release
During the outage, Florida A&M University worked closely with Instructure to monitor developments and assess operational impacts. Services have since been restored. The impact was minimized at Florida A&M University because spring semesters wrapped up the previous week and summer classes were starting the following week. University officials at both FAMU and FSU said they are also developing contingency plans in case something like this happens again.

**HBCU UPGRADE, second confirmed HBCU public statement (after Morgan State).** Largest public HBCU (~10K students). Calendar-driven 'limited impact' framing is distinctive.

WTXL Tallahassee

Cheyney University of Pennsylvania

Cheyney · PA · Silent through May 8, 2026 (EDT)

No Public Response
Cheyney University of Pennsylvania — the oldest HBCU in the US (founded 1837) — is a confirmed Canvas tenant within the Pennsylvania State System of Higher Education (PASSHE). No public Canvas-breach statement located through May 8, 2026.

**Oldest HBCU in the US (founded 1837).** Public HBCU, PASSHE member.

Cheyney University of Pennsylvania

Fayetteville State University

FSU-NC · NC · Silent through May 8, 2026 (EDT)

No Public Response
Per Instructure, NCCU and Fayetteville State are among the NC HBCU/IHE Canvas tenants surfaced via WRAL reporting on May 7-8, 2026. Vendor-confirmed Canvas tenant despite no institution-level statement.

HBCU gap-fill. Public HBCU in UNC System (~6,800 students). Vendor-confirmed Canvas tenant via WRAL.

WRAL

Albany State / Fort Valley State / Savannah State (GA HBCU cluster)

GA-HBCU-Cluster · GA · Silent through May 8, 2026 (EDT)

No Public Response
Three Georgia public HBCUs — Albany State University (~6K students), Fort Valley State University (~2,800 students, land-grant), and Savannah State University (~3K students, Georgia's oldest public HBCU) — are confirmed Canvas tenants within the University System of Georgia (USG). No public Canvas-breach statements located through May 8, 2026.

HBCU cluster gap-fill. USG member institutions. Pairs with Fulton / Cherokee / Forsyth GA K-12 already in hub.

Albany State / Fort Valley State / Savannah State

Bethune-Cookman / Edward Waters / Florida Memorial (FL HBCU cluster)

FL-HBCU-Cluster · FL · Silent through May 8, 2026 (EDT)

No Public Response
Three Florida private HBCUs — Bethune-Cookman University (~2,700 students, United Methodist), Edward Waters University (~1,300 students, AME Church; FL's first independent HBCU), and Florida Memorial University (~900 students; South Florida's only HBCU) — are confirmed Canvas tenants. No public Canvas-breach statements located through May 8, 2026 (FAMU upgraded to public-statement entry separately).

HBCU cluster gap-fill. Florida private HBCUs.

Bethune-Cookman / Edward Waters / Florida Memorial

Lincoln U PA / Langston / Wilberforce / Central State / Kentucky State / WV State / Bluefield State (HBCU silent cluster)

HBCU-Silent-Cluster · HBCU · Silent through May 8, 2026

No Public Response
Seven additional public/private HBCUs confirmed silent through May 8, 2026: Lincoln University of Pennsylvania (~2K, oldest degree-granting HBCU, founded 1854), Langston University Oklahoma (~2K, land-grant; OK's only HBCU), Wilberforce University Ohio (~400, AME Church; oldest private HBCU, founded 1856), Central State University Ohio (~3K, land-grant; Ohio's only public HBCU), Kentucky State University (~2K, land-grant; KY's only public HBCU), West Virginia State University (~3,500, land-grant), Bluefield State University (~1K).

HBCU cluster gap-fill across PA / OK / OH / KY / WV, completes documented HBCU footprint.

Multiple HBCU institutional pages

Pasco / Marion / St. Lucie / Volusia / Hillsborough verify FL (silent FL K-12 Canvas tenants)

FL-K12-Silent-Cluster · FL · Silent through May 8, 2026 (EDT)

No Public Response
Four confirmed Florida K-12 Canvas tenants without public breach statements as of May 8: Pasco County Schools (~68K students, Canvas branded 'myLearning'), Marion County Public Schools (~42K, 'MCPS-adopted LMS'), St. Lucie Public Schools (~41K, district LMS), and Volusia County Schools (~60K, status update posted but verbatim not retrievable). Adds to documented FL Canvas footprint (Brevard, Duval, Seminole, Hillsborough, Pinellas, Orange, Collier, Lee, Hawaii state DOE already covered).

FL K-12 cluster expansion. Pasco was featured in an Instructure case study.

Multiple FL K-12 sources

UNC Chapel Hill

UNC · NC · Silent through May 8, 2026 (EDT)

No Public Response
UNC Chapel Hill is part of the UNC System Canvas standardization. Sakai was historically UNC's LMS; Canvas standardization is rolling out per UNC System Board of Governors vote. No public Canvas-breach statement located through May 8, 2026 for UNC Chapel Hill main campus.

Public R1, AAU. UNC System has voted to standardize on Canvas.

UNC Chapel Hill

NC State University

NCSU · NC · Silent through May 8, 2026 (EDT)

No Public Response
NC State is a confirmed Canvas tenant within the UNC System. No public Canvas-breach statement located through May 8, 2026.

Public R1, land-grant (~37K students).

NC State Canvas

East Carolina University

ECU · NC · Silent through May 8, 2026 (EDT)

No Public Response
East Carolina University is a confirmed Canvas tenant within the UNC System. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~28K students).

ECU Canvas

Appalachian State University

App State · NC · Silent through May 8, 2026 (EDT)

No Public Response
Appalachian State University is a confirmed Canvas tenant within the UNC System. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~21K students).

Appalachian State Canvas

UNC Charlotte

UNCC · NC · Silent through May 8, 2026 (EDT)

No Public Response
UNC Charlotte is a confirmed Canvas tenant within the UNC System. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~30K students).

UNC Charlotte Canvas

Western Carolina University

WCU · NC · Silent through May 8, 2026 (EDT)

No Public Response
Western Carolina University is a confirmed Canvas tenant within the UNC System. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~12K students).

WCU Canvas

East Tennessee State University

ETSU · TN · Silent through May 8, 2026 (EDT)

No Public Response
East Tennessee State University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R2 (~14K students).

ETSU Canvas

University of Maryland, Baltimore County

UMBC · MD · Silent through May 8, 2026 (EDT)

No Public Response
UMBC is a confirmed Canvas tenant within the University System of Maryland (USM). No public Canvas-breach statement located through May 8, 2026.

Public R1 (~14K students). USM member.

UMBC Canvas

Towson University

Towson · MD · Silent through May 8, 2026 (EDT)

No Public Response
Towson University is a confirmed Canvas tenant within the University System of Maryland (USM). No public Canvas-breach statement located through May 8, 2026.

Public masters (~20K students).

Towson Canvas

University of Maryland Eastern Shore

UMES · MD · Silent through May 8, 2026 (EDT)

No Public Response
University of Maryland Eastern Shore — Maryland's land-grant HBCU — is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

**HBCU gap-fill.** Public HBCU, land-grant (~3K students). USM member.

University of Maryland Eastern Shore

University at Albany (SUNY)

UAlbany · NY · Silent through May 8, 2026 (EDT)

No Public Response
University at Albany (SUNY) is a confirmed Canvas tenant within the SUNY system. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~17K students).

UAlbany Canvas

Binghamton University (SUNY)

Binghamton · NY · Silent through May 8, 2026 (EDT)

No Public Response
Binghamton University (SUNY) is a confirmed Canvas tenant within the SUNY system. No public Canvas-breach statement located through May 8, 2026.

Public R1, AAU (~18K students).

Binghamton Canvas

UMass Boston / Lowell / Dartmouth (UMass System cluster)

UMass-System · MA · Silent through May 8, 2026 (EDT)

No Public Response
UMass Boston, UMass Lowell, and UMass Dartmouth are all confirmed Canvas tenants within the UMass System. UMass Amherst already responded (in hub). No additional public Canvas-breach statements located through May 8, 2026 for the other UMass campuses.

UMass System cluster gap-fill. ~13K (Boston) + 18K (Lowell) + 8K (Dartmouth) students.

UMass Dartmouth Canvas

Drexel University

Drexel · PA · Silent through May 8, 2026 (EDT)

No Public Response
Drexel University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1 (~22K students). Pairs with Penn (in hub).

Drexel Learn Canvas

Temple University

Temple · PA · Silent through May 8, 2026 (EDT)

No Public Response
Temple University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1 (~30K students). Pairs with Penn / Drexel.

Temple Canvas

Villanova University

Villanova · PA · Silent through May 8, 2026 (EDT)

No Public Response
Villanova University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, Catholic/Augustinian (~10K students).

Villanova Canvas

Fordham University

Fordham · NY · Silent through May 8, 2026 (EDT)

No Public Response
Fordham University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, Catholic/Jesuit (~17K students).

Fordham Canvas

Syracuse University

Syracuse · NY · Silent through May 8, 2026 (EDT)

No Public Response
Syracuse University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1 (~22K students).

Syracuse Canvas

Rochester Institute of Technology

RIT · NY · Silent through May 8, 2026 (EDT)

No Public Response
RIT is a confirmed Canvas tenant (myCourses / Canvas). No public Canvas-breach statement located through May 8, 2026.

Private R2 (~19K students).

RIT myCourses Canvas

University of Pittsburgh

Pitt · PA · Silent through May 8, 2026 (EDT)

No Public Response
University of Pittsburgh is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Public R1, AAU (~33K students).

Pitt Canvas

Case Western Reserve University

CWRU · OH · Silent through May 8, 2026 (EDT)

No Public Response
Case Western Reserve University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, AAU (~12K students).

CWRU Canvas

Emory University

Emory · GA · Silent through May 8, 2026 (EDT)

No Public Response
Emory University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, AAU (~16K students). Pairs with UGA / Georgia Tech.

Emory Canvas

Wake Forest University

Wake Forest · NC · Silent through May 8, 2026 (EDT)

No Public Response
Wake Forest University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R2 (~9K students).

Wake Forest Canvas

Carnegie Mellon University

CMU · PA · Silent through May 8, 2026 (EDT)

No Public Response
Carnegie Mellon University is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026.

Private R1, AAU (~16K students). Pittsburgh.

CMU Canvas

MIT (Massachusetts Institute of Technology)

MIT · MA · Silent through May 8, 2026 (EDT)

No Public Response
MIT uses Canvas as one of multiple LMSs (along with Stellar and edX). No public Canvas-breach statement located through May 8, 2026 — silence is notable given MIT appears on multiple ShinyHunters-named victim aggregations.

Private R1, AAU (~12K students). Hybrid LMS environment.

MIT Canvas

Yale University

Yale · CT · Silent through May 8, 2026 (EDT)

No Public Response
Yale University uses Canvas alongside other learning platforms. No public Canvas-breach statement located through May 8, 2026.

Private R1, AAU (~14K students). Pairs with UConn (in hub).

Yale Canvas

Dartmouth College

Dartmouth · NH · Silent through May 8, 2026 (EDT)

No Public Response
Dartmouth College is a confirmed Canvas tenant. No public Canvas-breach statement located through May 8, 2026 — pairs with UNH in hub.

Private R1, Ivy League (~6K students).

Dartmouth Canvas

Elizabeth City State University

ECSU · NC · May 8, 2026 (EDT)

Press Release
Elizabeth City State University is aware of the recent cybersecurity incident involving the Canvas Learning Management System. We appreciate your patience, understanding and flexibility as we work through this matter together. Please continue to monitor official university communication channels for updates.

**HBCU PUBLIC STATEMENT, third confirmed (after Morgan State + FAMU + Lincoln MO + NCCU).** Public bachelors HBCU (~2K students) in UNC System.

The Daily Advance

North Carolina Central University (reporter-mediated)

NCCU-Statement · NC · May 8, 2026 (EDT)

Press Release
NC Central told ABC11 that it was informed there had been no evidence of ongoing malicious activity and notified federal authorities, including the FBI and the Cybersecurity and Infrastructure Security Agency.

**HBCU PUBLIC STATEMENT (reporter-mediated).** Updates earlier silent NCCU entry, NCCU statement to ABC11 explicitly mentions FBI/CISA notification.

ABC11 Raleigh-Durham

PUC Chile (Pontificia Universidad Católica de Chile)Leak list

UC Chile · CL · Silent through May 8, 2026 (CLT)

No Public Response
Per Diario Financiero May 7 reporting, PUC Chile appears on the ShinyHunters affected_schools list among Chilean universities. PUC Chile [migrated all undergraduate and graduate courses to Canvas](https://www.uc.cl/temas/canvas-uc/) under its 2020-2025 strategic plan. No public statement from UC's Centro de Desarrollo Docente indexed.

**Second Chile entry in hub (after UAndes).** Top-ranked private R1 in Chile. Named on ShinyHunters leak list per local Chilean financial paper.

Diario Financiero

Chilean university cluster (UDP / UNAB / UDD / U Autónoma)

CL-Cluster · CL · Silent through May 8, 2026 (CLT)

No Public Response
Four additional Chilean Canvas tenants named on the ShinyHunters affected_schools list per Diario Financiero: Universidad Diego Portales (UDP, runs udp.instructure.com); Universidad Andrés Bello (UNAB, migrated Blackboard→Canvas in 2023); Universidad del Desarrollo (UDD, 'Aula Digital' Canvas since 2020); Universidad Autónoma de Chile (Canvas 'Campus Digital'). All silent through May 8, 2026.

Chilean cluster expansion, Chile is the highest-density Canvas adoption country in Latin America.

Diario Financiero

Texas State University

TXST · TX · May 7, 2026 evening CDT

Faculty / Student Email
We are working to mitigate the impacts of the Canvas outage that affected our campuses and thousands of institutions across the country. Because it is finals week, I ask that you work to provide your students with the needed alternatives or extensions that are necessary to support their ability to complete the final exams and assignments.

Public R2, HSI. Provost Pranesh Aswath email. CISO Dan Owen noted Texas State was NOT on ShinyHunters' affected list but acted out of caution.

The University Star (TXST)

Saint Louis University

SLU · MO · May 7, 2026 · 9:52 PM CDT

Faculty / Student Email
Provost Mike Lewis instructed faculty to inform students about the outage and any possible adaptations to be made and told students to not access Canvas until the issue is resolved.

Private R1, Catholic/Jesuit.

The University News (SLU)

Fayette County Public Schools

FCPS-KY · KY · May 7 · 10 PM EDT through May 8 · 7 AM EDT

Campus Alert
Around 10 p.m. on May 7, FCPS leaders said Canvas and other related services were rendered unavailable. Just before 7 a.m. Friday May 8, district leaders said Canvas issues were resolved. The incident affected FCPS's use of Canvas for students in grades 6 through 12, though the district said its internal network and systems were not involved.

Lexington, KY. **9-hour outage window precisely documented**, useful telemetry data point. ~42K students.

FOX 56 Lexington

Southern Methodist University

SMU · TX · May 7, 2026 · 8:12 PM CDT

Deadline Change
All final exams originally scheduled for Friday, May 8, will be postponed until Sunday, May 10. Exams will take place at the same locations and start times.

Private R1 (Methodist). Specific exam reschedule date, second institution after JMU to publicly commit to a rescheduled finals date.

SMU IT Connect / SMU Aware

University of Southern California

USC · CA · May 7, 2026 evening PDT

Press Release
USC is working with the students and faculty in programs affected by the Canvas issue.

Private R1, AAU. USC's main LMS is Brightspace for some schools, partial Canvas footprint.

LA Times via DNYUZ

University of Illinois Urbana-Champaign

UIUC · IL · May 7, 2026 evening CDT

Deadline Change
The university is postponing all final exams and assignments scheduled for Friday, Saturday, or Sunday, including those for classes that don't use Canvas.

**Most aggressive accommodation posture**, postponed even classes NOT using Canvas. Public R1, Big Ten flagship.

WAND-TV / Chambana Today

University of Oxford

Oxford · UK · May 8, 2026 (BST)

Campus Alert
Access to Canvas has been temporarily suspended by the University as a precautionary measure following an external breach of Instructure, the third-party supplier of Canvas. Oxford was named among 8,000+ affected institutions; the university acted to prevent further misuse while Instructure investigates.

**Only major university observed to fully suspend Canvas access at university level.** Distinctive among UK responses. Replaces WebLearn.

Cherwell (Oxford student newspaper)

Yale University

Yale · CT · May 7, 2026 evening ET

Press Release
Yale was notified of a security incident involving unauthorized access to user data in Canvas, potentially including names, email addresses, and Canvas messaging. There is no evidence that the information has been shared publicly. Yale has not been singled out in the breach.

Ivy / private R1, AAU. Yale Daily News separately covered the breach noting delayed final grade deadline.

Canvas @ Yale + Yale Daily News

University of Galway

Galway · IE · May 8, 2026 (IST)

Campus Alert
Services have been restored following a relatively low level of disruption in the last 24 hours. We are continuing to liaise with the company affected to understand the full nature and extent of the breach.

**First Ireland entry in hub.** Migrated Blackboard→Canvas 2023/24. ~19K students.

University of Galway

University College Cork

UCC · IE · May 8, 2026 (IST)

OIT / Status Page
Major incident: Security incident involving Canvas. UCC posted on status.ucc.ie that systems were restored overnight and no evidence at that point that UCC student/staff data was leaked.

Third Ireland entry. UCC Status Page issued formal 'Major incident' designation.

UCC Status Page

Palomar College

Palomar · CA · May 7, 2026 · 3:57 PM PT

OIT / Status Page
Canvas is currently down due to a cybersecurity attack on Instructure. Fully exit Canvas if you are currently signed in by closing your browser; do not access or attempt to log back into Canvas until Palomar College provides further guidance through official communications. Currently, no other Palomar systems are impacted. As a precaution, please remain vigilant for phishing emails or suspicious messages claiming to be related to Canvas, account verification, or password resets.

North San Diego County community college; precise 3:57 PM PT timestamp.

Palomar College, ATRC

Baylor University

Baylor · TX · May 7, 2026 · 5:22 PM CT

OIT / Status Page
Canvas is currently unavailable university-wide. This is a nationwide issue. Earlier today, several universities using Canvas reported that their access to the system was blocked by a ransom notice, in response to which Instructure took Canvas offline. Users should not attempt to engage with or respond within the Canvas system until further notice. Do not click links in unsolicited messages claiming to be from Canvas, Instructure, or BaylorITS.

Baylor noted Bear ID passwords were not stored on Instructure servers because of DUO MFA.

Baylor ITS News

Houston Independent School District

HISD · TX · May 7, 2026 · evening CT

Press Release
HISD confirmed it was affected by the Instructure incident and stated that 'while Canvas works to resolve the issue,' the district is 'standing up a temporary Google site to provide access to curriculum materials.'

First major Texas K-12 district to publicly confirm impact and stand up a Canvas alternative (Google Sites failover for curriculum delivery).

KHOU 11 Houston

St. Petersburg College

SPC · FL · May 7, 2026 · evening ET

OIT / Status Page
St. Petersburg College has been notified that it is an affected institution following an earlier report from Instructure of a cybersecurity incident. According to earlier reports from Instructure, this information was limited to basic user details. Instructure temporarily took Canvas offline for all institutions as they continue to respond.

Florida community college, independent confirmation that Instructure took Canvas globally offline May 7 (contradicts vendor 'fully operational' status copy).

St. Petersburg College Newsroom

University of California, Santa Cruz

UCSC · CA · May 7, 2026 afternoon PT

Campus Alert
UC Santa Cruz has proactively disabled local access points to further safeguard our campus data.

ANOMALY: UCSC was NOT on ShinyHunters' named list, yet pre-emptively disabled access. Voluntary precautionary stance.

UC Santa Cruz News

University of Notre Dame

ND · IN · May 7, 2026 evening EDT

Press Release
We do not yet know whether Notre Dame data was involved in the compromise. The University is working directly with Instructure to determine the scope of any potential impact to our students, faculty, staff, and academic operations.

Catholic R1. Cautious 'don't know yet' framing more honest than most peers.

The Observer (Notre Dame)

Texas Tech University

TTU · TX · May 7, 2026 evening CDT

Faculty / Student Email
Students should not be academically penalized because of this disruption. Faculty should pause or adjust online assessments as needed and communicate directly with students using TTU email.

Public R1. RaiderCanvas explicitly named as breached.

KCBD Lubbock

University of Copenhagen (Absalon)

KU-DK · DK · May 8, 2026 (CEST)

Press Release
A hacker group has claimed responsibility for the attack, and the supplier has confirmed that the University of Copenhagen is affected. Instructure, the provider of Absalon (also known as Canvas), has confirmed the security breach. The American supplier shut down the system behind Absalon due to a major hacker attack without warning in the early hours of Friday, 8 May. The University of Copenhagen has notified the Danish Data Protection Agency on 5 May 2026.

Canvas branded locally as 'Absalon'. **Major Nordic finding**, KU is one of Northern Europe's largest universities. Notified Datatilsynet (Danish DPA) on May 5.

Københavns Universitet Nyheder

University of Witwatersrand (Wits)

Wits · ZA · Silent through May 8, 2026 (SAST)

No Public Response
Wits University runs Canvas as 'Ulwazi' (its rebranded LMS, live since 2022 after migrating from Sakai). No public Canvas-breach statement located through May 8, 2026 — Wits is the only confirmed Canvas tenant among major South African universities (UCT uses Vula/Sakai; Stellenbosch uses SUNLearn/Moodle; Pretoria uses clickUP/Blackboard).

First South Africa entry in hub. POPIA breach-notification regime applies.

Wits University Ulwazi LMS

NTNU (Norwegian University of Science and Technology)

NTNU · NO · Week of May 5, 2026 (CEST)

Press Release
NTNU confirms it has been affected by the Canvas data breach. The university reports that approximately 40,000 users are registered in Canvas, of which 11,000 are active in the ongoing implementation phase. Which data has actually been compromised is still unclear, but the platform stores names, email addresses, FS-numbers and messages between users. Intruders did not gain access to passwords, dates of birth or financial information.

Mid-Blackboard-to-Canvas migration during breach. 40,000 registered / 11,000 active users, unique numeric disclosure.

Techwatch.no

UiT The Arctic University of Norway

UiT · NO · Week of May 5, 2026 (CEST)

Press Release
UiT issued a news note 'Sikkerhetsbrudd i Canvas' confirming the institution was among those affected by the Instructure/Canvas breach. Names, email addresses, student IDs and messages between users may have been compromised; no passwords, dates of birth or financial information.
UiT, 'Sikkerhetsbrudd i Canvas'

Datatilsynet (Norwegian DPA)

Datatilsynet · NO · Week of May 5, 2026 (CEST)

Press Release
Datatilsynet published 'Datainnbrudd i læringsplattformen Canvas' confirming receipt of breach notifications from a growing number of Norwegian universities and colleges; the regulator described the incident as 'serious' with potentially large amounts of personal data at risk. Sikt subsequently confirmed nearly all Norwegian universities and colleges were affected — 32 institutions, up to approximately 250,000 students.

**Second international regulator to issue a public statement** (after OAIC Australia). Provides Norway-wide denominator: 32 institutions / ~250,000 students. Sikt = Norwegian NREN.

Datatilsynet

University of Bergen / UiA / USN / Inland / Stavanger / Molde / NIH / HiOf / MF (Norway cluster)

NO-Cluster · NO · Week of May 5, 2026 (CEST)

Press Release
Eight additional Norwegian Canvas tenants have published their own breach-notification pages: University of Bergen (Mitt UiB), University of Agder (UiA), University of South-Eastern Norway (USN), Inland Norway University of Applied Sciences (INN), University of Stavanger (UiS), Molde University College (HiMolde), Norwegian School of Sport Sciences (NIH), Østfold University College (HiOf — published May 4 / updated May 6), and MF Norwegian School of Theology. All notified Datatilsynet. Sikt is coordinating sector response.

Consolidated cluster entry covering 9 additional Norwegian institutions. Norway is the most comprehensively documented Nordic response per Sikt's coordination role.

Datatilsynet + multiple Norwegian institutional pages

Eötvös Loránd University (ELTE)

ELTE · HU · May 7-8, 2026 (CEST)

Press Release
ELTE's LMS transition page references Canvas security risk as a possible reason to accelerate Canvas shutdown. ELTE explicitly noted: 'a security risk associated with Canvas may result in an earlier shutdown than currently planned.' ELTE leadership selected Moodle as the strategic platform going forward; staged Canvas-to-Moodle migration scheduled Sept 2026 / Feb 2027.

**First Hungary entry in hub.** Canvas customer mid-migration to Moodle. ELTE is one of the few institutions to cite the breach as accelerating an LMS migration.

ELTE eLearning

Wits / University of the Witwatersrand (UPGRADE — public statement)

Wits-Active · ZA · Notified May 7; restored by May 8, 2026 (SAST)

Press Release
Instructure informed Wits and other universities across the world of a data breach to its systems on 7 May 2026. At Wits, Canvas is known locally as the Ulwazi learning management platform. The university is one of approximately 8,800 institutions worldwide affected. Information that may have been compromised includes student names and email addresses, student numbers, and conversations contained within Canvas inboxes. The university's learning management platform, Ulwazi, has since been restored. The cyber extortion group ShinyHunters posted a message on Ulwazi threatening to release the stolen data if a settlement was not negotiated by 12 May.

**UPGRADES earlier 'silent' Wits status, now a public-statement entry.** Confirmed defacement victim: ShinyHunters posted extortion message inside Ulwazi itself. POPIA breach-notification regime applies.

ITWeb + The Citizen + News24

American University in Cairo

AUC · EG · Silent through May 8, 2026 (EET)

No Public Response
AUC is a confirmed Canvas tenant via canvas.aucegypt.edu. AUC ran on Blackboard from 2009 through Spring 2024, then migrated to Canvas. AUC is the only confirmed Canvas tenant among major Egyptian universities (Cairo University, Ain Shams, Alexandria all use Moodle). No public Canvas-breach statement located through May 8, 2026.

**First Egypt entry in hub.** Mid-migration timing, Spring 2024 pilots, full transition still in progress when breach landed. Egypt has no general data breach notification law as of May 2026.

AUC Digital Transformation

Florida International University

FIU · FL · May 7, 2026 · 5:33 PM ET

Press Release
Canvas is currently unavailable due to a national cybersecurity incident affecting the platform. Institutions nationwide are experiencing similar disruptions. FIU is actively coordinating with Instructure, the company that operates Canvas, to assess the situation and determine next steps. Please be aware of potential phishing attempts offering to recover access to your Canvas data.
FIU News

University of Pennsylvania

Penn · PA · May 7, 2026 · 5:19 PM ET

Faculty / Student Email
Penn is actively investigating [the breach and is] working with Instructure to restore access to Canvas as soon as possible. This issue is not limited to Penn and is affecting multiple institutions who use Canvas.

Email signed by Vice Provosts Composto & Jordan-Sciutto and CISO Nick Falcone. ShinyHunters claims ~306,000 Penn affiliates affected, Penn's second ShinyHunters incident in 8 months.

The Daily Pennsylvanian

Kean University

Kean · NJ · May 7, 2026 · 5:12 PM ET

Faculty / Student Email
We have received reports that Instructure Canvas is currently experiencing issues. When attempting to login, many users are encountering a 'Canvas is currently undergoing scheduled maintenance' message. Canvas Support is aware of the issue and actively investigating. We will continue to update the University community on the progress of the service outage. Thank you for your understanding and patience during this time.

Notable for omitting any mention of the hack/breach in the initial email, framed as 'scheduled maintenance.'

The Tower (Kean student paper)

University of California, Irvine

UCI · CA · May 7, 2026 · 2 PM PT

Campus Alert
UCI Canvas was reported down due to the nationwide hack; the Office of Information Technology pointed students to system status updates and reminded faculty that finals delivery alternatives remain available.

UC system-wide takedown affected all 10 UC campuses simultaneously during finals.

New University (UCI)

Morgan State University

Morgan · MD · May 7, 2026 evening EDT

Press Release
Morgan State University Information Technology has issued an Instructure Incident Communications page confirming the Canvas vendor incident and outlining ongoing coordination with Instructure.

**FIRST CONFIRMED HBCU PUBLIC STATEMENT** in the corpus, highest-priority gap-fill (R2 HBCU, Maryland's preeminent public urban research university). Dedicated 'Instructure Incident Communications' page.

Morgan State University Information Technology

University of California, San Diego

UCSD · CA · May 7, 2026 afternoon PT

Press Release
UC San Diego confirmed it was among UC campuses affected by the ShinyHunters Canvas compromise; named on ShinyHunters' affected list along with UC Berkeley, UCLA, UC Davis, UC Riverside, and UC Irvine.
Times of San Diego

Washington State University

WSU · WA · May 7, 2026 afternoon PDT

OIT / Status Page
WSU Canvas was taken down following the Instructure security incident; it returned online after Instructure's nationwide hack containment.
WSU LMS Transition site

University of Houston

UH · TX · May 7, 2026 afternoon CDT

Campus Alert
The University of Houston is aware of a global service disruption affecting the Canvas LMS platform due to a cybersecurity incident involving Instructure.

Public R1, HSI.

The Daily Cougar (UH)

Seton Hall University

SHU · NJ · May 7, 2026 evening EDT (access restored ~11 PM)

Campus Alert
Seton Hall's Information Technology is working closely with Instructure and is monitoring the situation closely. SHU is also working with the Office of the Provost and the Deans on guidance regarding exams, assignments, and deadlines affected by the outage.

Catholic private masters.

The Setonian

Kent State University

Kent · OH · May 7, 2026 evening EDT

Press Release
Kent State joined institutions including Columbia, Rutgers, Princeton, Harvard and Georgetown in issuing statements alerting students to the Canvas hack.

Public R2, Ohio.

AOL / Ohio coverage

University of Houston-Downtown / Houston Community College

UH-D · TX · May 7, 2026 afternoon CDT

Campus Alert
University of Houston-Downtown and Houston Community College both confirmed Canvas usage and outage impact during the May 7 incident.

Public bachelors/masters, HSI. UH-D one of the most diverse 4-years in the US.

ABC13 Houston

Oregon State University

OregonSt · OR · May 7, 2026 · 1:40 PM PDT

OIT / Status Page
Instructure, the vendor that operates Canvas, experienced a system outage that began on 5/7/2026 around 1:40 PM Pacific Time. Users were unable to access Canvas at this time.

Public R1, land-grant. Disambiguate from Ohio State (already in hub).

Oregon State University Technology

University of Oregon

UO · OR · May 7, 2026 afternoon PDT

OIT / Status Page
University of Oregon and dozens of other institutions across the country experienced a Canvas outage. Information that may have been involved at affected institutions includes names, email addresses, student ID numbers, and messages exchanged within Canvas.

Public R1, AAU.

University of Oregon Service Status

University of Toronto

UofT · CA · May 7, 2026 · 4:30 PM EDT

No Public Response
The university declined to comment on the incident. Quercus (UofT's Canvas instance) has been down since approximately 4:30 PM EDT on May 7, 2026.

U15 leader explicitly declined comment. Quercus is UofT's Canvas brand. PIPEDA + Ontario FIPPA notification likely required despite silence.

The Varsity (UofT)

University of Kansas

KU · KS · May 7, 2026 · 3:30 PM CDT

Campus Alert
Students across University of Kansas campuses are unable to access Canvas Thursday due to a data breach of Canvas' parent company, Instructure, that is reportedly affecting colleges worldwide.

Public R1, AAU, Big 12.

University Daily Kansan

Northwestern University

Northwestern · IL · May 7, 2026 afternoon CDT

Press Release
Northwestern's Canvas site went down following the alleged Instructure breach; the university is monitoring the situation in coordination with Instructure.

Private R1, AAU, Big Ten.

The Daily Northwestern

University of Chicago

UChicago · IL · May 7, 2026 afternoon CDT

No Public Response
Canvas access at the University of Chicago was disrupted; UChicago did not issue an extensive public statement at time of CBS/NBC reporting.

ANOMALY: minimal public response from a major R1; flagged 'no-response-confirmed' for the public-statement audit.

CBS Chicago

New Mexico State University

NMSU · NM · May 7, 2026 afternoon MDT

Campus Alert
NMSU Information Security advises users not to log in, click on anything, or download any files from Canvas or Canvas-related emails/notifications. Please log out of Canvas until further notice.

**Most aggressive 'do-not-click' posture** among R1/R2 publics. Public R2, HSI, land-grant.

NMSU Round Up

Tulane University

Tulane · LA · May 7, 2026 afternoon CDT

Campus Alert
Instructure's Canvas LMS is currently experiencing an unexpected outage affecting access to courses and class materials. Instructure is working to remedy the outage to restore access to all the impacted Canvas environments.

Private R1, AAU.

MyTulane / Tulane LMS

Northern Arizona University

NAU · AZ · May 7, 2026 afternoon MST

Campus Alert
Northern Arizona University has been impacted by the attack. Instructure is reporting an issue affecting Canvas for users globally.

Public R2.

Arizona's Family / 12 News

Iowa State University

Iowa State · IA · May 7, 2026 afternoon CDT

Campus Alert
Iowa State University is confirmed Canvas tenant; the Iowa State Daily reported the May 7 outage during finals week alongside U Iowa (already in hub).

Public R1, Big 12, land-grant (~30K students).

The Gazette (Cedar Rapids)

University of Colorado Colorado Springs

UCCS · CO · May 7, 2026 · ~2:20 PM MT

Press Release
When it comes to best cyber security practice, you do not pay that ransom.

Direct quote from UCCS OIT Services Professional Brock Stamper.

The Scribe (UCCS)

Kansas State University

K-State · KS · May 7, 2026 · 3:20 PM CDT

Campus Alert
Canvas is unavailable at this time. We are actively working to review the issue.

Sent via K-State Alert system at 3:20 PM CDT, extremely brief 11-word emergency-style alert. Useful contrast to lengthy peer statements.

Kansas State Collegian

Universities of Wisconsin / UW–Madison

UW–Madison · WI · Outage began 3:10 PM CT, May 7, 2026

OIT / Status Page
We are aware and multiple teams are working to address this issue on behalf of our students. A nationwide security incident at Instructure, the vendor that operates Canvas, occurred on May 1, 2026. This incident impacted Canvas at thousands of institutions worldwide and was not directed at UW–Madison specifically. The Office of Cybersecurity and the Learn@UW Team are actively monitoring the situation and working with UW System Administration and the vendor, Instructure, to assess specific impacts to UW–Madison data. DoIT has not received notification of direct impacts to UW–Madison data. If Canvas asks students or professors to perform any action, such as clicking a link, logging in, resetting your password or completing any tasks — do not proceed. Those prompts are not legitimate while the system is down.
UW–Madison DoIT

University of Iowa

Iowa · IA · May 7, 2026 · ~3:00 PM CT

OIT / Status Page
ICON is unavailable due to national cybersecurity breaches that are affecting universities across the country.

ICON is the Iowa-branded name for Canvas. Outage struck during dead week before finals.

The Daily Iowan

University of Washington Bothell

UWB · WA · May 7, 2026 · 1:00 PM PT

Campus Alert
UW Information Technology learned today at 1 p.m. that Canvas, which is used for UW online learning, is experiencing a global outage due to an apparent security incident. Canvas is fully inaccessible to all users at this time.

Branch campus of UW system; published on the Emergency Blog (typically reserved for safety incidents), notable framing.

UW Bothell Emergency Blog

Hillsborough County Public Schools

HCPS-FL · FL · May 7, 2026

Press Release
The school district said it was told that the data accessed was limited to names, email addresses, and student ID numbers. 'At this time, no action is required by students, families, or staff.'

8th-largest school district in the U.S. (~225K students).

WFLA Tampa

Pinellas County Schools

PCS · FL · May 7, 2026

Press Release
Student and staff Canvas accounts in the Pinellas County Schools system were compromised in early May; officials said only basic user details were taken, including names, email addresses, and student ID numbers.

7th-largest district in Florida; Tampa Bay regional pair with HCPS.

Tampa Bay Times

University of California, Los Angeles

UCLA · CA · May 7, 2026 afternoon PT

OIT / Status Page
UCLA proactively disabled local access to Bruin Learn out of precaution while Instructure dealt with the outage.

Public R1 / UC flagship. Bruin Learn = UCLA's Canvas tenant.

UCLA Office of the Chief Information Security Officer

University of California, Davis

UC Davis · CA · May 7, 2026 · 1:00 PM PDT

Campus Alert
Starting at approximately 1 p.m. on Thursday, May 7, 2026, Canvas, UC Davis' primary learning management system, became unavailable following a global cybersecurity incident affecting its vendor, Instructure.
UC Davis News

Mississippi State University

MSU-MS · MS · May 7, 2026 · 3:00 PM CDT

Press Release
Today, May 7, 2026, at approximately 3 p.m., Instructure, the vendor that provides Canvas, was breached, resulting in Mississippi State University experiencing an outage to the Canvas Learning Management System related to an ongoing nationwide security incident. No MSU internal systems have been compromised by this event, and MSU passwords are not involved.

**Most precise timestamp of any institutional statement** (specifies 3 PM detection). Public R1, SEC, land-grant.

Mississippi State University Newsroom

University of Tennessee, Knoxville

UTK · TN · May 7, 2026 afternoon EDT

Campus Alert
We are aware of a nationwide Canvas outage. The University of Tennessee, Knoxville, is closely monitoring updates from Instructure and will share information as it becomes available.
UT Knoxville Office of the Provost

Boston College

BC · MA · May 7, 2026 afternoon EDT

Faculty / Student Email
Boston College ITS confirmed a nationwide Canvas outage affecting the university and committed to providing an update when more information becomes available.

Catholic/Jesuit private R1.

The Heights (BC)

University of Kentucky

UKy · KY · May 7, 2026 afternoon EDT

Social Media
We are aware of a nationwide issue impacting access to Canvas and are actively investigating the situation. At this time, users may experience difficulty logging in or accessing course materials.
Kentucky Kernel

University of Minnesota

UMN · MN · May 7, 2026 afternoon CDT

Press Release
The University of Minnesota was notified by Instructure of a cybersecurity incident affecting its clients worldwide. Users are unable to access Instructure's Canvas system.

Public R1, Big Ten/AAU.

Star Tribune

University of Washington (Seattle)

UW · WA · May 7, 2026 · 1:00 PM PDT

Campus Alert
This is a Canvas system issue affecting universities across the country. It is not specific to the UW and is not originating within UW systems. No sensitive student information was involved in the incident.

Public R1, AAU, Pac-12.

The Daily of the University of Washington

University of South Florida

USF · FL · May 7, 2026 afternoon EDT

Press Release
Canvas temporarily cannot be accessed and we are working with Instructure and law enforcement to assess any specific impacts to university systems or data.

Public R1 (Florida preeminent state university).

10 Tampa Bay (WTSP)

Brown University

Brown · RI · May 7, 2026 · afternoon ET

Campus Alert
Brown's Canvas instance was hacked in the nationwide ShinyHunters cyberattack on May 7. Faculty were instructed to consider extending deadlines.

Ivy-League impact during reading period; reporting paraphrased rather than direct vendor quote.

Brown Daily Herald

Charlotte-Mecklenburg Schools

CMS · NC · May 7, 2026

Press Release
CMS confirmed it is among the Charlotte-area school districts affected by the Canvas/Instructure breach; district leaders said they believe student and staff data may have been accessed but found nothing indicating passwords, birth dates, or financial information were involved.

2nd-largest district in NC (~140K students).

WCNC Charlotte

Indiana University

IU · IN · May 7, 2026 afternoon EDT

Campus Alert
IU instructors were unable to enter grades or view some submitted assignments during finals week as a result of the Canvas outage.

Public R1, Big Ten/AAU. Note: nearby Purdue does NOT use Canvas.

Indiana Daily Student

University of New Mexico

UNM · NM · May 7, 2026 afternoon MDT

Campus Alert
The University of New Mexico is aware of a cybersecurity incident reported by Instructure, the company that provides Canvas to UNM. This was a vendor incident — UNM's own systems and networks were not affected. Out of an abundance of caution, UNM recommends that UNM Canvas users be cautious of phishing attempts.

Public R1, HSI.

UNM IT Alerts

Wake County Public School System

WCPSS · NC · May 7, 2026

Press Release
WCPSS announced it would temporarily stop using Canvas and disabled the Canvas icon within the WakeID portal, instructing users not to attempt to access Canvas through alternate links or bookmarks until further notice. A spokesperson confirmed some students received the same ransom message that appeared on defaced login pages.

WCPSS, among NC's largest districts (~160K students), took the unusually aggressive step of fully disabling Canvas access rather than waiting for Instructure remediation.

ABC11 Raleigh-Durham

Hong Kong University of Science and Technology

HKUST · HK · Silent through May 8, 2026 (HKT)

No Public Response
HKUST has run Canvas as its primary LMS since Winter 2015/16, replacing the in-house LMES. No public Canvas-breach statement located through May 8, 2026 — HKUST is the only Hong Kong tier-1 university using Canvas (HKU uses Moodle; CUHK uses Blackboard; CityU and PolyU use Canvas but partially).

First Hong Kong entry in hub. HK PCPD breach-notification scheme is voluntary.

HKUST Canvas portal

National University of Singapore

NUS · SG · Silent through May 8, 2026 (SGT)

No Public Response
National University of Singapore is a confirmed Canvas tenant. NUS migrated from LumiNUS (in-house) to Canvas; LumiNUS was shut down December 2023. No public Canvas-breach statement located through May 8, 2026.

First Singapore entry in hub. NUS is a major SE Asia tier-1 institution.

NUS Canvas Transition page

City University of Hong Kong

CityU · HK · Silent through May 8, 2026 (HKT)

No Public Response
City University of Hong Kong is a confirmed Canvas tenant (Instructure published a CityU case study; CityU ITS lists Canvas as the unified LMS, AWS Singapore-hosted). No public Canvas-breach statement located through May 8, 2026.

Second HK entry.

CityU IT Services LMS

Hong Kong Polytechnic University

PolyU · HK · Week of May 7-8, 2026 (HKT)

Press Release
PolyU's preliminary assessment shows that around 42,000 students and staff may have had personal data exposed in the global Canvas/Instructure cybersecurity incident. The leaked information is understood to include names and email addresses. PolyU has notified the Office of the Privacy Commissioner for Personal Data (PCPD). Canvas@PolyU was soft-launched on May 4, 2026 — one week before the global incident became public — as part of PolyU's phased migration to Canvas under the Education 4.0 initiative.

**LARGEST SINGLE-INSTITUTION HONG KONG IMPACT: 42,000 USERS.** PolyU is one of 5 HK institutions PCPD-notified. Ironic timing: Canvas@PolyU soft-launched May 4, just days before the breach went public.

Dim Sum Daily HK + SCMP

Hong Kong cluster (5+ institutions, 72,571 affected)

HK-Cluster · HK · Week of May 7-8, 2026 (HKT)

Press Release
Per SCMP and Hong Kong PCPD reporting, seven Hong Kong educational institutions filed Canvas-breach notifications: HKUST, PolyU, Hong Kong Academy for Performing Arts (HKAPA — fully Canvas-dependent), Hong Kong Institute of Construction (HKIC, vocational), Hong Kong Education City Limited (HKEdCity, K-12 services aggregator), CityU, and Hong Kong Art School. Combined affected count: 72,571 Hongkongers per SCMP. This is a Norway-comparable comprehensive sector response on the Asia side.

**Hong Kong cluster, 72,571 affected total.** Upgrades earlier silent HKUST/CityU entries. PCPD voluntary breach-notification scheme triggered. Single largest non-US/Norway sector impact documented.

South China Morning Post + Hong Kong PCPD

Universiti Brunei Darussalam

UBD · BN · Silent through May 8, 2026 (BNT)

No Public Response
UBD's IT FAQ confirms Canvas is the official LMS for all modules, formally adopted March 12, 2020 during pandemic emergency online transition. UBD is the oldest and largest university in Brunei (~3,500 students). No public Canvas-breach statement located through May 8, 2026.

**First Brunei entry in hub.** Canvas adoption was originally a pandemic-era emergency decision.

UBD IT FAQ

DLSU / UP / UST (Philippines Canvas cluster — silent)

PH-Cluster · PH · Silent through May 8, 2026 (PHT)

No Public Response
Three additional Philippines Canvas tenants beyond Ateneo: De La Salle University (DLSU; Canvas adopted institution-wide), University of the Philippines system (UP Diliman + UP Manila + UP Los Baños + UP Visayas + UP Mindanao + UP Open University), and University of Santo Tomas (UST). All four are named as the country's top Canvas-adopting universities. No public statements from DLSU/UP/UST located.

Philippines Canvas cluster, Ateneo only one to issue a public advisory. UP is system-wide with 6 campuses.

Manila Bulletin

Keio University

Keio · JP · Silent through May 8, 2026 (JST)

No Public Response
Keio University is the rare confirmed Canvas tenant in Japan. Keio's Information Technology Center operates K-LMS, branded internally as 'Keio Learning Management System' but powered by Canvas LMS. Most Japanese tier-1 universities use proprietary or Moodle systems (UTokyo: ITC-LMS/UTOL; Kyoto: PandA; Osaka: WebClass/Moodle; Waseda: Waseda Moodle) — Keio is the standout Canvas adoption. No public Canvas-breach statement located through May 8, 2026.

**First Japan entry in hub.** ~33K students. Japan APPI breach-notification regime applies. All other Japanese tier-1 universities confirmed NOT Canvas.

Keio University ITC

Hanyang University

Hanyang · KR · Silent through May 8, 2026 (KST)

No Public Response
Hanyang University is the only major South Korean Canvas adopter on record — CIEE Study Abroad documentation confirms 'Hanyang employs its own learning management system, which is based on Canvas.' All other major Korean universities use proprietary or Moodle-based systems. Instructure announced South Korea market entry in 2024 to grow Canvas presence. No public Canvas-breach statement located through May 8, 2026.

**First South Korea entry in hub.** PIPA breach-notification regime (one of Asia's strictest, 72h notification for breaches >1,000 records).

CIEE Study Abroad

Flinders University (deadline extension)

Flinders-Deadline · AU · Week of May 7-8, 2026 (ACST)

Deadline Change
Flinders University acknowledged potential student data compromise from the Canvas/Instructure cybersecurity incident and extended assessment deadlines by 48 hours during the outage.

**First South Australia entry in hub.** Joins JMU + Birmingham + SMU + Emory + ECU + ISU in explicit-deadline-extension cohort. New Adelaide University selected Canvas July 2024 but is pre-operational.

ACS Information Age

University of Massachusetts Amherst

UMass Amherst · MA · May 7, 2026 (initial post May 3)

OIT / Status Page
UMass Amherst has been notified by Instructure that UMass Amherst was impacted by the recent cybersecurity incident affecting Instructure's product, Canvas. Based on what Instructure has told us to date, the data involved may include personal information such as names, email addresses, student ID numbers, and messages among users. Instructure has told us that they have found no indication that passwords, dates of birth, government identifiers, or financial information were involved. UMass Amherst IT is actively monitoring communications from Instructure and will share material updates provided by the vendor on this web page as they become available.

Notes a Turnitin/API key rotation side-effect.

UMass Amherst IT

University of Auckland

UoA · NZ · May 8, 2026 (NZST)

Campus Alert
The University of Auckland has been affected by a global cybersecurity incident involving the Canvas learning management system used by staff and students. Canvas is currently offline. The cybersecurity incident relates to Canvas data held by a third-party provider, Instructure. This was not a breach of the University's systems, and no other systems are at risk. Instructure has advised that the breach may include names, email addresses, student ID numbers and Canvas Inbox and Discussion messages of past and current users.

Most detailed published international notice. NZ Privacy Act 2020 notification likely triggered.

University of Auckland News

Auckland University of Technology

AUT · NZ · May 8, 2026 (NZST)

Press Release
AUT confirmed it was among NZ institutions affected by the global Instructure/Canvas breach; the university stated its own independent systems were not breached, only the third-party Canvas platform.
RNZ News

Te Herenga Waka — Victoria University of Wellington

VUW · NZ · May 8, 2026 (NZST)

Campus Alert
Vice-chancellor Nic Smith said 'bad actors' had accessed third-party software Canvas, but not the institution's independent system. The university's priority was protecting the security of student and staff information, and they had taken proactive steps, including temporarily taking the system offline while working with external experts.

VUW operates Canvas under its 'Nuku' branding. VC Nic Smith on record.

VUW Digital Solutions

Pasadena City College

PCC · CA · May 7, 2026

OIT / Status Page
Canvas is currently experiencing a widespread security incident and have shutdown all services. Instructure is working on resolving the issue. We will update this page as we learn more details. Action Required: Do not attempt to log in to Canvas until further notice. If prompted, do not click on any links, download any content, or open any file. Imposter websites and email phishing have popped up offering access to Canvas by inputting personal information such as Social Security Number and date of birth. Neither PCC nor Canvas requires this information.

Mid-size urban California community college; explicit phishing-imposter warning is unique among CC responses.

Pasadena City College, Canvas Outage Page

Arizona State University

ASU · AZ · May 7, 2026

Press Release
ASU is aware of an incident that has affected Canvas, the online platform students and faculty use to access courses and submit work, that has resulted today in users being redirected and rendering the platform inaccessible at this time. This incident is unrelated to any ASU-managed system. The university is looking into the extent to which any data has been compromised and is working with students and faculty to circumvent this disruption in the closing days of the semester.
ASU Media Relations

Clark County School District (Las Vegas)

CCSD · NV · May 7, 2026 (Thursday afternoon)

Campus Alert
Canvas is currently unavailable while the issue is being assessed and additional security measures are implemented. The district is asking families not to attempt to log in to Canvas until further notice and not to click any links that appear in the system.

5th-largest U.S. K-12 district (~300K students). Proactively disabled Canvas access. Confirms April 25 incident-onset date matching NCDPI/Instructure timeline.

Fox 5 Vegas (KVVU)

University of British Columbia

UBC · CA · May 7, 2026 (PDT)

OIT / Status Page
UBC community members should not log into Canvas until further notice. If users are logged in, they should log out immediately and not log back in until notified by UBC IT that it is safe to do so.

Most aggressive 'do-not-login' advisory observed globally. BC PIPA + federal PIPEDA obligations apply.

UBC IT Status Page

Simon Fraser University

SFU · CA · May 7, 2026 (PDT)

Press Release
SFU confirmed it was among institutions affected by the cyber breach of the Canvas learning software's parent company Instructure; the university said students' personal information could be affected.
CBC News

Portland Public Schools

PPS-OR · OR · May 7, 2026

Faculty / Student Email
Portland Public Schools said it was notified on Tuesday about the breach of Instructure, the vendor for its Canvas Learning Management System. An unauthorized party gained access to company systems, potentially compromising personal information such as names, email addresses, student ID numbers and user messages.

Largest Oregon district (~44K students).

KGW News (NBC Portland)

Beaverton School District

BSD-OR · OR · May 7, 2026

Faculty / Student Email
Beaverton School District sent out warnings to families this week about a data breach involving Canvas. The unauthorized party potentially compromised personal information, such as names, email addresses, student ID numbers and user messages.

3rd-largest Oregon district (~39K students).

KGW News

Tigard-Tualatin School District

TTSD · OR · May 7, 2026

Faculty / Student Email
Tigard-Tualatin School District warned families this week about a data breach involving Canvas. Personal information potentially compromised includes names, email addresses, student ID numbers and user messages.

OR suburban Portland district (~12K students).

KGW News

Stanford University

Stanford · CA · May 7, 2026 (PDT)

Campus Alert
Criminal hacker group ShinyHunters breaches Canvas — Stanford named on victim list per Stanford Daily May 7 coverage.

Confirms Stanford on the affected list; specific Stanford-IT statement not yet located in indexed coverage.

Stanford Daily

Southern California school districts (multiple)

S-CA-K12 · CA · May 7, 2026

Press Release
Massive Canvas data breach impacting several schools across Southern California per ABC7 Los Angeles. Districts not yet individually named in coverage.

Multi-district SoCal K-12 confirmation; LAUSD not impacted (Schoology), so this excludes the largest district.

ABC7 Los Angeles

Spokane Public Schools

SPS · WA · May 7, 2026 (PDT)

Press Release
Canvas recently experienced a nationwide security breach. SPS maintains strong security measures to protect the privacy and confidentiality of all student and staff information. We are not aware of any sensitive data contained in this breach. We will provide updates as more information becomes available.

~30K students. First confirmed Pacific NW K-12 district response.

FOX 28 Spokane

San José State University

SJSU · CA · Week of May 4, 2026 · restored May 8 (PDT)

Press Release
San José State University was informed in the week of May 4, 2026 of a cybersecurity incident involving Instructure, the vendor that provides Canvas. The university warned students and faculty that cyber criminals might have access to personal information including names, email addresses, student ID numbers, and user messages. As of May 8, Canvas is operational again.

**AANAPISI + HSI gap-fill, first AANAPISI + HSI public-response page in the hub.** Public R2 (~36K students).

SJSU University Marketing & Communications

San Francisco State University

SFSU · CA · May 7-8, 2026 (PDT)

Faculty / Student Email
SFSU issued campus-wide messaging regarding the Canvas outage that began Thursday, May 7, until Friday, May 8, 2026. The university continued working with the CSU Chancellor's Office, Instructure, and campus partners to gather information. Students were directed to contact Academic Technology (at@sfsu.edu or 415-405-5555) for questions.

AANAPISI + HSI. Public masters (~24K students). Operationally specific support routing (at@sfsu.edu, 415-405-5555).

SFSU Academic Technology Central

California State University, Northridge

CSUN · CA · May 7-8, 2026 (PDT)

Campus Alert
CSUN issued a dedicated CSUN Alert: Instructure (Canvas) Update page covering the May 2026 Canvas cybersecurity incident, advising the campus community that students were unable to access classes, exams, and assignments while Canvas was offline, and warning of the ShinyHunters ransom threat with a May 12 deadline.

HSI + AANAPISI. Public masters (~38K students). One of the largest HSI institutions in the US.

CSUN Alert, Instructure (Canvas) Update

California State University, Long Beach

CSULB · CA · Finals week, May 7-8, 2026 (PDT)

Faculty / Student Email
An email to students and staff at Cal State Long Beach indicated that names, email addresses, campus ID numbers and user messages may have been affected by the Canvas/Instructure breach. The notice was issued during finals week and warned of the ShinyHunters extortion deadline of May 12, 2026.

HSI + AANAPISI (~40K students).

Long Beach Post quoting CSULB email

Sonoma State University

SSU-CA · CA · Early May 2026 (PDT)

Press Release
Sonoma State University posted an Important Update: Canvas Security Incident to its SSU News campus-updates feed in early May 2026, joining the CSU campus-by-campus response pattern.

Public masters, HSI federally-designated (~6K students). 6th CSU campus public statement in hub.

Sonoma State News

Utah State Board of Education

USBE · UT · May 7, 2026

Press Release
We have a state contract that allows K-12 schools to utilize the product if they wish. Not all schools use Canvas, but I would say most do. We don't currently have the information [of which schools or districts were impacted] at this time.

State board response. Notable because Instructure is HQ'd in Salt Lake City. Utah AG silent on home-state vendor.

KUTV 2News (Katy Challis, USBE Director of Privacy)

Granite School District

Granite-UT · UT · May 7, 2026

Faculty / Student Email
Granite School District received communication from Instructure that they had been impacted by this nationwide data breach. Instructure told Granite School District: At this time, we have found no indication that passwords, dates of birth, government identifiers, or financial information were involved.

3rd-largest Utah district (~62K students).

ABC4 Utah

Davis School District

Davis-UT · UT · May 7, 2026

Faculty / Student Email
Davis School District teachers will provide flexibility on due dates for students. Davis School District does not provide sensitive information such as passwords, government-issued identification numbers, birth dates, or financial information to Instructure.

2nd-largest Utah district (~73K students). Notable for vendor-data-minimization framing.

ABC4 Utah

Idaho State University

ISU · ID · May 7, 2026 (MDT)

Deadline Change
All final exams scheduled after noon are canceled and will not be rescheduled or counted toward final grades.

**Most aggressive academic accommodation** in the dataset, outright canceled all afternoon finals on May 7 rather than rescheduling.

Idaho State Journal

Norman Public Schools

NPS-OK · OK · May 7, 2026

Faculty / Student Email
We have received confirmation that some NPS student data was included in the breach. In compliance with Oklahoma student data privacy standards, we are notifying affected families and staff. Based on the information provided to us, the data involved appears to include limited personal information. At this time, there is no indication that passwords, dates of birth, government identifiers, or financial information were involved. There is no indication that Norman Public Schools' internal systems or network were compromised.

Only district to explicitly invoke a state student-privacy framework ('Oklahoma student data privacy standards'), a possible template for districts in the 38 states with student-privacy statutes. Replaces earlier shorter NPS entry.

OU Daily

Austin Independent School District (BLEND)

AISD · TX · May 7, 2026 (CDT)

Campus Alert
BLEND (the district's branded Canvas instance) was affected by the cyberattack. Some user data was exposed, including names, email addresses, student IDs, and messages. Hacker message was reportedly displayed on BLEND login page; screenshots received from McCallum HS parents and teachers.

~73K students. Uses Canvas under brand 'BLEND.' Defacement HTML reportedly visible to parents and faculty before global takedown.

KUT News (Austin NPR)

Conroe Independent School District

Conroe-ISD · TX · May 7, 2026 (CDT)

Press Release
Conroe ISD, along with universities and school districts globally, has been impacted by the ongoing Canvas by Instructure security incident. Conroe ISD has communicated with families and staff on the situation. We are actively monitoring updates from Instructure and will continue updating families and staff as additional information becomes available.

~70K students, Houston-area suburban.

FOX 26 Houston

Pearland Independent School District

Pearland-ISD · TX · May 7, 2026 (CDT)

Press Release
Instructure, the company that hosts Canvas, notified Pearland ISD of a cybersecurity incident that was not directed at the district but is part of a nationwide breach affecting nearly 9,000 school districts and universities across the country. The only data Pearland ISD shares with Canvas consists of student names and email addresses. The district has safety measures in place that further mitigate any risk; they keep Canvas messaging disabled and restrict student email accounts to only receive messages from .edu or military domains.

~21K students. **Notable for technical risk-mitigation detail**, Canvas messaging disabled and email-domain whitelist (.edu / .mil only), example of pre-existing controls that reduced exposure.

FOX 26 Houston

Katy Independent School District

Katy-ISD · TX · May 7, 2026 (CDT)

Press Release
Canvas has indicated that certain user information may have been exposed, including names, email addresses, student ID numbers, and messages exchanged within the platform. However, more sensitive personal information, such as Social Security numbers, home addresses, and passwords, is not stored within Katy ISD's Canvas environment and was not impacted.

~95K students. Houston-area suburban; Canvas as primary LMS.

FOX 26 Houston

Wichita Public Schools (USD 259)

USD 259 · KS · May 7, 2026 (CDT)

Press Release
We're aware of the nation-wide issue, but we're investigating to see if we have been impacted.

Largest KS K-12 district (~46K students). Cautious wait-and-see posture; contrast Galena KS (already in hub).

KSN Wichita

Iowa City Community School District

ICCSD · IA · May 7, 2026 (CDT)

Campus Alert
Iowa City Community School District's Canvas site went down Thursday after Instructure announced it was investigating a cyberattack and later revealed it had suffered a data breach exposing users' names, email addresses and private messages.

Iowa K-12 (~14K students). Pairs with U Iowa / Iowa State.

The Gazette (Cedar Rapids)

Oklahoma City Public Schools

OKCPS · OK · May 7, 2026 (CDT)

Press Release
We want to inform you of a recent cybersecurity incident involving Canvas, owned by Instructure. Canvas is the learning management system used by Oklahoma City Public Schools (OKCPS). Instructure confirmed that an unauthorized third party gained access to certain user data within its systems. Compromised data may include names, email addresses, student ID numbers and private messages sent within Canvas.

~33K students. Oklahoma's largest K-12 district. Tightens OK cluster (Norman PS + Galena KS already in hub).

News9 Oklahoma City

Lincoln University of Missouri

Lincoln MO · MO · May 7, 2026 (CDT)

Press Release
Lincoln University in Jefferson City confirmed it is being impacted by the widespread, ongoing Canvas outage, alongside Stephens College in Columbia. Officials confirmed the impact to local Missouri news outlets as Canvas was taken offline May 7-8, 2026.

**HBCU gap-fill, first HBCU in Missouri.** Public HBCU, land-grant (~1,800 students). Differentiate from Lincoln U Pennsylvania.

KCUR

Stephens College

Stephens · MO · May 7, 2026 (CDT)

Press Release
Stephens College in Columbia, Missouri confirmed that it is being impacted by the widespread, ongoing Canvas outage. Stephens officials made the confirmation to local Missouri news outlets as Canvas was taken offline May 7-8, 2026.

Private women's-focused liberal arts college (~700 students). One of the smallest US private institutions to publicly acknowledge impact.

KCUR

University of North Texas

UNT · TX · May 7, 2026 (CDT)

Press Release
As a precautionary measure related to the recent security incident involving Instructure Canvas, campus-wide access to the Canvas application has been temporarily disabled while the parent company, Instructure, continues its investigation and remediation efforts. Academic and IT leaders at each institution will be convening to discuss how to manage pending assignments, any final exams, grades, etc. and will be providing relevant information to their student populations.

Public R1 (~46K students). Proactively disabled Canvas. Pairs with TWU response.

KERA News

James Madison University

JMU · VA · May 7, 2026

Deadline Change
Canvas sites at universities worldwide, including JMU, are down in response to a security breach. The duration of the outage is unknown. Plan for upcoming exams and grading without Canvas access. Exams scheduled for Friday, May 8 at 8 a.m. and 10:30 a.m. will be delayed until Wednesday, May 13. Canvas is currently inaccessible as Instructure takes measures to remediate the situation, and has taken steps to secure the platform, including remediating the underlying vulnerability. Additionally, Instructure has engaged a third-party forensics firm for an investigation and notified law enforcement authorities.

First documented US institution to formally postpone final exams (May 8 → May 13).

JMU Computing, Canvas Outage

Orange County Public Schools

OCPS · FL · May 7, 2026

Press Release
Orange County Public Schools officials said that Instructure had confirmed on May 2 that an unauthorized third party gained access to certain user data within its systems. There is currently no evidence that passwords, Social Security numbers, birth dates, or financial information were compromised in the breach.

9th-largest U.S. district (~210K students).

Click Orlando (WKMG)

Montgomery County Public Schools

MCPS-MD · MD · May 7, 2026

Campus Alert
myMCPS Classroom (Canvas) has been temporarily disabled due to a reported widespread cybersecurity concern involving the platform. Out of an abundance of caution, please do not attempt to log in while MCPS and the vendor assess the issue.

Largest Maryland district (~160K students). Among the first major Atlantic-coast districts to proactively disable Canvas.

The MoCo Show

Virginia Beach City Public Schools

VBCPS · VA · May 7, 2026

Faculty / Student Email
Virginia Beach City Public Schools notified families and staff about a cybersecurity incident involving unauthorized access to certain student and staff information. Impacted students will not be penalized for missed assignments. The Virginia Department of Education, Virginia Fusion Center, and legal counsel have been contacted.

Largest Virginia district (~64K students). **Only known district to publicly cite state Fusion Center engagement**, only public hint of intel-community coordination.

WTKR News 3

Charlottesville City Schools

CCS-VA · VA · May 7, 2026

Faculty / Student Email
Only parent accounts on Canvas, which contain very limited information, were affected. Student and staff accounts on Canvas do not appear to have been breached because they are protected by multifactor authorization. Data in parent accounts includes parent email, parent name, student name, class announcements, class assignments, and calendar events.

**Most specific data-scope description in entire dataset**, confirms MFA worked as a partial mitigation: parent accounts (no MFA enforced) breached, staff/student accounts (MFA-protected) not breached.

29News (CBS-19 Charlottesville)

York County School District 1 (Clover)

YCSD-1 · SC · May 7, 2026

Press Release
York County District 1 said its own investigation found that the data it sends to Canvas does not include any information that is personally identifiable.

Strongest 'data-minimization' defensive claim in the dataset. Possible model for parent-pacification messaging.

WCNC Charlotte

Rock Hill School District

RHSD · SC · May 7, 2026

Press Release
An official for Rock Hill Schools said their district is still determining the impact of the data breach.

Largest district in York County, SC (~17K students). One of only two SC K-12 districts publicly responding.

WCNC Charlotte

Port Byron Central School District

Port-Byron-NY · NY · May 7, 2026

Faculty / Student Email
Information potentially accessed during the breach may include student and parent names, email addresses, student ID numbers and internal Canvas messages exchanged between students and teachers. The district said there is currently no evidence that passwords or dates of birth were compromised. The district will continue monitoring updates from Instructure's ongoing forensic investigation.

Tiny upstate NY rural district (~700 students). **Only confirmed New York State K-12 district** to formally notify families, NYC DOE silence is correctly explained: NYC DOE uses Google Classroom, not Canvas.

Fingerlakes1.com

Indiana colleges (multi-institution)

IN-Multi · IN · May 7, 2026

Press Release
Multiple Indiana colleges impacted by Canvas hack per WTHR Indianapolis coverage. Specific IU/Purdue/Notre Dame statements not yet individually located in indexed coverage.

Multi-institution Indiana confirmation; IU and Purdue likely subset but not individually quoted.

WTHR Indianapolis

Anne Arundel County Public Schools

AACPS · MD · May 7, 2026 (EDT)

Campus Alert
Anne Arundel County Public Schools has shut down access to Canvas after detecting suspicious activity. Users should not attempt to log in or enter their usernames or passwords on any interface until further notice.

5th-largest district in Maryland (~83K students). **Aggressive proactive Canvas shutdown**, joins WCPSS / Cherokee GA / Brevard FL pattern.

Fox News (citing AACPS)

Cherokee County School District

CCSD-GA · GA · May 7, 2026

Press Release
Cherokee County School District has been informed by Instructure, the vendor for our Canvas learning management system, of a cybersecurity incident. We have stopped all access to Canvas until further notice. According to Instructure's communication, basic user data such as names and email addresses, and internal messages may have been accessed. However, student grades were not accessed, nor were passwords. Canvas does not store Social Security numbers or financial information for any users.

~42K students in GA exurbs. Took unusual aggressive step of fully stopping Canvas access. Explicit assurance grades, SSNs, financials not in Canvas, useful template for parent communications.

Cherokee County School District board post

Brevard Public SchoolsLeak list

BPS-FL · FL · May 7, 2026

Campus Alert
Brevard Public Schools has disabled student access to the Canvas learning management system as a precaution after a worldwide ransomware attack on Canvas's parent company.

~73K students on FL Space Coast. **Named on ShinyHunters leak list** alongside Princeton, Cincinnati Public Schools, UC Berkeley, implies record exfiltration claim, not just LMS access disruption.

The Space Coast Rocket

Knox County Schools

KCS-TN · TN · May 7, 2026 (EDT)

Faculty / Student Email
While we understand this may cause concern, please know that there is no additional action needed at this time. Our Technology Department is working with Instructure, which is the vendor for Canvas, and the message has been removed. KCS is not the only district that has been impacted by the cybersecurity incident.

94-school district (~60.5K students). Confirms unauthorized message visible to students/staff at login on May 7 (defacement event).

WBIR Knoxville

Forsyth County Schools

FCS-Forsyth · GA · May 7, 2026

Press Release
Forsyth County Schools has been notified that the district was impacted by the Canvas/Instructure cybersecurity breach. Compromised data may include names, email addresses, student ID numbers, and Canvas in-platform messages. There is no evidence that passwords, dates of birth, government identifiers, or financial information were involved.

~55K students fast-growing exurban district north of Atlanta. Tightens Atlanta-region cluster: Fulton + Cherokee + Forsyth all named.

Forsyth County Schools

Dartmouth College (Canvas down)

Dartmouth-Down · NH · May 7-8, 2026

Press Release
Canvas site down after Instructure breach, per The Dartmouth (student paper) May 7-8 reporting.

Updates earlier Dartmouth silent entry, Canvas confirmed-down. Ivy League private R1.

The Dartmouth

University of Miami

U Miami · FL · May 7-8, 2026 (EDT)

Press Release
Instructure.com is still working on its investigation of the recent unauthorized activity across its systems.

Private R1, AAU. Minimal statement, directed community to Instructure's status page rather than issuing UM-specific narrative.

The Miami Hurricane

Florida Gulf Coast University

FGCU · FL · May 7, 2026 (EDT)

OIT / Status Page
Instructure, a global educational technology company, recently experienced a cyber security incident that gave unauthorized access to private client data. The compromised information could include names, emails, home addresses and student and/or employee identification numbers, as well as private messages stored in the Canvas platform.

Public R2 (~16K students). **Only institution listing 'home addresses' as potentially compromised**, most institutions list only names/emails/IDs/messages.

FGCU Inside

PUC Minas (Pontifícia Universidade Católica de Minas Gerais)

PUC-Minas · BR · May 7, 2026 (BRT)

Press Release
A plataforma Canvas, utilizada pela PUC Minas para suas atividades acadêmicas, está passando por instabilidade técnica em razão de um incidente de cibersegurança que afetou a Instructure, fornecedora global do serviço. O incidente não se restringe à PUC Minas. A PUC Minas recomenda atenção a e-mails ou mensagens suspeitas (phishing). A Universidade não solicitará senhas ou dados pessoais por e-mail em razão desse incidente.

**FIRST BRAZIL ENTRY IN HUB, one of two Brazilian PUCs to issue public Canvas-breach statement.** Private R2 Catholic. Explicit phishing-warning framing.

PUC Minas Sala de Imprensa

PUCPR (Pontifícia Universidade Católica do Paraná)

PUCPR · BR · May 7, 2026 (BRT)

Press Release
A PUCPR informa que tomou conhecimento de um incidente de segurança global envolvendo a Instructure, empresa responsável pela plataforma Canvas. Desde o início do incidente, a área de Segurança da Informação da PUCPR vem acompanhando a situação em contato direto com a fornecedora. Até o momento, não foram identificadas evidências de comprometimento de dados da Universidade. Como medida preventiva, a PUCPR reforça a importância de que estudantes, professores e colaboradores mantenham atenção redobrada a possíveis tentativas de phishing.

**Second Brazilian Canvas tenant in hub.** Private R2 Catholic. Notably explicit 'no evidence of compromise of University data identified to date.'

PUCPR Nota Oficial

University of Birmingham

Birmingham · UK · May 7-8, 2026 (BST)

Deadline Change
The provider of Canvas informed the University of Birmingham of a global cybersecurity incident affecting many universities worldwide. Data associated with the University has been accessed, including names, email addresses, student ID numbers, and messages exchanged in Canvas. Instructure states there is no evidence that passwords, dates of birth, government identifiers, or financial information were involved. Submission deadlines on the day of the incident were extended until Wednesday 13 May at 5 p.m.

**Most detailed UK Russell Group response.** Full institutional Canvas tenant. Issued explicit May 13 5 PM deadline extension, a deadline-change action like JMU + SMU.

University of Birmingham student intranet

University of Edinburgh

Edinburgh · UK · Week of May 7, 2026 (BST)

Campus Alert
The University of Edinburgh has been advised of an ongoing global cybersecurity incident affecting Instructure, the parent company of the learning platform Canvas used by short course learners and staff. The main university VLE is Learn (Blackboard), so the impact is limited to the Short Courses Platform Canvas tenant. Affected users are being notified directly.

Hybrid LMS environment, Learn (Blackboard) is the primary VLE; Canvas powers Short Courses Platform only. Blast radius narrower than Oxford / Birmingham.

University of Edinburgh Information Services

Munster Technological University

MTU · IE · May 7, 2026 (IST)

Campus Alert
MTU issued public alert to students about 'global cybersecurity incident' affecting Canvas across all 6 Cork/Kerry campuses on May 7, 2026.

Second Ireland entry. Canvas across all 6 Cork/Kerry campuses (~18K students).

MTU Student Canvas + RTÉ News + Irish Examiner

University of Oslo

UiO · NO · Notified May 5; confirmed affected May 7, 2026 (CEST)

Campus Alert
UiO was notified by Instructure on 5 May 2026 of a possible security breach in the Canvas learning platform; on 7 May 2026 Instructure confirmed UiO was affected. Unauthorised parties may have gained access to personal data including name, email address, student ID and messages sent between users in Canvas. UiO has informed active Canvas users and notified the Norwegian Data Protection Authority (Datatilsynet). UiO is following up with the service provider Sikt and Instructure.

First Norwegian entry in hub. Full Canvas tenant. Notified Datatilsynet (Norwegian DPA).

UiO For ansatte

Cornell University

Cornell · NY · May 6, 2026 · 4:20 PM ET

OIT / Status Page
Canvas, the university's learning management system, was affected by a nationwide security incident involving Instructure, the company that provides Canvas. Instructure believes the incident is contained. Canvas remains available to Cornell faculty, staff, and students.

Posted by Weill Cornell ITS. Cornell reported Canvas remained operational locally.

Cornell ITS, Security Alert

Technische Universiteit Eindhoven

TU/e · NL · May 6, 2026 evening (CEST)

Press Release
During a global cyberattack on the Canvas learning platform, user data was stolen. Wednesday evening, the university confirmed that data from TU/e students and staff was also leaked. TU/e has filed a preliminary breach notification with the Autoriteit Persoonsgegevens.
Cursor (TU/e student magazine)

Ateneo de Manila University

Ateneo · PH · Week of May 5-7, 2026 (PHT)

Campus Alert
Instructure, the provider of Ateneo de Manila University's Canvas learning management system, recently notified the University of a cybersecurity incident affecting their infrastructure. Members of the University community may continue using Canvas for teaching and learning activities. The University is working closely with Instructure to obtain more detailed information from their ongoing investigation, which is being conducted with the assistance of external forensic experts, and will continue to assess any potential impact on institutional data. The University has activated its incident response protocols, including the engagement of legal counsel and data protection personnel.

**First Philippines entry in hub.** AteneoBlueCloud Canvas (Sept 2020 acquisition). Notable for explicit legal-counsel + data-protection-officer activation language. NPC (Philippine National Privacy Commission) breach-notification applies.

Ateneo de Manila University Advisories

Universiteit van Amsterdam

UvA · NL · May 6, 2026 (CEST)

Press Release
Basisgegevens van studenten en medewerkers zijn gelekt: namen, e-mailadressen en mogelijk Canvas-ID's of student- en medewerkernummers. Volgens Instructure zijn geen wachtwoorden, geboortedata, identiteitsdocumenten, bankgegevens of andere bijzondere persoonsgegevens gelekt. De UvA heeft, samen met de andere getroffen instellingen, melding gedaan bij de Autoriteit Persoonsgegevens. De Canvas-omgeving is weer veilig te gebruiken.

GDPR Art. 33 notification to Autoriteit Persoonsgegevens (Dutch DPA) confirmed. UvA among 7 Dutch research universities individually named by Instructure. Coordinated response routed via SURF and Universiteiten van Nederland (UNL).

UvA Nieuwsbericht

University of Nevada, Reno

UNR · NV · May 6, 2026

Press Release
Be alert to unsolicited emails or messages appearing to come from Canvas or your institution, particularly any requesting login credentials or personal information.

Most prominent president-level public warning tied to the incident. Brian Sandoval (former NV Governor) named on record.

UNR President's Messages (Brian Sandoval)

Texas A&M University System (System-level CISO advisory)

TAMUS · TX · May 6, 2026 (CDT)

OIT / Status Page
The Texas A&M University System is aware of a cybersecurity incident affecting Instructure, the company that operates Canvas — the learning management system used across member universities. This incident was not directed at the Texas A&M University System or any of its institutions. Instructure serves thousands of institutions worldwide, and this is a vendor-level event that may affect multiple institutions globally. The TAMUS Office of the System CISO and member institution IT security teams are closely monitoring Instructure's disclosures and working to assess any specific impacts.

**System-level advisory** covering all 11 TAMUS member institutions including TAMU College Station. Separate from TAMU-Corpus Christi's individual statement (already in hub). Deflective framing: 'not directed at TAMUS' or any of its institutions.

Texas A&M System Cybersecurity Office

New Hanover County Schools

NHCS · NC · May 6, 2026

Faculty / Student Email
Canvas is a state-supported platform and is also widely used by colleges and universities across the country. Because of its widespread use, this situation is not isolated; it is being addressed at the state and national levels. Instructure has engaged cybersecurity experts and notified federal law enforcement agencies as part of their response. The North Carolina Department of Public Instruction (NCDPI) is actively reviewing this situation alongside Instructure to assess any potential impact across North Carolina.

Coastal NC district (~25K students). Most thorough superintendent-signed statement; references federal law enforcement.

WECT (Superintendent Christopher Barnes)

Wake Forest University

WFU · NC · May 5-6, 2026 (EDT)

OIT / Status Page
Canvas, Wake Forest's cloud-based learning management system, recently experienced a cybersecurity incident. Instructure, the company that operates Canvas, informed school systems and higher education institutions across the country, including Wake Forest, that it has identified unauthorized access to a limited set of user data associated with its platform. There is no indication that sensitive data, such as Social Security numbers, financial information, or account passwords, was exposed. Canvas indicated that the issue has been corrected and that the software remains available for use by faculty, staff and students.

Private R2. Measured update notes Canvas 'remains available' rather than offline.

Inside WFU

Emory University

Emory · GA · May 6, 2026 (EDT)

Deadline Change
Emory University is restricting access to Canvas so it can assess the security and stability of the platform following the nationwide security breach. Due to the ongoing problems with Canvas, the Office of the Provost extended by seven days the grade submission deadlines for each of Emory's schools. Instructure shared that the compromised information includes names, email addresses, student identification numbers and messages among Canvas users. However, Emory can't independently verify Instructure's findings.

Private R1, AAU. **Rare 'we cannot independently verify vendor claims' framing.** 7-day grade-deadline extension. Distinctive among private R1 responses.

Emory News Center

University of Iceland (Háskóli Íslands)

HÍ · IS · May 6, 2026 (GMT)

Faculty / Student Email
An unauthorised party illegally obtained part of the data within the Canvas system that relates to users at a number of universities worldwide, including Háskóli Íslands. The data may contain email addresses and messages between Canvas users. Canvas does not store passwords or ID numbers of Háskóla Íslands users, and there are no indications that financial information or other sensitive data reached unauthorised parties. Students were notified by email on 6 May 2026.

**First Iceland entry in hub.** Full Canvas tenant since fall 2020. Icelandic press characterized incident as 'attack at the worst possible time' (exam period).

Morgunblaðið (mbl.is)

University of Liverpool

Liverpool · UK · May 6, 2026 (BST)

Campus Alert
The University of Liverpool has been notified by Instructure, the supplier of our Canvas learning platform, of a cyber security incident affecting Canvas users worldwide. The University has reported this to the Information Commissioner's Office (ICO) as required under UK GDPR, and is working with Instructure to understand the impact on Liverpool data.

Russell Group university; second confirmed UK Russell Group response (after Manchester). UK GDPR Art. 33 ICO notification confirmed.

University of Liverpool News

Vrije Universiteit Amsterdam

VU · NL · May 6, 2026 (CEST)

Press Release
VU Amsterdam confirmed via the joint UNL statement that staff and student basic data (names, e-mail addresses, possibly Canvas IDs / personnel numbers) was leaked. VU has filed a preliminary breach notification with the Autoriteit Persoonsgegevens and is coordinating with SURF.
Universiteiten van Nederland (UNL)

Erasmus Universiteit Rotterdam

EUR · NL · May 6, 2026 (CEST)

Press Release
Gegevens van EUR-studenten en -medewerkers zijn gestolen na de cyberaanval op Canvas. Het gaat om basisgegevens zoals namen en e-mailadressen. EUR heeft melding gemaakt bij de Autoriteit Persoonsgegevens.
Erasmus Magazine

Tilburg University

TiU · NL · May 6, 2026 (CEST)

Press Release
Tilburg University confirmed that data of TiU students and staff was among the records stolen in the Instructure/Canvas breach. The university filed a preliminary breach notification with the Autoriteit Persoonsgegevens through the joint UNL channel.
Univers (Tilburg University magazine)

Universiteit Maastricht

UM-NL · NL · May 6, 2026 (CEST)

Press Release
Maastricht University confirmed via the joint UNL bulletin that basic data of its students and staff was leaked, that the Canvas environment is again safe to use, and that a preliminary breach notification has been filed with the Autoriteit Persoonsgegevens.
Universiteiten van Nederland (UNL)

Universiteiten van Nederland (UNL collective)

UNL · NL · May 6, 2026 (CEST)

Press Release
Volgens Instructure zijn gegevens van medewerkers en studenten van zeven Nederlandse universiteiten betrokken: Universiteit van Amsterdam, Vrije Universiteit Amsterdam, Erasmus Universiteit Rotterdam, Tilburg University, Technische Universiteit Eindhoven, Universiteit Maastricht en Universiteit Twente. Alle getroffen universiteiten hebben (voorlopige) melding gedaan bij de Autoriteit Persoonsgegevens en staan in nauw contact met SURF.

Dutch sector-level (NL) collective statement. NL Times reports 44 Dutch educational institutions (incl. hogescholen and a small number of secondary schools) impacted in total. SURF coordinating role explicit.

Universiteiten van Nederland

Autoriteit Persoonsgegevens (Dutch DPA)

AP-NL · NL · Notifications filed week of May 4-6, 2026

OIT / Status Page
All seven affected Dutch research universities filed preliminary GDPR Article 33 data-breach notifications with the Autoriteit Persoonsgegevens in the days following Instructure's May 1, 2026 disclosure. As of May 8, 2026, AP has not yet published a public-facing advisory but is in receipt of the notifications via SURF and UNL.

**Dutch DPA is the FIRST regulator in our archive confirmed to have received breach notifications**, breaking the ICO/OAIC/NCSC public-silence pattern. Under GDPR a controller-side breach affecting 7+ institutions will likely produce a public AP statement within 2-4 weeks.

Universiteiten van Nederland (confirms AP notifications)

Swedish University of Agricultural Sciences

SLU · SE · Approximately May 6, 2026 (CEST)

OIT / Status Page
Instructure, the company that operates the Canvas learning platform, has notified SLU of a security incident. Information that may have been accessed includes names, email addresses, student IDs, and inbox/discussion messages. SLU is investigating in coordination with Sunet and has reported a suspected personal-data incident to IMY.

Specialized agricultural / forestry / veterinary research university.

SLU News

Aalto University Executive Education

Aalto EE · FI · May 6, 2026 (EEST)

Press Release
On April 25, 2026, an external criminal threat actor gained unauthorized access to Instructure's (Canvas) systems. Instructure detected the breach on April 29, and access was revoked. On May 6, Instructure confirmed that Aalto EE's Canvas was among those affected. Aalto EE has notified the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) and is in active contact with Instructure demanding full clarification of the scope of data affected.

First Finnish institution. Notified Tietosuojavaltuutettu (Finnish Data Protection Ombudsman). Confirms April 25 intrusion onset / April 29 detection / containment timeline.

Aalto EE Newsroom

University of Sydney

USYD · AU · May 6, 2026 (AEST)

Press Release
Instructure, the vendor of Canvas, has confirmed that University of Sydney data has been impacted by a cyber security breach. The University is one of approximately 9,000 educational institutions worldwide that is potentially impacted.

Australia's NDB scheme under Privacy Act 1988 likely triggers OAIC notification; 2022 amendments raised maximum penalties to AU$50M / 30% domestic turnover.

University of Sydney News

Fresno State (California State University, Fresno)

Fresno State · CA · May 5, 2026 (PDT), earliest confirmed CSU campus disclosure

Press Release
As of May 5, 2026, Instructure has confirmed a cybersecurity incident involving unauthorized access to data. Fresno State, along with other institutions, was affected, and some data associated with its Canvas environment was accessed without authorization. There is no indication that passwords, dates of birth, government-issued identification numbers, or financial information were involved.

**HSI** (federally-designated). Public masters (~24K students). **Earliest CSU campus-specific disclosure (May 5)**, earlier than the system-wide May 7 message.

Fresno State Canvas Incident page

Boise State University

BSU · ID · May 5, 2026

OIT / Status Page
Thousands of institutions worldwide are potentially impacted. Instructure, Canvas's parent company, has confirmed the incident and stated that core data was not accessed, though the investigation is ongoing.
Boise State OIT

University of Wisconsin–Milwaukee

UWM · WI · May 5, 2026

OIT / Status Page
A nationwide security breach was reported May 1 at Instructure, which provides the cloud-based Canvas learning management system at UWM and other Universities of Wisconsin (UWs) campuses. Instructure reports that the breach has been contained, and the company is still investigating the extent of the incident. The UWs are working to learn more about any impacts on campuses. UWM's information security team, along with UWs, will continue to actively monitor the situation. UWM does not collect student ID numbers, dates of birth, government identifiers or financial information in Canvas.

Unique reassurance: 'UWM does not collect student ID numbers... in Canvas.'

UWM Information Technology

Universiteit Twente

UT-NL · NL · May 5, 2026 (CEST)

Campus Alert
The University of Twente has taken note of reports published on 4 May regarding a data breach at Instructure, the provider of the Canvas learning platform, and Instructure has confirmed that UT has also been affected. According to current information, the worst-case scenario involves basic data such as names, email addresses, and possibly Canvas IDs or student and staff numbers, as well as potentially messages sent within Canvas. Instructure has taken additional security measures and the University of Twente has taken extra steps to protect data, including refreshing access keys and additional monitoring.

Most operationally specific Dutch statement: discloses key-rotation, monitoring uplift, explicit data minimisation.

University of Twente news

Windesheim University of Applied Sciences (NL hogeschool)

Windesheim · NL · Week of May 5, 2026 (CEST)

Press Release
Windesheim is among the 44 Dutch educational institutions named by NL Times as affected by the Canvas / Instructure breach — beyond the 7 Dutch research universities, the broader figure includes hogescholen (universities of applied sciences) and a small number of secondary schools.

Represents the broader 44-institution Dutch impact figure. Other named hogescholen: Hague University of Applied Sciences, Deltion College, Grafisch Lyceum Haarlem.

NL Times

KTH Royal Institute of Technology

KTH · SE · Approximately May 5, 2026 (CEST)

Campus Alert
KTH has received information that Canvas has been affected by a cybersecurity incident through notifications from Sunet and Canvas's provider Instructure. The information that may have been exposed includes user data such as name, email address, student ID, and messages exchanged between users in Canvas. There is no information indicating that passwords have been compromised. A suspected personal data incident has been reported to the Swedish Authority for Privacy Protection (IMY).

Sweden's premier technical university. IMY (Swedish DPA) notification confirmed via Sunet (Swedish NREN). Cross-Nordic notification cascade includes KI, Lund, Uppsala, SLU.

KTH Student News

Lund University

Lund · SE · Approximately May 5, 2026 (CEST)

Campus Alert
Lund University has been confirmed by Instructure as one of the institutions affected by the Canvas security incident. Potentially affected data includes names, email addresses, student IDs, and messages in Canvas. There are no indications that passwords, personal identification numbers, or financial information were compromised. The university has reported the incident to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) and is coordinating with other Swedish universities and educational institutions.

Sweden's oldest university (~46K students). IMY notification confirmed via Sunet.

Lund University Medarbetarwebben

Karolinska Institutet

KI · SE · Approximately May 5, 2026 (CEST)

OIT / Status Page
Information has reached Karolinska Institutet about a data breach in the learning platform Canvas. Instructure has confirmed that user data including names, email addresses, student IDs, and messages may have been accessed by a criminal actor. The incident has been reported to the Swedish Authority for Privacy Protection (IMY) and KI is in dialogue with Sunet and Instructure.

Top European medical research university.

Karolinska Institutet Operating Info

Uppsala University

Uppsala · SE · Approximately May 5, 2026 (CEST)

Press Release
Uppsala University's learning platform Canvas has been hacked and personal data has been leaked. Information that may have been exposed includes names, email addresses, student IDs, and messages exchanged between users. The incident has been reported to the Swedish Authority for Privacy Protection (IMY).

Sweden's oldest university by founding date (1477). Reconstructed from Cybernews/IDM cross-reference.

Uppsala University Student Pages

Wayzata Public Schools

Wayzata · MN · May 4, 2026

Faculty / Student Email
This was a vendor-side incident. The internal networks and systems of Wayzata Public Schools were not breached or compromised. Families should be cautious of unsolicited emails or messages that appear to come from Canvas, especially those asking for personal information or password resets.

12,000-student district in western Minneapolis suburbs; reportedly one of the first U.S. K-12 districts to formally notify parents, three days before mass-defacement event.

FOX 9 Minneapolis-St. Paul

Clemson University

Clemson · SC · May 4, 2026 (EDT)

Press Release
Canvas vendor Instructure has reported a cybersecurity incident as part of a broader event affecting multiple institutions. Clemson's Canvas administrators are reviewing the Clemson instance for any usability or service impacts.

**Earliest US public university notice**, May 4, three days before the May 7 defacement. Public R1, ACC, land-grant.

Clemson CCIT News

University of Technology Sydney

UTS · AU · May 5, 2026 (AEST)

Press Release
UTS has been notified of a cyber incident impacting the Canvas learning management system globally. UTS is working with the vendor, Instructure, to confirm whether UTS data has been compromised, and is also working with relevant Australian authorities. Canvas is currently operating as normal, and UTS will be in touch if there are any identified impacts to users.

Notably names 'relevant Australian authorities', implies OAIC and ACSC engagement.

UTS News

Rutgers University

Rutgers · NJ · May 4, 2026

OIT / Status Page
Instructure, the provider of Canvas, has informed the Office of Information Technology (OIT) that they are responding to a vendor-driven, nationwide security event. The information involved in the attack included names, student ID numbers, messages between users and email addresses. Instructure informed OIT that there is no indication that passwords, dates of birth, government identifiers, or financial information were involved in this incident. Canvas is fully operational, and Canvas users do not need to take any action in connection with this incident at this time.
Rutgers IT Alerts

University of Manchester

UoM · UK · May 4, 2026 (BST)

Campus Alert
The University was informed of a cyber security incident by Instructure, the supplier of Canvas. Data associated with the University of Manchester has been accessed, which may include names, email addresses and user identification numbers of some Canvas users, but is not believed to include sensitive personal data such as dates of birth, financial information or passwords.

Earliest dated UK Russell Group acknowledgement. UK GDPR Article 33 ICO notification clock expired ~May 7.

University of Manchester Student News

University of Melbourne

UniMelb · AU · Week of May 4, 2026 (AEST)

Campus Alert
The vendor has advised that some University of Melbourne data has been involved in this breach. Instructure confirmed on 1 May that the company had suffered a cybersecurity incident perpetrated by a criminal threat actor, and had engaged outside experts to understand the extent of the incident.

Migrated from Blackboard to Canvas in 2023, high exposure.

University of Melbourne Cybersecurity

Fulton County Schools

FCS-GA · GA · Initial security update April 27, 2026 · families notification May 7

Faculty / Student Email
Fulton County Schools is alerting families of a nationwide cybersecurity incident involving Canvas, a software platform provided by technology vendor Instructure. While the software remains operational, the vendor confirmed that unauthorized parties may have accessed user data, including names and internal district messages. Sensitive information such as social security numbers, passwords, and financial data was not involved in the breach.

Largest Georgia district (~90K students). **Critical timeline anomaly:** Fulton's initial security update was posted April 27, five days BEFORE Instructure's May 1 public disclosure, suggesting Instructure quietly notified some K-12 customers under NDA early.

Fox 5 Atlanta

Harvard University

Harvard · MA · May 7-8, 2026

Press Release
[The University is] aware that the Canvas platform is currently unavailable due to a cyber incident. [HUIT is] actively investigating [the breach and will update its status page with any new information.]

HUIT spokesperson Tim Bailey to The Harvard Crimson; bracketed text reflects how the Crimson stitched the verbatim phrases into a sentence.

Harvard Crimson

Princeton University

Princeton · NJ · May 6-7, 2026

OIT / Status Page
Princeton University has been notified by Instructure, the vendor that operates the Canvas learning management system, of a security incident affecting the platform. Princeton has received confirmation from Instructure that Princeton data was impacted. Given the timing of this incident, the university has asked instructors to download a copy of their Canvas gradebook as a purely precautionary measure.

Dean of the College Michael Gordin separately emailed instructors with the gradebook-download guidance (per Daily Princetonian).

Princeton OIT, Instructure Security Incident Update

Columbia University

Columbia · NY · May 6, 2026 or later

Press Release
On May 6, 2026, Instructure notified Columbia University that its learning management system may have been impacted by a widespread data breach affecting thousands of educational institutions. Columbia's Courseworks data does not include dates of birth, social security numbers, or financial information, and all users are required to multi-factor authenticate in order to access the system.

Columbia brands Canvas as 'CourseWorks.'

Columbia Office of Public Affairs

Duke University

Duke · NC · May 6, 2026 · Wednesday evening ET

Faculty / Student Email
Duke has been notified by Canvas, which provides the university's learning management system, of a cybersecurity incident resulting in unauthorized access to data at Canvas from thousands of institutions, including Duke. Duke's IT Security Office is closely monitoring this incident and is continuing to assess any effect on the University community. At this time, Canvas remains operational and available to Duke faculty, staff, and students.

Email from CISO Nick Tripp to Duke faculty and students.

The Duke Chronicle

Pennsylvania State University

Penn State · PA · May 7, 2026, finals week

Press Release
Penn State is currently experiencing an outage to Canvas related to an ongoing security incident affecting Instructure, the vendor that provides the Canvas platform. Penn State is one of many institutions around the country affected by this issue.

Outage hit during finals week as faculty tried to enter grades before commencement. The login page reportedly displayed: 'ShinyHunters has breached Instructure (again).'

Penn State News

Liberty University

Liberty · VA · May 7, 2026

Deadline Change
Liberty University is aware of an ongoing situation with Canvas affecting Liberty and many other schools. Internal Teams are in active communication with the vendor about the issue. We understand the impact this disruption is having and want to reassure you that appropriate class extensions will be provided. We will share more specific guidance as soon as we have clarity on the duration of the outage.

Explicitly committed to deadline extensions.

WSLS-10

Virginia Tech

VT · VA · May 7, 2026

Press Release
Similar to other colleges and universities across the nation, Canvas is down and unavailable at Virginia Tech. The Division of Information Technology and Technology-enhanced Learning and Online Strategies are working with the vendor, Instructure, to identify and resolve the problem. We are aware of the impact on final exams and other end-of-semester activities.
WSLS-10

University of Virginia

UVA · VA · May 5-7, 2026

OIT / Status Page
Instructure, the parent company of Canvas, has confirmed the organization was affected by a criminal threat actor who obtained data associated with Canvas accounts. However, Canvas remains available and operational, and there is no disruption to access, course content, or functionality. UVA is continuing to monitor the situation and is keeping the community updated on the UVA Information Technology Services website.

Unlike many peers, UVA reported Canvas remained operational locally throughout the incident.

UVACanvas

Virginia Commonwealth University

VCU · VA · May 7, 2026

OIT / Status Page
VCU has taken its learning management system, Canvas, offline following a cyberattack against the software's parent company, Instructure. The reported breach potentially affects thousands of institutions worldwide and is not unique to VCU. Do not click on any links, visit any advertised websites, or open unsolicited messages or emails that appear to be related to Instructure or Canvas.
WTVR / VCU IT Status (it.vcustatus.com)

University of Maryland, College Park

UMD · MD · May 7, 2026 · Thursday afternoon

OIT / Status Page
Canvas was taken offline Thursday at all institutions using the technology, including the University of Maryland, College Park, after the company that owns and manages the learning management system, Instructure, was recently compromised. As the company investigates, Canvas will be unavailable.

Attributed to UMD's Division of Information Technology by The Diamondback.

The Diamondback

University of Michigan

U-M · MI · May 7, 2026

OIT / Status Page
The University of Michigan was among the organizations whose data was breached in a vendor-related incident involving Instructure, the parent company of the Canvas Learning Management System. The data involved appears to include some personal information, including names, email addresses, and student ID numbers, as well as messages among users. Instructure has stated that at this time, it has found no indication that passwords, dates of birth, government identifiers, or financial information were involved. Instructure's investigation remains ongoing, and the university is still awaiting additional detailed information about what specific U-M data may have been exposed.
U-M Safe Computing

Texas A&M University–Corpus Christi

TAMU-CC · TX · May 7, 2026

Campus Alert
CODE BLUE: Cybersecurity Incident Affecting Canvas. Texas A&M University-Corpus Christi is aware of a cybersecurity incident affecting Instructure, the company that operates Canvas. This incident was not directed at TAMU-CC — Instructure serves thousands of institutions worldwide, and this is a vendor-level event that impacts thousands of institutions. The Office of Information Technology (IT) is working closely with the Texas A&M System Information Security Office to actively monitor the situation. Watch for phishing emails, texts, and phone calls. We are already receiving reports of fraudulent messages claiming to be able to get you back into Canvas. Do NOT click links in unsolicited emails claiming to be from Canvas, Instructure, or TAMU-CC IT.

Notably escalated to 'CODE BLUE', campus emergency-tier alert classification, unusual for an LMS outage.

TAMU-CC Campus Announcements

University of Texas at Austin

UT Austin · TX · May 5-7, 2026

OIT / Status Page
On May 1, 2026, Instructure disclosed a cybersecurity incident that is currently under investigation. The information involved consists of certain user data, including names, email addresses, student ID numbers, and messages among users. Canvas continues to operate normally and this was not a targeted attack on UT Austin. Watch for phishing emails and do not click links in unsolicited emails claiming to be from Canvas, Instructure, or UT IT — instead access Canvas directly using official links at canvas.utexas.edu.

UT Austin reported Canvas was operating normally locally.

UT Austin Enterprise Technology

University of Missouri System

UM System · MO · May 7, 2026

Press Release
Access to Canvas for the University is closed. We did that to make sure that things remained as safe as we can make them. We are going to be working with Canvas to get a solution as quickly as we possibly can.

Direct quote from UM spokesman Christopher Ave. Affected all four UM System campuses (MU, UMKC, UMSL, Missouri S&T).

KBIA / KCUR

Oklahoma State University

OSU · OK · May 6, 2026 · afternoon CT

Press Release
Oklahoma State University is aware that the incident with Canvas and its parent company Instructure has escalated and universities across the country are affected. We do not currently have a timeframe for resolving this issue, but we are working diligently with Instructure to identify solutions. We understand this situation presents challenges with accessing academic material, and we will share updates as soon as possible with additional information.

Outage hit during OSU finals week.

The O'Colly

University of Oklahoma

OU · OK · May 7, 2026 · Thursday afternoon CT

Faculty / Student Email
The University of Oklahoma is aware of a cybersecurity incident involving Canvas, operated by Instructure. This is a global issue affecting institutions worldwide, and Canvas services are currently experiencing disruptions. The University is actively working with Instructure to monitor the situation and gather additional information. The University recognizes this disruption comes as students prepare for final exams and end-of-semester coursework and is committed to supporting students, faculty, and staff during this time.

Email co-signed by Senior VP and Provost André-Denis Wright and Senior VP/OU Health Provost Gary Raskob.

OU Daily

University of California (system-wide)

UC · CA · May 6, 2026

Press Release
Instructure, the maker of the University's learning management system Canvas, has notified the University of California of a data breach involving Instructure's systems. This is a nationwide issue affecting thousands of institutions. We are in close communication with Instructure and are actively coordinating with UC location cybersecurity partners to monitor the situation. As always, we encourage our community members to remain vigilant and exercise caution regarding potential phishing attempts.

System-wide statement covering all 10 UC campuses. ShinyHunters specifically claimed 600,000+ UC Berkeley records.

UCnet

UC Berkeley

Berkeley · CA · Early May 2026

OIT / Status Page
Information that may have been involved includes names, email addresses, student ID numbers, and messages exchanged in Canvas/bCourses. There is no evidence that passwords, birthdates, government IDs, or financial information were compromised, but this may change as the investigation progresses.

Berkeley brands Canvas as 'bCourses.' ShinyHunters specifically claimed 'more than 600,000' Berkeley records.

UC Berkeley Information Security Office

California State University Chancellor's Office

CSU · CA · Early May 2026

Press Release
The California State University (CSU) is aware of a cybersecurity incident involving Canvas, a third-party learning management system used across our campuses. We have been informed that this incident has likely impacted the CSU. We are working diligently to gather more details to better understand the scope and impact of this incident. Protecting the security and privacy of our students and employees is a top priority. We will provide updates as they become available.

23-campus regional public system response. Names six campuses confirmed affected: Humboldt, Long Beach, East Bay, Dominguez Hills, Bakersfield, Channel Islands.

CSU Learning Technology Services

California Community Colleges Chancellor's Office

CCCCO · CA · Early May 2026

Faculty / Student Email
Several outlets have reported [on the attack]. There is no evidence at this time that Social Security numbers, Financial Data, or Date of Birth information was included in the breached data. At this point, the risk to our colleges appears contained and manageable.

System-wide statement covering 116 California community colleges.

Contra Costa Advocate (quoting Chancellor Sonya Christian email)

Peralta Community College District

Peralta · CA · May 4-5, 2026

Press Release
Over the weekend of May 2-3, 2026, Instructure confirmed a security incident, and by Monday morning, May 4, they implemented containment measures, including revoking compromised credentials and applying security patches. At this time, no immediate action is required from students or employees. There is no indication of impact to our internal Student Information System (Campus Solutions), Employee Information System (HCM), or other third-party platforms. The Peralta Community College District is in close contact with the California Community Colleges Chancellor's Office and the Systemwide Security Center as we validate the scope of the incident.

Bay Area 4-college district. Among the earliest CCD responses.

Peralta CCD

Long Beach City College

LBCC · CA · Early May 2026

Press Release
LBCC regrets any concern or inconvenience that this incident may cause. LBCC encourages people to remain vigilant for incidents of fraud and identity theft and to carefully review account statements and immediately notify them of any suspicious activity. For additional questions, a phone line is available at 855.540.5646, Monday through Friday between 6:00 a.m. and 6:00 p.m. Pacific Time.

LBCC stood up a dedicated /securityincident page with toll-free hotline.

LBCC Security Incident Notice

Orange Coast College

OCC · CA · May 7, 2026

OIT / Status Page
An issue with Instructure's hosting provider is affecting web services worldwide, including the Canvas Learning Management System. Some third party tools connected to Canvas may also be impacted until the issue is resolved.

Notable for downplaying as a hosting issue rather than a cyberattack.

Coast Report Online (OCC student paper)

College of the Canyons

COC · CA · Reported May 6, 2026

Press Release
Canvas was down Monday, but we were able to resolve the issue the same day.

Direct quote from COC spokesperson Eric Harnish.

Hometown Station

Sacramento State University

Sac State · CA · May 7, 2026

Faculty / Student Email
There is no known time frame for when the problem will be solved, or when Canvas will be functioning again.

Sac State IRT relayed the CSU Chancellor's Office message to students.

The State Hornet

University of Utah

Utah · UT · May 7, 2026

Press Release
University of Utah systems were not breached. The university takes this matter seriously and is working closely with Instructure as they coordinate with law enforcement and third-party forensic experts to determine the full scope of the impact.

Utah explicitly distinguished its own systems from Instructure's.

@theU

University of Colorado Boulder

CU Boulder · CO · May 4, 2026

OIT / Status Page
CU is aware of a data breach involving Instructure, the parent company of Canvas, our learning management system. This reported data breach is a nationwide event affecting multiple institutions. Currently, CU has not been notified of any direct impact to our campuses or the system office. Canvas continues to be available for use by faculty, staff, and students.
CU Boulder OIT

Colorado State University System

CSU System · CO · May 6, 2026 (updated May 7)

OIT / Status Page
CSU requires all vendors to meet strict IT security and data protection standards, and user passwords are managed within CSU systems and are not shared with Canvas or other third-party platforms, meaning CSU passwords were not compromised in the incident. Instructure said it has taken immediate steps to mitigate the issue and is working with external cybersecurity experts as the investigation continues.
CSU System IT

Mt. San Antonio College

Mt. SAC · CA · May 7, 2026

Social Media
Mt. San Antonio College is aware of the systemwide Canvas outage and is actively coordinating with Instructure/Canvas.
California Community Colleges system page

Union County Public Schools (NC)

UCPS-NC · NC · May 7, 2026

Press Release
Union County Public Schools confirmed it was impacted by the Canvas/Instructure breach.

Largest of the Charlotte suburban NC districts named alongside CMS, Cabarrus, Catawba, Kannapolis.

WCNC Charlotte

Durham Public Schools

DPS-NC · NC · May 7, 2026

Press Release
Durham Public Schools is among NC districts confirmed affected by the Canvas/Instructure breach.

Major Triangle-area NC district (~32K students).

CBS17 Raleigh

Chapel Hill-Carrboro City Schools

CHCCS · NC · May 7, 2026

Press Release
Chapel Hill-Carrboro City Schools is among NC districts confirmed affected by the Canvas/Instructure breach.

NC Triangle K-12 district adjacent to UNC Chapel Hill.

CBS17 Raleigh

Cumberland County Schools

CCS-NC · NC · May 7, 2026

Press Release
Cumberland County Schools is among NC districts confirmed affected by the Canvas/Instructure breach.

Fayetteville-area NC district (~50K students).

CBS17 Raleigh

Norman Public Schools

NPS-OK · OK · May 7, 2026

Faculty / Student Email
Norman Public Schools confirmed it was on the list of institutions affected by the Canvas hack alongside the University of Oklahoma.

Oklahoma K-12 district, tight geographic clustering with OU's R1 disclosure.

OU Daily

Galena USD 499

USD 499 · KS · May 7, 2026

Campus Alert
Galena USD 499 posted a Canvas (Instructure) Breach Information notice to families confirming the district uses Canvas and is reviewing whether students were affected.

Small Kansas K-12 district, example of mid-/small-tier district notifying parents proactively.

Galena USD 499

Broward County Public Schools

BCPS · FL · As of May 8, 2026

No Public Response
Broward County appears on the ShinyHunters affected-schools list among large K-12 districts; no public BCPS response located as of May 8, 2026.

6th-largest U.S. district (~260K students); on the list but no formal district statement located.

BleepingComputer (named in leak list)

Federal & Sector-Consortium Silence Tracker

The defining federal-response feature of this incident has been near-total silence from every agency, congressional committee, and sector consortium with jurisdiction. The list below is the verified-silent set as of May 8, 2026. Each row will be promoted to a confirmed response the moment a public product is issued.

CISA

no advisory / KEV addition

FBI

declined to comment (ABC11)

FTC

no COPPA enforcement filing

ED PTAC

no FERPA breach bulletin

FSA (Title IV)

no Dear Colleague Letter

ONCD / White House

no statement

Senate HELP

no Cassidy/Sanders letter

Senate Commerce

no Cruz hearing notice

Senate HSGAC

no Peters letter

House Ed & Workforce

no Walberg statement

House Homeland Sec.

no Garbarino statement

House E&C

no Pallone statement

Markey-Cassidy COPPA 2.0

no joint letter

Utah AG (home state)

no statement

California AG Bonta

no Instructure investigation

NY AG James

no Instructure investigation

EDUCAUSE / HEISC

no public bulletin

REN-ISAC

no public advisory

NACUA

no NACUANOTES on FERPA timing

AAU

no joint statement (8 Ivies affected)

AAUP

no faculty-side commentary

UK ICO

no public advisory

Australian OAIC

no public statement

Dutch AP

received 7 notifications; no public advisory yet

Swedish IMY

received Sunet notifications; silent

Danish Datatilsynet

received KU notification; silent

Finnish DPA

received Aalto EE notification; silent

Cutoff timestamp: May 8, 2026 · end of day ET. The first agency or committee to break silence resets this panel.

Decision-Maker Checklist

For OIT, Emergency Management, Provost, Registrar

  1. 1Subscribe to component-level alerts at status.instructure.com and confirm at least two staff members are subscribed.
  2. 2Independently verify your tenant URL (canvas.<institution>.edu) and check it against the vendor status page, local availability has varied.
  3. 3**Rotate any API keys** shared with Canvas integrations (Turnitin, Pearson, Top Hat, Zoom). UMass Amherst publicly noted a Turnitin key-rotation side-effect.
  4. 4**Communicate to faculty about phishing risk.** TAMU-CC reports already receiving fraudulent messages claiming to restore Canvas access. Multiple institutions warn against clicking links in unsolicited messages.
  5. 5If Canvas is offline, **publish a customer-facing summary on your OIT status page** even if Instructure has not, your community looks to you first.
  6. 6**Coordinate with the registrar BEFORE announcing exam postponements** that affect grade-submission deadlines (JMU model: explicit new exam date; Liberty model: open-ended commitment to extensions).
  7. 7**Ask instructors to download Canvas gradebook copies** as a precaution (Princeton's Dean Gordin model). Quizzes and submissions may also be exportable from the API while available.
  8. 8Consider a faculty-facing FAQ: how to extend Canvas due dates, accept email submissions, run paper-based exam protocols.
  9. 9Capture screenshots of vendor status messages and your own communications for post-incident review and any FERPA breach-notification documentation.
  10. 10If your institution is in active legal review for FERPA notification: the data exposed reportedly includes names, email addresses, student ID numbers, and Canvas messages, discuss with general counsel.
  11. 11**Track the litigation.** Multiple federal class actions were filed by late May 2026 (several in the District of Utah, plus an S.D.N.Y. case naming owner KKR); affected institutions should preserve incident records and coordinate with general counsel on potential discovery and state breach-notification obligations.

Primary Sources

News Coverage

Open Questions

Items the maintainer cannot independently confirm against a primary source. Promoted to Confirmed Facts only when verified.

  • ?**Resolved: initial access vector.** The May 2026 production-side entry point was the Free-For-Teacher (FFT) account program, which allowed account creation without institutional verification but ran on the same backend as paid tenants; the September 2025 Salesforce-side compromise provided the targeting foothold. CrowdStrike (not Mandiant) served as the forensic IR partner and reported no evidence of system-level access, malware, or credential theft. No CVE was assigned because the failure was configuration-class, not a software defect.
  • ?**Resolved: did ShinyHunters publish after the May 12 deadline?** No. The May 12, 2026 deadline passed without a public data dump; ShinyHunters delisted Instructure from its leak site after the May 11-12 settlement and 'shred log' destruction claim. External verification of actual deletion remains impossible.
  • ?**Resolved: exam/deadline accommodations cascaded.** Numerous institutions adjusted finals, including JMU (exams to May 13), Emory (+7 days on grade submission), East Carolina (grade deadline to May 13), Idaho State (afternoon finals canceled May 7), Liberty (open-ended extensions), and SMU (Friday exams to Sunday May 10).
  • ?**Open: the ransom amount and whether Instructure paid.** Instructure has not disclosed any dollar figure and has not explicitly stated it 'paid a ransom,' framing the outcome as an 'agreement' yielding 'digital confirmation of data destruction.' Some outlets reported an unconfirmed ~$10 million figure. The exact terms remain undisclosed.
  • ?**Open: no IOCs published.** No CISA, MS-ISAC, REN-ISAC, or commercial CTI vendor published file hashes, IPs, or domain indicators of compromise. Detection guidance remained behavioral (anomalous Developer Key creation, OAuth token issuance, and Canvas Data 2 / Beta export volumes).
  • ?**Open: whether SSO / IdP endpoints were compromised.** Multiple universities (Boise State, Baylor) emphasized that Canvas does not hold primary credentials due to institutional SSO/SAML, and no evidence of IdP compromise was reported. Not affirmatively closed by a vendor statement.
  • ?**Open: CIRCIA and state breach-notification compliance.** It remains unclear whether Instructure or downstream districts filed under the 72-hour CIRCIA disruptive-incident rule, and ClassAction.org/Inside Higher Ed reported Instructure may not have notified state AGs within statutory windows, a potential additional regulatory exposure.
  • ?**Open: FERPA breach-notification outcome.** The Department of Education's Student Privacy Policy Office / PTAC requested information from Instructure but had not issued a public finding; whether Canvas messages and student ID numbers trigger formal FERPA breach obligations across affected institutions is unresolved.
  • ?**Open: litigation and regulatory outcomes.** Well over a dozen federal class actions were pending (with KKR named in at least one S.D.N.Y. case) with no JPML consolidation order, and no state AG, FTC, or international DPA enforcement action had concluded at the time of this archived writing.

Methodology

Primary Source First
Every claim on this page links to a primary source. Vendor status posts, university OIT pages, official emails, press releases, and verified social-media posts qualify. Secondary news coverage is welcome but tagged separately.
Honest About Gaps
Items that the maintainer cannot independently verify against a single source are kept in the Open Questions section rather than promoted to Confirmed Facts. Where a quote was reconstructed from search-result snippets rather than a fetched archive page, isVerbatimConfirmed is set to false.
Update Cadence
This record was maintained continuously while the incident was active and is now an archived retrospective. It will be updated only if litigation, regulatory, or Congressional outcomes are confirmed. Last-updated timestamps reflect actual maintenance activity, not auto-generated build times.
Scope
US colleges and universities only, consistent with the National Campus Alert Archive's mission. International institutions affected by the same vendor incident are out of scope here but may be linked.
Submit Tip
If your institution has issued an alert, posted to an OIT status page, or extended deadlines and is not yet listed below, please send a tip to the maintainer.

Hub maintained as part of the Campus Alert Archive. Page rebuilt continuously as primary sources are confirmed. Last data update: June 2026.