Hackers demand ransom after Canvas breach hits schools nationwide
Hackers demand ransom after Canvas breach hits schools nationwide
Hackers claim access to vast Canvas data and threaten a public leak unless schools pay a ransom by May 12.
A major cyberattack targeting a widely used education platform is sending shockwaves through schools and universities across the country. Hackers calling themselves ShinyHunters said they breached Instructure, the company behind Canvas, and warned they would release stolen data unless districts pay a ransom by May 12. The extortion note was posted online after the breach was detected, and officials say the attackers claim they gained access to a broad trove of messages, student records, and other sensitive files. While many districts are still assessing what was accessed, the ransom demand has already prompted urgent action across campuses.
Canvas is among the nation’s largest learning management systems, used for assignments, messaging, and classroom coordination by thousands of schools and millions of students. The breach appears to affect hundreds of institutions and, according to threat researchers, could involve billions of private messages and other records. The scale of exposure has officials rushing to determine what was taken, what could be leaked publicly, and how to secure systems still in operation.
Security researchers called the situation fluid and evolving. Luke Connolly, a threat analyst at Emisoft, cited postings from the attackers claiming that nearly 9,000 schools worldwide were affected and that negotiations around payment and leaks might still be underway. In Wake County, North Carolina, officials said Canvas had to be temporarily disabled as investigators determine what data may have been accessed and to protect students and staff from further risk.
Among the schools named in the breach are the University of North Carolina at Chapel Hill, the University of Pennsylvania, the University of Illinois, and the University of Oklahoma, along with other major institutions that depend on Canvas to run courses, host discussions, and distribute assignments. The disruption has forced some districts to fall back on alternative tools and to pause certain online activities while IT leaders review access controls, passwords, and network traffic for unusual patterns.
Instructure and its customers are listening to investigators and cybersecurity experts as they decide next steps. Authorities urge caution over ransom payments, noting that paying does not guarantee data safety and can encourage future crimes. Districts are advised to monitor login activity, reset passwords, and review incident response plans. The incident underscores growing concerns about education technology security as schools increasingly rely on cloud-based platforms to support remote and hybrid learning.
While some reports describe defaced login pages and broad leaks promised by the attackers, officials say the full scope of what was accessed remains under review. The ongoing incident highlights the need for robust cyber defenses in schools and universities, including layered authentication, regular backups, and rapid incident response. As districts work to restore normal operations, students and teachers are left awaiting clarity about what data may have been exposed and how quickly systems can return to full service.