More than 30 million active users of Canvas were locked out of course materials during Spring finals week after Instructure disclosed a data breach and an extortion demand from the hacking group ShinyHunters. The company placed Canvas, Canvas Beta and Canvas Test into maintenance mode, blocking access to grades, quizzes and study resources for students at thousands of institutions. Instructure said names, email addresses, student ID numbers and private messages for users at affected institutions may have been exposed, and the vendor briefly removed services while it patched systems and increased monitoring. The attackers set a deadline of end of day May 12 and urged schools to contact them privately to negotiate.

Canvas, the cloud learning platform owned by Instructure, fell into an acute service disruption as a breach and an extortion demand coincided with a peak academic moment. The platform, which Instructure says serves more than 30 million active users and supports more than 8,000 institutions, was placed into maintenance mode while the company investigated what it called a cybersecurity incident.

What happened, and what was exposed

Instructure first acknowledged the incident on May 1 and opened a running incident log that its security team used to publish updates. The company’s chief information security officer, Steve Proud, contributed entries explaining the nature of data that appeared to be affected. Instructure and multiple university communications indicated the vendor believed names, email addresses, student ID numbers and private messages for users at some institutions were exposed.

The vendor said it deployed patches and stepped up monitoring after the initial discovery. After those remediation actions, one internal status log entry cited by sources said Canvas was "fully operational" and that the company was not seeing ongoing unauthorized activity, a statement attributed to Steve Proud. Instructure later reported the platform was available again "for most users" after the brief maintenance period for Canvas, Canvas Beta and Canvas Test.

But the disruption had already reached tens of thousands of students. The maintenance mode blocked access to grades, quizzes and study resources during Spring finals week, leaving many relying on alternative channels for timely feedback and submission.

How schools and students were affected

Multiple universities and K-12 districts reported ransom messages or defaced login pages on their Canvas portals. Student-facing homepages at some institutions were replaced with an injected message from the group calling itself ShinyHunters. The messages listed allegedly affected schools and urged institutions to negotiate privately with the attackers, according to screenshots and accounts of the compromised pages.

The group also repeated a demand that Instructure contact them by a specific deadline, a demand that appeared in multiple reports of the injected pages.

Campus communications from Columbia, Rutgers, Princeton, Harvard, Georgetown and other institutions confirmed disruptions. Administrations warned students to expect delays in access to course content and grading tools. Some professors redistributed assignments through email or alternate platforms while administrators worked to restore service.

Outage-tracking services and student reports showed a sharp surge in complaints during afternoon and evening hours, precisely when students were attempting to sit finals or access study materials. The scale of the disruption is notable for the education sector: Instructure’s own site lists more than 30 million active users and more than 8,000 institutional customers, and reports of outages came from a wide cross-section of colleges and school districts across the United States, including Ivy League and state schools as well as districts in at least a dozen states.

One live coverage item alleged that Down Detector recorded more than 8,000 outage complaints, but that figure hasn't been independently confirmed here. The number, if accurate, would underline how many users attempted to reach the service at once as the disruption unfolded.

Beyond the interruption of service, the attackers have asserted a broader history of breach and loss of large volumes of data in posts on criminal forums. Those posts include past claims of multiple terabytes and hundreds of millions of affected records. Neither those figures nor the hacker-published lists of allegedly impacted institutions have been corroborated by Instructure or by independent forensic inquiry at this stage, and the claims remain single-sourced in the public record.

There are also contradictions in the public timeline. One report cited a status entry that marked the situation "Resolved" on the Wednesday before the user-facing disruption.

Other incident updates and company statements show Canvas entering maintenance mode midday Thursday and becoming available again for most users late that same Thursday. The mismatch creates uncertainty about when the company believed the incident contained and when users actually lost access.

Schools and districts faced a choice about how to respond. The attackers urged affected institutions to consult cyber advisory firms and to contact the group privately to negotiate, a suggestion some institutions were reported to be weighing in the days after the outage.

Throughout the incident, Instructure’s public messaging focused on containment and restoration. The company maintained its incident log and updated customers as the security team completed remediation steps. Students and faculty, meanwhile, had to adapt quickly to ensure assessments and grading could continue during a high-pressure period in the academic calendar.

Related Articles

The attackers set a hard deadline of end of day May 12 for Instructure to make contact, a date that remained in effect while vendors, schools and advisers continued remediation and review of what data had been exposed.

This article was created with AI assistance.