Canvas users across major universities and schools lost access to coursework, assignments, and exam materials after a cyberattack linked to the hacking group ShinyHunters disrupted Instructure’s learning platform.
Quick Summary – TLDR:
- Canvas suffered a widespread outage after hackers linked to ShinyHunters targeted parent company Instructure.
- Universities including Harvard, MIT, Rutgers, Princeton, and Columbia reported disruptions during final exam season.
- Hackers threatened to leak stolen data on May 12 unless negotiations begin with affected institutions.
- Millions of students and teachers temporarily lost access to coursework, messages, lecture recordings, and assignments.
What Happened?
A major outage affecting Canvas, one of the world’s most widely used online learning platforms, disrupted thousands of universities and K-12 schools across the United States and beyond. The outage came after cybercriminal group ShinyHunters claimed responsibility for breaching Instructure, the company behind Canvas.
Users attempting to access Canvas on Thursday were redirected to a ransom style message from the hackers before the platform was later taken offline for maintenance.
🚨 BREAKING: Instructure, the company behind Canvas – the LMS tool used by almost every university in the United States, has been breached by popular threat actor ShinyHunters.
— Titan Security (@TitanSecAI) May 7, 2026
List of breached schools:
http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt pic.twitter.com/bm5Pq2cjJk
Hackers Target Instructure and Canvas
The disruption began escalating after students and faculty members reported unusual messages appearing on Canvas login pages. The message, allegedly posted by ShinyHunters, claimed the group had breached Instructure “again” and warned schools that stolen data would be leaked publicly if negotiations were not opened before May 12.
The hackers accused Instructure of ignoring previous outreach attempts and relying only on small security patches after an earlier breach disclosed on May 1.
According to the messages seen by users, the group claimed to have stolen data tied to more than 275 million people across nearly 9,000 schools. The hackers also threatened to leak “several billions of private messages among students and teachers.”
Instructure has not confirmed the scale of the claims made by the attackers.
Universities Across the US Report Disruptions
Several universities publicly acknowledged problems tied to the outage, including Harvard University, MIT, Rutgers, Georgetown, Princeton, Columbia, the University of Michigan, the University of Washington, and the University of Pennsylvania.
At Harvard, students reported that Canvas remained accessible until Thursday afternoon before suddenly redirecting users to the hacker message around 3:30 p.m. By later in the evening, the platform displayed a maintenance notice instead.
Harvard University Information Technology spokesperson Tim Bailey said the university was “aware that the Canvas platform is currently unavailable due to a cyber incident.”
Bailey added that the university was actively investigating the situation and monitoring updates from Instructure.
Multiple school districts and colleges also warned students and faculty about temporary disruptions to assignments, lecture recordings, course websites, and professor announcements.
Final Exams Thrown Into Chaos
The timing of the outage created major problems for schools already deep into final exam season.
Many instructors rely heavily on Canvas for communication, assignment submissions, quizzes, and study materials. Students across social media complained they could not access lecture recordings, revision guides, project files, or even messages from professors during critical preparation periods.
Some institutions temporarily switched to email and alternative communication tools while others delayed assignments and exams entirely.
James Madison University reportedly revised parts of its exam schedule and postponed several tests until the following week because of the disruption.
What Data Was Exposed?
Instructure first disclosed a cybersecurity incident on May 1, saying attackers had accessed certain user information. According to the company, compromised data included:
- Names
- Email addresses
- Student ID numbers
- Canvas messages exchanged between users
The company said there was no evidence that passwords, dates of birth, financial records, or government identifiers were exposed.
Steve Proud, Instructure’s chief information security officer, previously said the company brought in forensic experts and security teams to contain the breach.
Instructure stated earlier this week that the incident had been contained and that “Canvas is fully operational.” However, Thursday’s renewed disruptions and login page defacements raised questions about whether attackers retained access or exploited additional vulnerabilities.
By Thursday evening, Instructure said Canvas had been restored for most users, though some services remained under maintenance.
ShinyHunters Expands Attacks on Education Sector
ShinyHunters has become one of the most recognizable cybercriminal groups in recent years, previously linked to attacks involving Ticketmaster, Microsoft, and AT&T.
The group has increasingly targeted the education sector in recent months, including attacks involving Infinite Campus and textbook publisher McGraw Hill.
Security experts warn that education platforms remain attractive targets because they store massive amounts of student data, private communications, and institutional records.
SQ Magazine Takeaway
I think this incident shows just how fragile modern education systems have become when everything depends on a single online platform. Universities now rely on services like Canvas for almost every part of academic life, from exams to communication. When these systems fail during a cyberattack, millions of students are left stranded instantly.
What makes this even more concerning is the possibility that attackers may still have access even after companies claim incidents are contained. Schools and education companies are clearly becoming major targets for cybercriminals, and this outage may push universities to rethink how much they depend on centralized learning platforms.