&imwidth=600&imheight=450&format=webp&quality=medium)
Canvas hacked: The Learning Management System used by several schools and universities across the world was hacked for a second time on Thursday. The hackers claim to have access to information on nearly 231 million people and have set a deadline of May 12 for a settlement.
Canvas, a Learning Management System (LMS) used primarily by schools, universities, and other educational institutions, was hacked for a second time on Thursday, following Tuesday's attack in which a trove of private data was breached. As students trying to access grades and study materials opened the page, they saw a message from a hacking group. Schools and universities across the United States had a ransom note pop up on the homepage of their schools’ Canvas sites. “ShinyHunters has breached Instructure (again),” the warning read, as reported by various portals in America. “Instead of contacting us to resolve it they ignored us and did some ‘security patches.’ Instructure still has until EOD 12 May 2026 to contact us,” the ransom note read. User reports on Downdetector also indicated problems with Canvas by Instructure since 4:16 pm ET. Instructure is the company that operates Canvas and has officially acknowledged a "cybersecurity incident" currently under investigation.
The company said that the data breached in the hack included private information that is also found in a campus directory, such as names, email addresses, and student identification numbers. Messages stored within the platform also could have been leaked, it added. Instructure further confirmed that it has found no evidence that sensitive information, like passwords, financial records, government identifiers, or dates of birth, was compromised in the attack. However, it has taken steps to mitigate the situation.
Meanwhile, TechCrunch reported that the hackers compromised Instructure again and defaced the Canvas login pages of several schools. According to the outlet, the cybercrime group published a message on the Canvas login pages of three schools, which read that they will publish the stolen data on May 12 if Instructure fails to “negotiate a settlement.” The outlet checked the pages and noted that the hackers seem to have inserted an HTML file into the login screens to display their message. TechCrunch also reached out to a member of ShinyHunters and asked how they managed to breach the login pages, but the person refused to share specifics. However, he confirmed that this was a second, separate breach. Notably, the hackers claimed that they had stolen data from almost 9,000 schools around the world in the first hack, with nearly 231 million affected people.