
Online education platform Canvas experienced a significant service disruption during finals week after Instructure, the company behind Canvas, detected unauthorized activity tied to a cybersecurity incident. According to CyberGuy reports, Instructure detected unauthorized activity in Canvas on April 29, 2026, immediately revoked the unauthorized party's access, and started an investigation with outside forensic experts. The company then identified additional unauthorized activity on May 7, 2026, when the unauthorized actor made changes to pages that appeared when some students and teachers were logged in through Canvas. Out of caution, Instructure temporarily took Canvas offline into maintenance mode to contain the activity and investigate further.
The service disruption affected millions of students and teachers across colleges, universities and K-12 schools during the worst possible timing - finals week. As reported by CyberGuy, Canvas serves as the main classroom platform where schools post assignments, messages, grades, class updates and exam instructions. The outage created confusion at a critical time when students needed access to submit papers, check exam details, or message professors. The disruption primarily impacted the mobile application, which accounts for 56% of reported problems, while the website represented 33% of user reports, and login-related issues constituted 11% of reported problems.
In a subsequent update at 13:45 AEST on June 9, 2026, Canvas announced that the technical issue had been identified by its engineering teams. According to the company's status update, engineers were actively working to implement a fix for the platform disruption. Instructure later confirmed that the unauthorized actor exploited an issue related to its Free-For-Teacher accounts, leading to the temporary shutdown of these accounts as a precautionary measure. The company has since revoked privileged credentials and access tokens tied to affected systems, deployed additional platform protections, rotated certain internal keys, restricted token creation pathways, and added monitoring across its platforms. Instructure says its outside forensic partner reviewed known indicators and found no evidence that the threat actor currently has access to the platform.
Based on Instructure's investigation, the data taken in the April 29 incident includes certain personal information of users at affected organizations, including names, email addresses, student ID numbers and messages among Canvas users. However, Instructure has found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. The company also said it has found no evidence that data was taken during the May 7 activity, though the investigation remains ongoing. The hacking group ShinyHunters claimed responsibility for the attack and reportedly threatened to leak school data unless affected schools responded by May 12, 2026, though the group's claims about having data tied to nearly 9,000 schools and about 275 million people have not been publicly verified by Instructure.
According to CyberGuy reports, Canvas is now fully back online and available for use, though Free-For-Teacher accounts remain temporarily shut down while Instructure works through the issue. The company has notified impacted organizations on May 5, 2026, and will contact affected institutions' primary contacts directly. For students, parents and employees, Instructure recommends that the school or institution should be the first point of contact regarding any personal information involvement. The company also advises being cautious of unexpected emails or messages about the incident, avoiding suspicious links, and reporting anything unusual to the school's IT or security team. Schools should also warn students and staff about follow-up scams, as the risk can continue through fake emails, fake login pages and scam messages even after the platform comes back online.