Canvas (Instructure) LMS Down in Ongoing Ransomware Attack
Canvas (Instructure) experienced a massive ransomware attack by ShinyHunters affecting 9,000 schools and 275 million students, teachers, and staff, with the threat actors demanding ransom by May 12, 2026, before leaking sensitive data including names, emails, and ID numbers. This incident represents a critical business continuity and reputational risk for educational institutions, exposing significant vulnerabilities in widely-adopted enterprise learning platforms and highlighting the inadequacy of post-breach security patches against sophisticated threat actors. IT leaders must reassess their vendor risk management practices and incident response protocols, particularly for mission-critical educational infrastructure serving hundreds of millions of users.
Canvas (Instructure) experienced a massive ransomware attack by ShinyHunters affecting 9,000 schools and 275 million students, teachers, and staff, with the threat actors demanding ransom by May 12, 2026, before leaking sensitive data including names, emails, and ID numbers. This incident represents a critical business continuity and reputational risk for educational institutions, exposing significant vulnerabilities in widely-adopted enterprise learning platforms and highlighting the inadequacy of post-breach security patches against sophisticated threat actors. IT leaders must reassess their vendor risk management practices and incident response protocols, particularly for mission-critical educational infrastructure serving hundreds of millions of users.