Instructure, the edtech company behind Canvas - used by 9k+ universities and other institutions globally - has been targeted by hacking group ShinyHunters, who tonight escalated their attacks, replacing all instances of Canvas with this message
"Instructure didn't fix all of the vulnerabilities, we have more," a spokesperson said. The warning on Canvas set a deadline for "the end of the day by 12 May 2026" before "everything is leaked."
The ShinyHunters message has since been replaced by a Canvas "scheduled maintenance" page. Yikes
NEW: A Columbia student has sent me the following screenshot of what appears to be a large-scale hack of the University's learning software.
Students cannot access Canvas at this time.