惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
人人都是产品经理
人人都是产品经理
罗磊的独立博客
博客园 - 聂微东
雷峰网
雷峰网
量子位
美团技术团队
V
V2EX
The GitHub Blog
The GitHub Blog
大猫的无限游戏
大猫的无限游戏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
The Cloudflare Blog
爱范儿
爱范儿
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
Jina AI
Jina AI

NPR Topics: Technology

Trump administration imposes restrictions for Anthropic to halt access to 2 AI models Australia plans to strengthen laws banning children from social media Despite AI bubble fears, memory chip makers work to fill insatiable demand U.S. military works on building a better meal for the troops Meta plans to release AI-powered prediction market app, documents show Star Fox Review: Can't quite teach an old Fox new tricks Is AI 'one big bubble'? Behind the tech sell-off An AI proxy war could reshape Congress — before Congress reshapes AI Get with the times — here's what a 'Luddite' means today Snap plans to sell $2,000 AR glasses. Are they the future of wearable tech? Are Snap's $2,195 smart glasses the next big thing in tech? Researchers find malware that may have aimed to slow down Iran's nuclear program Anthropic incident leaves confusion about Trump administration's AI regulation SpaceX IPO makes history as largest ever. Stock gains 19% on first day SpaceX blasts off with a record-breaking $75 billion IPO The theory taking the rich by storm: China funds data center haters ICE denies having a protester database. But a letter to Congress sheds more light Pope Leo calls AI firms a new form of colonialism, echoing tech critics AI development is driving economic inequality, says tech critic Karen Hao Hey, Siri: Apple just announced a long-awaited AI update Kalshi and Polymarket crack down on paid influencers claiming election fraud Most K-12 teachers say AI's impact on education will eclipse the internet or computers I wrote about George Santos. Then he made a violent threat and lied about it What do you actually get when you pay for AI? Thieves are targeting the world's copper. This phone company is fighting back Trump signs order requesting AI companies submit products for government review DOJ is investigating former congressman George Santos for insider trading on Kalshi Trump signs AI safety order seeking voluntary review of new models Florida sues OpenAI and Sam Altman over alleged safety lapses AI giant Anthropic prepares to sell stock to the public; files preliminary IPO paperwork
Canvas is back online, but questions — and final exam dis...
Rachel Treis · 2026-05-09 · via NPR Topics: Technology
An image of a notice sent by Georgia Tech's information technology department warning users about the Canvas breach on Friday.

An image of a notice sent by Georgia Tech's information technology department warning users about the Canvas breach on Friday. Michael Warren/AP hide caption

toggle caption

Michael Warren/AP

The online education platform Canvas went offline after a data breach on Thursday, temporarily leaving students and faculty at thousands of U.S. colleges — and K-12 schools — without access to course materials and communications during finals period.

"I'm sure somewhere in the country when the outage happened, there probably were people actually taking final exams on the platform when it crashed," says Damon Linker, a senior lecturer in political science at the University of Pennsylvania.

Thirty million users — including at half of the higher education institutions in North America — rely on Canvas to manage courses, submit assignments, view grades and facilitate communication, according to its parent company, Instructure.

But when Linker and many other users tried to do so on Thursday afternoon, they met a black screen and a warning message.

"ShinyHunters has breached Instructure (again)," it read. "Instead of contacting us to resolve it they ignored us and did some 'security patches.'"

ShinyHunters is the same entity that took credit for a massive Ticketmaster data breach in 2024. Like many such groups, it's a cluster of young people working remotely together, "kind of like a ransomware gang," says Rachel Tobac, the CEO of SocialProof Security, which trains people and companies to defend themselves against hackers.

ShinyHunters wrote on a threat intelligence website earlier this week that the initial breach on Saturday involved data — including private messages — from 275 million students, teachers and staff at nearly 9,000 schools worldwide. The group said Thursday that affected schools can prevent the release of their data by consulting with cyber advisory firms and negotiating settlements through the encrypted chat platform Tox.

"You have till the end of the day by 12 May 2026 before everything is leaked," the hackers wrote.

Instructure has confirmed a series of cybersecurity breaches this week and provided status updates on its website. It said the breach only appeared to involve identifying information like names, email addresses, student ID numbers and user messages — no passwords, birth dates, government identifiers or financial information.

Instructure confirmed on an FAQ page that it started an investigation after it first detected unauthorized activity in Canvas on April 29, and took Canvas offline on Thursday after that same unauthorized actor "made changes that appeared when some students and teachers were logged in." They said the actor exploited an issue with its Free-for-Teacher accounts, which it has temporarily shut down.

"This gives us the confidence to restore access to Canvas, which is now fully back online and available for use," it said in a statement to NPR. "We regret the inconvenience and concern this may have caused."

It's not clear whether Instructure paid a ransom or what the return of Canvas access could mean for the hackers' May 12 deadline.

Tobac says Canvas could be back online because of a successful negotiation, or because the hackers "didn't get super far in their attack." Either way, she says users should stay vigilant, especially for phishing messages — whether it's someone posing as Canvas prompting a password change, or pretending to be a professor sending course materials.

"I would operate under the assumption that there's going to be some knock-on effects here," she says.

Not everyone got back online immediately 

Just before midnight on Thursday, Instructure posted online that "Canvas is now available for most users," though two separate services, Canvas Beta and Canvas Test, remained in maintenance mode.

Students and faculty at at least some schools were still unable to access Canvas on Friday — either because service had not yet been restored or because administrators warned them to stay away.

Penn State University, for example, said Friday morning that while the school's Canvas access had been partially restored, it was "not yet ready for use."

"Technical teams at Penn State are actively working to prepare the system for our community," it added. "As access is restored, Canvas integrations and related services will be brought back online in phases."

Several schools have taken similar approaches, either temporarily disabling Canvas access or outright asking users to steer clear. The University of California said across its schools, "Canvas access will not be restored until we are confident the system is secure."

And it's not just higher education: The Montgomery County Public School system in Maryland alerted families on Friday morning that even as service returned, it is "continuing to test and review systems before restoring access."

Tobac says this could mean that schools think the attackers might still be within their systems, potentially stealing information like passwords and messages.

"The attackers probably got some sensitive information and … [schools] don't want this information out online," she says.

Many schools are urging users to be on high alert for any unsolicited emails or messages that appear to come from Canvas, especially those requesting login credentials, as Georgetown University warned. The University of Amsterdam — which says it's one of 44 Dutch educational institutions affected — also recommends people change their passwords on any other sites where they use the same one.

Tobac also recommends using a password manager — to generate long, random passwords for each login — and turning on multi-factor authentication for all online accounts, not just Canvas. She says any student or professor who gets a suspicious call, text or email should "use another method of communication to verify what is authentic."

"Even if there was no breach yesterday, I would say these are the things that I recommend you do," she adds, urging people to "be politely paranoid."

The breach disrupts finals, highlights vulnerabilities

Several schools affected by the breach have already postponed or outright scrapped some final exams, with others warning students and professors that they might need to do so.

The University of Illinois is postponing all final exams and assignments scheduled through Sunday. Penn State canceled certain exams scheduled for Thursday night and Friday, saying it was working with faculty to "determine next steps for final grading" and urging students to check their emails (not Canvas) regularly in the meantime. And Baylor University delayed Friday exams and asked all faculty to send students "whatever study materials they have on their local computers to students as soon as possible."

The breach has underscored how much of academia relies on a single, centralized platform.

Linker, of UPenn, told NPR that he received an influx of panicked messages from students on Thursday afternoon when they suddenly couldn't access PowerPoints, readings and previous exams as they tried to study for Monday's final.

"The problem with using a platform like Canvas is that most [students] are not going to have the readings available printed out or on their laptops," he explains. "It all lives on the online platform, and if that platform goes down, they have no way to access them."

He told students on Thursday that he would upload the course materials to another platform (like Dropbox or Google Docs) if Canvas access wasn't restored by Friday morning. Fortunately, he says, it came back online shortly before 9 a.m. ET.

But Linker says he has concerns about relying fully on Canvas in the future.

"Given what this has exposed, the vulnerability involved and also the concern with the data breaches, I'm starting to rethink whether this is really a wise way to proceed," he says.

One example of that is grading. Linker says Canvas makes it so easy to calculate and weigh students' scores — on individual assessments and overall — that it's come to function as a digital grade book. Going forward, he says he may start keeping an analog record of students' grades just in case.

While Canvas does have competitors like Blackboard, Linker says he doesn't think any would be less vulnerable to a future breach. And Tobac agrees.

"The problem is not that this one website had this cyber event, right? Because nothing in this world is unhackable," she says. "The thing that we have to think about is disaster recovery: How do we continue doing business when there is a cyber event, and how do we do our very best to keep the bad actors out?"

Tobac says this week has shown that many institutions did not have a clear plan for how students and professors can be in touch and access course materials without Canvas. She said those plans should vary based on schools' different circumstances and schedules — which might explain why some are proceeding with finals as usual while others are scrapping exams altogether. But she'd like them to approach the immediate aftermath with one common goal.

"We have to treat people with dignity and respect," Tobac says. "And I hope that that is something that the institutions do, within their timelines and constraints."