惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
C
Check Point Blog
D
Docker
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
MongoDB | Blog
MongoDB | Blog
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
量子位
有赞技术团队
有赞技术团队
IT之家
IT之家
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
M
MIT News - Artificial intelligence
B
Blog
阮一峰的网络日志
阮一峰的网络日志
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
月光博客
月光博客

Latest news

Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026 Amazon just slashed $250 off the Google Pixel 10 - and a Prime subscription isn't required I found the apps slowing down my PC - how to kill the biggest memory hogs These companies are actually upskilling their workers for AI - here's how they do it Verizon will give you Meta Ray-Bans for free with this Fios Internet deal - how to get yours I tried the new Gemini app for Mac - it has one major advantage over the web version How Google's updated AI Mode will ease your tab clutter when you search Why this MagSafe battery pack is our readers' favorite model right now - especially at its price T-Mobile will give you a Google Pixel 10a for free - plus an extra gift OpenAI's Codex Desktop can run your computer now - and has its own browser Want to build a startup that gets acquired? This founder shares 5 proven tips Google to pay $135M settlement to Android phone users - how to claim your share if you qualify
Worried about the nationwide Canvas data breach? Take the...
2026-05-09 · via Latest news
abstractdatasgettyimages-2256422659
Outflow Designs/ iStock / Getty Images Plus via Getty Images

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Canvas was disrupted this week by a cyberattack.
  • Many students are unable to access the popular educational portal.
  • Instructure says data was stolen; what Canvas users should do next.

Canvas is at the center of an ongoing cyberattack and data extortion attempt by a well-known cybercriminal group that claims to have stolen student records. If you are a Canvas user, you can take defensive measures now.

Also: No one pays ransomware demands anymore - so attackers have a new goal

What is Canvas?

Canvas is a Learning Management System (LMS) from Instructure, a Salt Lake City-based educational technology company founded in 2008.

Designed for remote learning, Canvas has been adopted by thousands of schools for course creation and management, grading, feedback, and coursework submission. Instructure says the LMS now supports tens of millions of users -- students and parents -- and has recorded 27 million mobile app downloads. Canvas is available in over 100 countries. 

What happened?

While Canvas boasts a 100% uptime notice on its website, Instructure CISO Steve Proud said last week that the LMS had "recently experienced a cybersecurity incident perpetrated by a criminal threat actor."

The company began investigating. On May 6, Proud said the company believed the incident had been "contained," but some data may have been exposed -- and it didn't take long for students to begin reporting login issues.

Also: The shadowy SIM farms behind those incessant scam texts - and how to stay safe

On Thursday, May 7, Canvas login interfaces were defaced, with ransom notes reportedly posted by the ShinyHunters group as it moved from data theft to public extortion. Students who tried to log in were unable to access their course materials, likely a deliberate attempt by the cyberattackers to put pressure on Instructure to pay up, with finals just around the corner. 

In response, Canvas displayed a maintenance mode page, an action that had drawn criticism

The hackers' ransom note, which has since circulated online, demands that Instructure contact the group by May 12. 

"ShinyHunters has breached Instructure (again)," the note reads. "Instead of contacting us to resolve it, they ignored us and did some 'security patches.'"

While access has reportedly been restored for most users, with the deadline approaching, this may not be the end of the story.

What is ShinyHunters?

ShinyHunters is a collective of cybercriminals that extorts companies for payment. Since making headlines in 2020 with a swathe of company breaches, ShinyHunter's modus operandi is to quietly infiltrate a target business, steal information, and then publicly pressure the victim into paying a "settlement."

Also: The best free VPNs: Expert tested and reviewed

Often associated with large-scale breaches, ShinyHunters, like many other cybercriminal groups, operates a "leak site." Leak sites are public-facing websites that list alleged victims and the items stolen, and often include a demand for payment. 

If a victim fails to comply, the information stolen from them may be published. Having the victim's name removed from the leak site may also be part of negotiations. 

What information was stolen?

ShinyHunters has threatened to leak data on approximately 275 million students from 8,800 academic institutions if its demands are not met. 

Also: I'm a tech professional, and an AI job scam almost fooled me - here's how I caught on

According to Instructure, exposed data may include:

  • Names
  • Email addresses
  • Student ID numbers
  • Messages between users

"At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved," Instructure said. "If that changes, we will notify any impacted institutions."

Instructure's response

It is not known whether Instructure has communicated with ShinyHunters. Instructure said it is currently "not seeing any ongoing unauthorized activity."

Also: This critical Linux vulnerability is putting millions of systems at risk - how to protect yours

The company has revoked privileged credentials and access tokens associated with affected systems, deployed security patches -- although no associated vulnerability disclosures have been made yet -- and rotated security keys. Instructure said it has also ramped up monitoring across its platforms. 

"As a precaution, we recommend customers follow security best practices, including enforcing MFA on privileged accounts, reviewing admin access, and rotating API tokens or keys where applicable," the company added. 

6 steps to take immediately

  1. School updates: As this security incident appears to affect thousands of schools and academic institutions, reach out to your institution or visit its website and communication channels for updates. 
  2. Passwords: Whenever you suspect you have been involved in a data breach, the first thing you should do is to change the password you use to access your account. If you are using the same password to access other online services, change those passwords as well.  If the ransomware group releases stolen data and manages to grab credentials, those credentials may be made public. You should consider using a password manager to create complex passwords and to receive leak alerts. 
  3. Have I Been Pwned: It's too early for this data breach and any subsequent data leak to be recorded on Have I Been Pwned, but we recommend visiting this website frequently to check whether you have been involved in any online data breaches. It's free, and all you need to do is search with your email address. 
  4. Enable 2FA/MFA: If you have not already done so, enable two-factor or multi-factor authentication on your associated accounts. 
  5. Keep an eye on your email: If Canvas follows appropriate procedures, it should inform users if their information has been exposed -- keep an eye out for any updates. 
  6. Watch out for phishing: However, if stolen email addresses or contact details are leaked online, they may be used in targeted phishing campaigns, so be careful if you receive correspondence that appears to be from your school or Canvas itself. If there are any indications of a phishing attempt -- such as strange grammar, spoofed email addresses, or requests to click unofficial links or open attachments -- verify it by phone or another means first. 

Also: These 5 critical Windows Defender settings are off by default - turn them on ASAP 

We reached out Instructure for comment and a spokesperson shared this statement: 

Yesterday, Instructure discovered the unauthorized actor involved in our ongoing security incident made changes to the pages that appeared when some students and teachers were logged in. Out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate. We have confirmed that the unauthorized actor exploited an issue related to our Free-For-Teacher accounts. As a result, we have made the difficult decision to temporarily shut down our Free-For-Teacher accounts. This gives us the confidence to restore access to Canvas, which is now fully back online and available for use. We regret the inconvenience and concern this may have caused