On the morning of May 7, students logging into Canvas to access their final exams found extortion messages where their coursework should have been. The message was from a ransomware group called ShinyHunters, and it wasn’t empty posturing.
The group had been inside Instructure’s systems since April 30. In the week before finals, they had exfiltrated 3.65 terabytes of data — records from an estimated 275 million users across 8,809 institutions, including K-12 schools, community colleges, and universities across North America, Europe, and Asia-Pacific.
What happened next — a ransom paid, a shutdown during finals, and a breach disclosure affecting hundreds of millions of people — is the kind of incident that changes how educators, students, and parents think about the digital systems that hold the most sensitive records of students’ academic lives.
What Is Canvas?
For readers outside higher education: Canvas, built by Instructure, is the dominant learning management system (LMS) in the United States and widely used internationally. It’s where assignments are submitted, grades are posted, course materials are stored, and students communicate with instructors.
More than half of American universities use Canvas as their primary academic platform. Many K-12 districts use it as well. If you or someone in your household has been a student in the last decade, there’s a reasonable chance their academic life ran through Canvas.
That scale is exactly what makes this breach consequential. Canvas isn’t a niche app. It’s infrastructure.
How the Breach Happened
ShinyHunters gained initial access by exploiting a vulnerability in Instructure’s Free-for-Teacher program — a publicly accessible account tier that let educators create free Canvas accounts to test the system. This gave the group a foothold that they used to move laterally into Instructure’s broader infrastructure.
Once inside, they exfiltrated data across multiple institutional tenants. Because Canvas operates as a multi-tenant platform — many institutions sharing the same underlying infrastructure, each in their own logical space — a single compromise of Instructure’s systems had downstream impact across thousands of separate institutions.
ShinyHunters claimed 8,809 institutions were affected. The breach was not announced publicly for the first week, during which the group continued its access and assembled the full dataset before surfacing with its demands.
What Was Taken
The stolen data included:
- Names and email addresses — the core personally identifiable information present for every user
- Student ID numbers — institutional identifiers that can be used to access university systems, apply for financial aid, or impersonate students
- Course enrollment details — what a person studied, when, and where
- Internal messages — direct messages sent between students and instructors within Canvas
The combination is significant. Course enrollment records create a detailed academic biography. Student ID numbers have practical downstream use. And internal messages between students and instructors often contain sensitive content: medical accommodations requested, grade disputes, personal circumstances shared to explain absences.
It’s not the kind of data breach where only generic contact information is exposed. It’s a breach of the record of someone’s academic life.
The Disruption During Finals
The breach’s most visible impact came during the May 7 extortion display. Students who expected to access final exams instead encountered messages from ShinyHunters, effectively shutting down the testing infrastructure for institutions that relied on Canvas for exam delivery.
For students already under end-of-semester pressure, the disruption wasn’t abstract. Classes scrambled to reschedule. Institutions that had no contingency for LMS unavailability during finals faced difficult choices about how to proceed fairly.
On May 11 — one day before ShinyHunters’ deadline to begin leaking the stolen data publicly — Instructure paid a ransom. Unconfirmed reports suggest the payment was in the range of $10 million, though Instructure has not confirmed the figure.
Paying ransomware attackers doesn’t guarantee data security. It typically purchases a temporary promise not to publish what’s already been stolen — a promise made by an organization with no legal accountability for honoring it.
Why LMS Platforms Are High-Value Targets
Learning management systems have a property that makes them attractive targets beyond pure data volume: they hold records that are genuinely difficult to replace or revoke.
A leaked password can be changed. A compromised credit card number can be cancelled. But academic records — enrollment histories, course completions, internal communications — don’t have a revocation mechanism. A student whose Canvas messages are exposed can’t undo the content of those messages. A student whose ID number is stolen and used fraudulently faces a complex recovery process with their institution.
LMS platforms also have structural characteristics that elevate breach impact:
Multi-tenant architecture means that a single vulnerability at the platform provider propagates across thousands of institutions simultaneously, rather than being contained within one organization.
Sensitive contextual data like disability accommodations, grade appeals, and personal circumstances shared in instructor messages is mixed with standard academic records.
Long retention periods mean that records from students who graduated years ago may still be on the platform, expanding the population at risk.
The Canvas breach is not an isolated incident specific to one institution’s poor security posture. It’s a reminder that the platforms institutions outsource their academic infrastructure to are themselves breach targets.
What Students and Parents Should Do Now
If you or your student attended an institution using Canvas — which includes the majority of U.S. universities — treat this as a breach disclosure that affects you until proven otherwise.
Change your institutional email password. The stolen data includes email addresses linked to institutional accounts. These are the addresses associated with Canvas logins and potentially with other university systems.
Monitor your student ID. If the breach exposed your student ID number, check with your institution’s registrar or bursar’s office about placing a flag on your records to prevent unauthorized access.
Watch for phishing. Attackers who have your name, email, and institutional affiliation can send convincing phishing messages that appear to be from your institution, instructor, or financial aid office. Be suspicious of any email asking you to log in, confirm your identity, or take urgent action.
Check your institution’s breach disclosure. Institutions should be sending specific notifications to affected users. If you haven’t received one, contact your institution’s IT or student services office directly.
Don’t use the same password elsewhere. If your Canvas password (or a variant of it) is used on other accounts, change those accounts now.
The Deeper Lesson About Centralized Student Data
The Canvas breach highlights a structural tension in how educational institutions manage student data.
Over the past two decades, schools and universities have moved away from self-hosted systems toward cloud-based platforms that offer better features, lower IT costs, and continuous updates. The tradeoff is concentration: millions of students’ records housed in a single vendor’s infrastructure.
When that infrastructure is breached — not through any institution’s fault, but through a vulnerability in the shared platform — the fallout is measured in millions rather than thousands.
Individual students have almost no input into this architecture. You enroll in a university; the university uses Canvas; your records are in Canvas. You didn’t agree to share your academic life with a multi-tenant cloud platform in the way you’d consciously choose a personal storage service. It just happens as a condition of enrollment.
That’s distinct from the personal files and records you choose to store in personal cloud services. The decisions you make about where to keep your own documents, photos, and personal records are yours to make based on the security model you want.
Protecting Personal Records That Are Yours to Control
Your academic transcript, tuition receipts, financial aid documents, and any copies of your coursework that you personally maintain are different from what’s on Canvas. Those are records you hold copies of — and where you store them is your choice.
For personal copies of academic and financial records, the principles are the same as for any sensitive document:
Store them somewhere with encryption in transit and at rest. Understand the provider’s data retention and deletion policy. Choose a provider whose business model doesn’t depend on monetizing your content.
daftei stores files with TLS 1.3 in transit and AES-256 at rest, offers 5 GB free with unlimited storage on Pro (starting at $5.99/month), and doesn’t sell data or use your files to train AI models. It’s designed for exactly this kind of personal record-keeping: documents that are yours, stored with a clear security posture, deleted permanently when you ask.
The Canvas breach affected data you had no control over. The records you keep yourself — that’s a different category. You get to choose how those are stored.