Canvas back online after major breach, but some California campuses locked amid ongoing threat
-
Click here to listen to this article - Share via
See more from the L.A. Times in Google Search. Set us as preferred
- Canvas, the learning management system used by UC, Cal State, USC, Stanford and California community colleges, went offline Thursday during finals preparations after a massive cybersecurity breach at Instructure.
- Students at dozens of California campuses lost access to coursework and assignments.
- On Friday, the platform was online again, the company said, but still blocked by some California schools amid security concerns.
A massive data breach at the company behind Canvas, one of the nation’s most widely used education technology platforms, stirred chaos across California campuses this week, interrupting classes, assignments and finals preparations for hundreds of thousands of students and professors as hackers threatened to release their personal data.
By Friday, the cyberattack at Utah-based Instructure, which operates the learning management system used by thousands of schools nationwide — including University of California, California State University and community college districts — was largely contained and most of the platform was back in operation, the firm said.
But some campuses were still restricting access Friday, as the crippling breach raised broader questions about how universities can protect student data and keep classes running while relying on centralized third-party tech platforms.
The platform is crucial to communications and workflow among students and professors, and Instructure touts that 8,000 institutions rely on it across the globe. Canvas is where reading assignments and lecture notes are posted. It’s often used to conduct classes, take quizzes and tests, submit coursework, join discussion boards, and chat with teachers. When it shut down, work virtually halted as frantic students and instructors scrambled to make adjustments to deadlines and tests.
“I started getting emails from panicked undergrads,” said May-lee Chai, a San Francisco State creative writing professor. She sent assignments by email with a warning: “Don’t try to upload anything to Canvas.”
Instructure said it notified law enforcement, including the FBI and the U.S. Cybersecurity and Infrastructure Security Agency, about the hack that included names, email addresses, student ID numbers and messages among Canvas users. The breach did not include passwords, dates of birth, government identifiers or financial information, the company said.
What is ShinyHunters?
The group ShinyHunters — which previously has claimed to be behind hacks of Ticketmaster and AT&T — is taking credit for the disruption.
Little is known about the organization, cyber experts said. Security researchers describe it as an extortion group known for gaining access to large databases of private information and threatening releases unless the victims pay up. Canvas is not its first education target. It also has said it was behind earlier attacks and breaches of McGraw Hill and Infinite Campus.
“They’re a loose affiliation of young adults and teenagers ... and they’re particularly good at social engineering. Social engineering is basically being really good liars,” said Luke Connolly, a threat intelligence analyst at the tech security provider Emsisoft. Connolly said “social engineering” can be as “simple as tricking the helpdesk into thinking you are a user who has been locked out.”
Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, said such online criminals are increasingly drawn to providers such as Instructure because penetrating one platform can compromise many school accounts at the same time.
“Even if highly sensitive financial information was not exposed, educational records, communications, and identity data can still be valuable to cyber-criminals for phishing, impersonation, and future attacks,” he said.
Security experts said the incident shows how depending on a single education technology company can deal a paralyzing and potentially damaging blow to institutions that outsource education technology to cloud-based corporations.
“What we’re seeing with Canvas is the same pattern that is playing out across virtually every sector of the U.S. economy,” said JP Castellanos, director of threat intelligence at Binary Defense. “Organizations are consolidating around single centralized technology providers, and that concentration is creating extraordinarily high-value targets.”
The hackers threatened campuses in a letter that popped up when accessing Canvas on Thursday. “You have till the end of the day by 12 May 2026 before everything is leaked.” A UC Berkeley student shared a photo of the threat with The Times.
The response to the disruption and restoration was uneven in California, one of the biggest user bases for Canvas. Stanford and UC Berkeley said the platform was back online for students. A UC webpage on Friday said the system was “making risk-based decisions about when to restore access to Canvas at campuses based on their operational needs.” A CSU website said the university was re-enabling access while urging users to “use caution” and download important documents to their computers. A notice was sent Thursday to Los Angeles Community College District employees saying Canvas was disabled.
In a statement Friday, an Instructure spokesperson said an “unauthorized actor involved in our ongoing security incident made changes to the pages that appeared when some students and teachers were logged in. Out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate.”
“We have confirmed that the unauthorized actor exploited an issue related to our Free-For-Teacher accounts,” said the spokesperson, Brian Watkins. “As a result, we have made the difficult decision to temporarily shut down our Free-For-Teacher accounts. This gives us the confidence to restore access to Canvas.”
What happened during the breach?
In California, the effects immediately rippled across the state’s largest public and private institutions, Stanford and USC. The attack also hit public school districts, including San Diego Unified. A Los Angeles Unified spokesperson said the district does not use Instructure products that were part of the data breach.
Public school districts in Utah and North Carolina reported outages earlier this week. Nationally, campuses including Harvard, Duke and the University of Pennsylvania reported similar outages.
At UCLA, students were locked out of the school-branded version of Canvas, Bruin Learn, midday Thursday.
“Oh my gosh, it is so concerning. Almost every single person I know has been talking about it,” said Titilope Olotu, a junior double-majoring in biology and women and reproductive health. The issue put her behind on assignments and readings for a marine biology assignment and evolutionary medicine courses.
Olotu said she was still locked out Friday morning. So was Sherry Zhou, a senior majoring in political science and communications.
Zhou said she had a paper due Thursday that she would “have to turn in late because we have no access to the reading course materials right now.” Zhou said she was relieved that her professor offered extensions and promised to share materials through another means.
Threats linger
While the breach appears to have mostly affected higher education institutions, K-12 schools have also experienced pain from online security failures.
Over the Labor Day weekend in 2022 a cyberattack disabled computer systems across LAUSD, including the district’s website and systems teachers use to post lessons and take attendance. It was later revealed that the attacker posted approximately 2,000 student assessment records on the dark web and an unspecified number of driver’s license numbers and Social Security numbers, some dating back years. Full recovery took time and many said instruction was disrupted as technicians worked to restore systems and users reset more than 600,000 passwords.
Luis Corrons, a security analyst at Norton, said names, email addresses, student IDs and internal messages can give attackers enough information to craft believable scams when phishing.
“A student receiving an email about Canvas, a course, grades, financial aid or an account reset is much more likely to trust it if the message appears to fit their real school life,” Corrons said.
Anton Dahbura, executive director of the Johns Hopkins University Information Security Institute, said campuses should tread carefully in case risks persist even with Canvas back online. He said students and employees should watch for phishing emails, and colleges should encourage users to change passwords and reauthorize logins while IT teams review Canvas integrations into their systems and access tokens.
“The dependency of so many educational institutions on Canvas is certainly a systemic risk,” Dahbura said. “Therefore, colleges should require stronger security measures plus resilience plans and alternatives for instruction during outages.”
Times staff writer Lee Rogers contributed to this report.