
Millions of students at universities and schools across multiple countries are dealing with the fallout of a significant cyberattack on Canvas, the widely used educational platform, after a hacking group stole 3.5 terabytes of sensitive student data and threatened to release it publicly unless a ransom was paid by May 12.
What happened and how widespread it is
Canvas, which is owned by tech firm Instructure and used by approximately 30 million people at nearly 9,000 institutions worldwide, was targeted by a cybercrime group called ShinyHunters. The attack disrupted access to the platform beginning earlier in the week, leaving students unable to access coursework, submit assignments or communicate with instructors at some of the most recognizable universities in the world.
By Saturday, May 9, Instructure’s status page confirmed that Canvas had been restored for most users, though several institutions noted their systems were not yet fully operational. It was not publicly confirmed whether any ransom payment had been made.
Breaking news: Canvas hackers gave up the site after receiving million student requests to raise their grades.
— Khoa Vu (@KhoaVuUmn) May 8, 2026
What data was stolen and the ransom demand
ShinyHunters said it had obtained 3.5 terabytes of data from the breach, including student names, email addresses, student identification numbers and private messages. The group set a deadline of May 12 to receive payment, threatening to release the data publicly if their demands were not met.
On May 5, the group posted a message indicating that Instructure had not engaged in discussions with them and described their demand as lower than might be expected. No specific dollar figure was publicly disclosed.
Which schools and universities were affected
The attack reached institutions across the United States, the Netherlands, Sweden, Australia and the United Kingdom. Penn State, Harvard, the University of Illinois, Columbia and Georgetown were among the schools working to adjust or extend exam deadlines to accommodate students who could not access their coursework.
Harvard’s student newspaper reported that access had been unavailable since Thursday. The University of Cambridge said it had temporarily suspended access to Canvas on Friday as a precaution. The University of Sydney said Canvas had been restored but not yet opened to students and staff while internal checks were completed. The University of Alberta in Canada said its version of the platform had come back with reduced functionality.
The timing was widely noted as particularly difficult. A significant portion of US and international institutions are currently in the middle of final exam season, making the disruption considerably harder to manage than it would be at any other point in the academic year.
Who ShinyHunters are and why this matters
ShinyHunters is a global cybercrime group that has been active since 2019 and has claimed responsibility for a series of high-profile data breaches. Their most notable recent target before Canvas was Rockstar Games, the developer behind the Grand Theft Auto franchise.
The Canvas attack is part of a broader trend that security experts have increasingly flagged: the targeting of schools, universities and the technology companies those institutions rely on. Educational organizations often hold large volumes of personal and academic data, and their security infrastructure is not always as robust as that of large financial or corporate institutions, making them attractive targets for groups seeking ransom payouts.
What students and families should do now
The FBI confirmed it was aware of a service disruption affecting a learning system and acknowledged the impact on schools and students across the country, without naming Canvas specifically in its statement.
Students whose institutions use Canvas should monitor official communications from their schools regarding platform status, any changes to exam or assignment deadlines, and whether personal data was confirmed to be part of the stolen files. The May 12 ransom deadline will be a critical date, as it may determine whether any of the stolen student information becomes publicly accessible.
SOURCES: CNN, ALJAZEERA