:

CANVAS LMS DOWN IN ONGOING RANSOMWARE ATTACK

SECURITY DESK2 MIN READ
WED, MAY 13, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Instructure's Canvas learning management system faces widespread disruptions following a ransomware attack by the ShinyHunters group. The breach has affected schools nationwide, with the NYC Public School system hit particularly hard during final exam season.

Instructure confirmed that hackers exploited a security vulnerability in Canvas to modify login portals and leave extortion messages. The ShinyHunters group has claimed responsibility for the attack, which resulted in the theft of student data and operational disruptions across educational institutions. The company paid a ransom to the threat actors, though service disruptions have persisted. The incident has drawn significant attention from federal authorities, with the U.S. House Committee on Homeland Security calling for Instructure executives to testify about the attack and security lapses that enabled it. The NYC Public School system is simultaneously managing a separate malware attack affecting one Manhattan campus, compounding security challenges across the district. The timing of the Canvas breach during final exams has amplified its impact on students and educators relying on the platform for course materials and grade submissions. This marks the second major cyberattack targeting Canvas within a recent period, raising questions about the platform's security infrastructure. Canvas serves millions of students globally, making it a high-value target for extortion groups. The breach highlights vulnerabilities in critical educational technology infrastructure that many institutions depend on for daily operations. The incident underscores broader cybersecurity challenges facing the education sector, which has become increasingly targeted by ransomware groups seeking high-value data and operational leverage. Schools face particular pressure to pay ransoms quickly due to the disruption of academic calendars and student services. Instructure has not disclosed full details about the vulnerability or timeline for complete service restoration. The company's security practices are now under congressional scrutiny as federal lawmakers examine whether adequate safeguards exist for protecting sensitive student information in education technology platforms.

■ SOURCES

Bloomberg TechBleeping ComputerHacker NewsWiredBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.

3H AGOAI Desk

A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.

5H AGOSecurity Desk

Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.

20H AGOIndustry Desk

Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.

23H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.