Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

Canvas breach turns to extortion: Education Department alert follows ransom deadline

After ShinyHunters set a May 12 ransom deadline and claimed a second intrusion, the U.S. Department of Education warned schools about the ongoing Canvas LMS incident.

Malik Johnson, · May 30, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
School IT administrator reviewing a federal alert at a district office

The Canvas LMS breach moved from disclosure to demand in mid-May 2026: the extortion crew ShinyHunters had set a ransom deadline of May 12, 2026 for Instructure, per ComplexDiscovery's tracking, and claimed a second attack against the company within eight months — including the defacement of university and college login pages, as reported by Dark Reading. On May 12, the U.S. Department of Education issued a Technology Security Alert (GENERAL-26-27, updated May 29) addressing the ongoing cybersecurity incident involving Canvas and advising institutions on steps to take. Instructure has continued to describe the incident as under investigation.

What do we know as of late May?

The established facts: an intrusion in late April affecting Canvas with data theft and an outage; a threat-actor claim of tens of millions of records across thousands of schools — still a claim, not a verified count; a second claimed intrusion with login-page defacements at institutions; a ransom deadline that passed on May 12; and an active federal alert to educational institutions. What remained unverified: the actual volume and sensitivity of data taken, whether any ransom was paid, and the intrusion vector. Reporting on the claims and the alert frames the incident as a textbook data-extortion campaign — leak-site pressure, escalating deadlines, and secondary attacks on the same victim — rather than a service disruption alone.

What does the Education Department alert say?

The alert, addressed to the federal-aid and institutional community, describes the ongoing incident involving Canvas and its potential impact on institutional systems and student data — with an update on May 29, 2026 reflecting the investigation's progress. It directs institutions to review their integrations with Canvas, monitor for unauthorized access and defacements on their login infrastructure, and prepare for notification obligations affecting student records, which may implicate FERPA requirements for the institutions themselves.

What should institutions do now?

  1. Follow the Department of Education alert's guidance — including its updated version — as the authoritative federal channel for this incident.
  2. Review SSO and integration logs for the April-May window: anomalous authentications, new API credentials, defaced or altered login pages.
  3. Prepare FERPA notifications with counsel if student records are confirmed exposed — the alert era makes timing and scope assessments urgent.
  4. Warn your community about follow-on phishing: emails referencing real courses and the breach itself are the standard second wave.
  5. Plan for the vendor relationship question: security questionnaires, contractual breach-response duties, and the second-intrusion pattern all belong in the institutional review.

What should students and families take from this?

The advice from our initial coverage stands and hardens: change Canvas passwords and their reuse, enable MFA on school accounts, and treat any email about the breach or Canvas credentials as suspect unless it comes through the institution's official portal. The second-attack pattern matters to individuals too — an extortion crew that defaces login pages is comfortable with impersonation, so the "university login page" itself deserves a bookmark rather than a search. As verified findings emerge from Instructure and regulators, we will update our coverage.

Frequently Asked Questions

What happened after the Canvas ransom deadline?
The May 12, 2026 deadline passed with the U.S. Department of Education issuing its security alert the same day and updating it May 29. The crew had claimed a second intrusion including defaced university login pages; whether any ransom was paid remained unverified.
What is the Department of Education alert GENERAL-26-27?
A May 12, 2026 Technology Security Alert warning schools about the ongoing Canvas LMS incident, advising review of integrations, monitoring for unauthorized access and defacements, and preparation for student-data notification obligations.
Should students trust Canvas login pages right now?
Navigate to Canvas only through your institution's official portal bookmark. Attackers in this campaign defaced university login pages, so a searched-for or emailed link is not a safe path.