:

CANVAS LMS DOWN IN ONGOING RANSOMWARE ATTACK

SECURITY DESK2 MIN READ
MON, JUN 8, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Instructure's Canvas learning management system faces widespread disruptions following a ransomware attack by the ShinyHunters group. The breach has affected schools nationwide, with the NYC Public School system hit particularly hard during final exam season.

Instructure confirmed that hackers exploited a security vulnerability in Canvas to modify login portals and leave extortion messages. The ShinyHunters group has claimed responsibility for the attack, which resulted in the theft of student data and operational disruptions across educational institutions. The company paid a ransom to the threat actors, though service disruptions have persisted. The incident has drawn significant attention from federal authorities, with the U.S. House Committee on Homeland Security calling for Instructure executives to testify about the attack and security lapses that enabled it. The NYC Public School system is simultaneously managing a separate malware attack affecting one Manhattan campus, compounding security challenges across the district. The timing of the Canvas breach during final exams has amplified its impact on students and educators relying on the platform for course materials and grade submissions. This marks the second major cyberattack targeting Canvas within a recent period, raising questions about the platform's security infrastructure. Canvas serves millions of students globally, making it a high-value target for extortion groups. The breach highlights vulnerabilities in critical educational technology infrastructure that many institutions depend on for daily operations. The incident underscores broader cybersecurity challenges facing the education sector, which has become increasingly targeted by ransomware groups seeking high-value data and operational leverage. Schools face particular pressure to pay ransoms quickly due to the disruption of academic calendars and student services. Instructure has not disclosed full details about the vulnerability or timeline for complete service restoration. The company's security practices are now under congressional scrutiny as federal lawmakers examine whether adequate safeguards exist for protecting sensitive student information in education technology platforms.

■ SOURCES

Bloomberg TechBleeping ComputerHacker NewsWiredBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Apple has published SOC 3 audit reports for its Private Cloud Compute infrastructure, providing third-party verification of security controls for on-device AI processing that routes some tasks to Apple servers.

10H AGOIndustry Desk

A developer discovered their coding interview assignment included hidden malware designed to execute via Git hooks. The sophisticated setup raised questions about interview practices and candidate vetting.

13H AGOIndustry Desk

Engineers designing passkeys overlooked critical usability issues that confuse average users, according to criticism gaining traction in tech communities. The passwordless authentication standard is struggling with consumer adoption due to poor design decisions.

14H AGOAI Desk

Upbound Group disclosed that hackers exploited stolen data to create $13 million in fraudulent Acima leases. The fintech company's security breach gave threat actors access to customer information used to establish fake lease accounts.

14H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.