:

CANVAS LMS DOWN IN ONGOING RANSOMWARE ATTACK

SECURITY DESK2 MIN READ
WED, MAY 13, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Instructure's Canvas learning management system faces widespread disruptions following a ransomware attack by the ShinyHunters group. The breach has affected schools nationwide, with the NYC Public School system hit particularly hard during final exam season.

Instructure confirmed that hackers exploited a security vulnerability in Canvas to modify login portals and leave extortion messages. The ShinyHunters group has claimed responsibility for the attack, which resulted in the theft of student data and operational disruptions across educational institutions. The company paid a ransom to the threat actors, though service disruptions have persisted. The incident has drawn significant attention from federal authorities, with the U.S. House Committee on Homeland Security calling for Instructure executives to testify about the attack and security lapses that enabled it. The NYC Public School system is simultaneously managing a separate malware attack affecting one Manhattan campus, compounding security challenges across the district. The timing of the Canvas breach during final exams has amplified its impact on students and educators relying on the platform for course materials and grade submissions. This marks the second major cyberattack targeting Canvas within a recent period, raising questions about the platform's security infrastructure. Canvas serves millions of students globally, making it a high-value target for extortion groups. The breach highlights vulnerabilities in critical educational technology infrastructure that many institutions depend on for daily operations. The incident underscores broader cybersecurity challenges facing the education sector, which has become increasingly targeted by ransomware groups seeking high-value data and operational leverage. Schools face particular pressure to pay ransoms quickly due to the disruption of academic calendars and student services. Instructure has not disclosed full details about the vulnerability or timeline for complete service restoration. The company's security practices are now under congressional scrutiny as federal lawmakers examine whether adequate safeguards exist for protecting sensitive student information in education technology platforms.

■ SOURCES

Bloomberg TechBleeping ComputerHacker NewsWiredBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.

8H AGOIndustry Desk

Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.

11H AGOAI Desk

Quad9 provides an open DNS recursive service that prioritizes user privacy and security at no cost. The service blocks malware and phishing domains while maintaining minimal data collection.

14H AGOSecurity Desk

A government website running Ruby on Rails was exploited within hours of a critical vulnerability patch becoming public. The rapid attack demonstrates how quickly threat actors weaponize disclosed security flaws.

14H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.