{"id":92945,"date":"2026-05-08T05:38:39","date_gmt":"2026-05-08T05:38:39","guid":{"rendered":"https:\/\/diyhaven858.wasmer.app\/index.php\/the-canvas-hack-is-a-new-kind-of-ransomware-debacle\/"},"modified":"2026-05-08T05:38:39","modified_gmt":"2026-05-08T05:38:39","slug":"the-canvas-hack-is-a-new-kind-of-ransomware-debacle","status":"publish","type":"post","link":"https:\/\/diyhaven858.wasmer.app\/index.php\/the-canvas-hack-is-a-new-kind-of-ransomware-debacle\/","title":{"rendered":"The Canvas Hack Is a New Kind of Ransomware Debacle"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.<\/p>\n<p class=\"paywall\">The widely used digital learning platform Canvas was put into \u201cmaintenance mode\u201d on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker &#8220;ShinyHunters.&#8221; Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.<\/p>\n<p class=\"paywall\">Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.<\/p>\n<p class=\"paywall\">In a running incident update log that began on May 1, Steve Proud, Instructure&#8217;s chief information security officer, said that the company had \u201crecently experienced a cybersecurity incident perpetrated by a criminal threat actor.\u201d He added on May 2 that \u201cthe information involved\u201d for \u201cusers at affected institutions\u201d included names, email addresses, student ID numbers, and messages exchanged by users on the platform.<\/p>\n<p class=\"paywall\">The situation was ultimately marked as \u201cResolved\u201d on Wednesday, with Proud writing that \u201cCanvas is fully operational, and we are not seeing any ongoing unauthorized activity.\u201d At midday on Thursday, though, the Instructure status page registered an \u201cissue\u201d where \u201csome users are having difficulties logging into Student ePortfolios.\u201d Within a few hours, the company had added another status update: \u201cInstructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.\u201d Late Thursday evening, the company said that Canvas was available again \u201cfor most users.\u201d<\/p>\n<p class=\"paywall\">TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools&#8217; Canvas portals by injecting an HTML file to display their own message on the schools&#8217; Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.<\/p>\n<p class=\"paywall\">The message from attackers \u201curged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12\u2014or else risk their data being leaked,\u201d The Crimson reported. \u201cIt is unclear what information tied to Harvard affiliates was included in the alleged breach.\u201d<\/p>\n<p class=\"paywall\">Instructure did not immediately respond to a request for comment about Thursday&#8217;s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.<\/p>\n<p class=\"paywall\">The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States. The widely used digital learning platform Canvas was put into \u201cmaintenance mode\u201d on Thursday after [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":92946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_daextam_enable_autolinks":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[11],"tags":[],"class_list":["post-92945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/diyhaven858.wasmer.app\/wp-content\/uploads\/2026\/05\/SSECURITY_HARVARD.jpg","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts\/92945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/comments?post=92945"}],"version-history":[{"count":0,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/posts\/92945\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/media\/92946"}],"wp:attachment":[{"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/media?parent=92945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/categories?post=92945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/diyhaven858.wasmer.app\/index.php\/wp-json\/wp\/v2\/tags?post=92945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}