{"id":126673,"date":"2026-05-08T17:30:17","date_gmt":"2026-05-08T17:30:17","guid":{"rendered":"https:\/\/christiancorner.us\/index.php\/2026\/05\/08\/schools-disrupted-across-the-country-due-to-canvas-violations-6-steps-to-be-taken-now\/"},"modified":"2026-05-08T17:32:17","modified_gmt":"2026-05-08T17:32:17","slug":"schools-disrupted-across-the-country-due-to-canvas-violations-6-steps-to-be-taken-now","status":"publish","type":"post","link":"https:\/\/christiancorner.us\/index.php\/2026\/05\/08\/schools-disrupted-across-the-country-due-to-canvas-violations-6-steps-to-be-taken-now\/","title":{"rendered":"Schools disrupted across the country due to canvas violations: 6 steps to be taken now"},"content":{"rendered":"<p>\n<\/p>\n<div>\n<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage c-cmsImage_loaded\" style=\"aspect-ratio:1280\/720.1039411000432;\"><source media=\"(max-width: 767px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/2fa09424b4bb439018853f16dac822d633ea1d14\/2026\/05\/08\/9c25110c-6f9a-4b32-ae0f-61f1285a50a6\/abstractdatasgettyimages-2256422659.jpg?auto=webp&amp;width=768\" alt=\"abstractdatasgettyimages-2256422659\"><source media=\"(max-width: 1023px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/39b9f6bb97c7475aaa88f0f23740d677b6170915\/2026\/05\/08\/9c25110c-6f9a-4b32-ae0f-61f1285a50a6\/abstractdatasgettyimages-2256422659.jpg?auto=webp&amp;width=1024\" alt=\"abstractdatasgettyimages-2256422659\"><source media=\"(max-width: 1440px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/e1f146a956273c4df737e1d3a5185e18833f6f86\/2026\/05\/08\/9c25110c-6f9a-4b32-ae0f-61f1285a50a6\/abstractdatasgettyimages-2256422659.jpg?auto=webp&amp;width=1280\" alt=\"abstractdatasgettyimages-2256422659\"><\/source><\/source><\/source><\/picture><\/div>\n<p> <!----><\/div><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall u-block\">Outflow Design\/iStock\/Getty Images Plus via Getty Images<\/span><\/figcaption><\/figure>\n<p><em>Follow ZDNET: <\/em><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=zdnet.com\" class=\"c-regularLink\">Add us as a favorite source<\/a><em>  On Google.<\/em><\/p>\n<hr\/>\n<h3>ZDNET Highlights<\/h3>\n<ul>\n<li>Canvas was disrupted by a cyberattack this week.<\/li>\n<li>Many students are unable to access popular educational portals.<\/li>\n<li>Instructor says data was stolen; What should Canvas users do next?<\/li>\n<\/ul>\n<hr\/>\n<p>Canvas is at the center of an ongoing cyberattack and data extortion attempt by a well-known cybercriminal group, which claims to have stolen student records. If you&#8217;re a Canvas user, you can take defensive measures now.<\/p>\n<p><strong>Also: No one pays ransomware demands anymore \u2013 so attackers have a new target<\/strong><\/p>\n<h2>What is canvas?<\/h2>\n<p>Canvas Instruction is a learning management system (LMS) from Instruction, a Salt Lake City-based educational technology company <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.instructure.com\/about\" class=\"c-regularLink\">2008<\/a>.<\/p>\n<p>Designed for remote learning, Canvas has been adopted by thousands of schools for course creation and management, grading, feedback, and coursework submission. Instructor says the LMS now supports millions of users \u2013 students and parents \u2013 and has recorded 27 million mobile app downloads. Canvas is available in over 100 countries. <\/p>\n<h2>What happened?<\/h2>\n<p>While Canvas claims <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.instructure.com\/canvas\" class=\"c-regularLink\">100%<\/a> uptime notice on its website, instructables CISO Steve Proud <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/status.instructure.com\/incidents\/9wm4knj2r64z\" class=\"c-regularLink\">Said<\/a> Last week the LMS &#8220;recently experienced a cybersecurity incident perpetrated by a criminal threat actor.&#8221;<\/p>\n<p>The company started investigation. On May 6, Proud said the company believed the incident had been &#8220;contained&#8221; but that some data may have been exposed \u2013 and it didn&#8217;t take long for students to begin reporting login problems.<\/p>\n<p><strong>Plus: The shady SIM farm behind those persistent scam messages \u2014 and how to stay safe<\/strong><\/p>\n<p>On Thursday, May 7, the Canvas login interface was defaced, with ransom notes allegedly posted by the ShinyHunters group as it moved from data theft to public extortion. Students who attempted to log in were unable to access their course materials, possibly a deliberate attempt by cyber attackers to pressure the instructor into paying with finals looming. <\/p>\n<p>In response, Canvas displayed a maintenance mode page, an action that was drawn <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.cloudskope.com\/insights\/post\/instructure-canvas-ransomware-attack-hits-universities-2026\" class=\"c-regularLink\">Criticism<\/a>. <\/p>\n<p>hackers&#8217; <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/vxunderground\/status\/2052504169521500378\/photo\/1\" class=\"c-regularLink\">ransom note<\/a>which has since circulated online, demanding that Instruct contact the group by May 12. <\/p>\n<p>&#8220;ShinyHunters has (again) violated the directive,&#8221; the note reads. &#8220;Instead of contacting us to resolve it, they ignored us and did some &#8216;security patch&#8217;.&#8221;<\/p>\n<p>While access has reportedly been restored <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/status.instructure.com\/incidents\/m88d7ymwpzpy\" class=\"c-regularLink\">most users<\/a>With the deadline approaching, this may not be the end of the story.<\/p>\n<h2>What is ShinyHunters?<\/h2>\n<p>ShinyHunters are a group of cyber criminals who extort money from companies. Since ShinyHunter came into limelight in 2020 over multiple violations of the company <em>working style <\/em>The goal is to quietly infiltrate a business, steal information, and then publicly pressure the victim to &#8220;compromise.&#8221;<\/p>\n<p><strong>Also: Best Free VPNs: Expert Tests and Reviews<\/strong><\/p>\n<p>often associated with large-scale violations, <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/valicyber.com\/resources\/shinyhunters\/\" class=\"c-regularLink\">shiny hunter<\/a>Like many other cybercriminal groups, operates a &#8220;leak site&#8221;. Leak sites are public-facing websites that list alleged victims and stolen items, and often include a demand for payment. <\/p>\n<p>If a victim fails to comply, the information stolen from them may be published. Removing the victim&#8217;s name from the leak site could also be part of the negotiations. <\/p>\n<h2>What information was stolen?<\/h2>\n<p>ShinyHunters almost threatens to leak data <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/millions-of-students-personal-data-stolen-in-major-education-cyberattack#link={%22role%22:%22standard%22,%22href%22:%22https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/millions-of-students-personal-data-stolen-in-major-education-cyberattack%22,%22target%22:%22_blank%22,%22absolute%22:%22%22,%22linkText%22:%22275 million%22}\" class=\"c-regularLink\">275 million<\/a> If its demands are not met then students of 8,800 educational institutions. <\/p>\n<p><strong>Also: I&#8217;m a tech professional, and an AI job scam almost fooled me \u2014 here&#8217;s how I got caught<\/strong><\/p>\n<p>According to the Instruction, the exposed data may include:<\/p>\n<ul>\n<li>Name<\/li>\n<li>email addresses<\/li>\n<li>student id number<\/li>\n<li>messaging between users<\/li>\n<\/ul>\n<p>&#8220;At this time, we have found no evidence that passwords, dates of birth, government identifiers or financial information were involved,&#8221; the instructor said. \u201cIf this changes, we will notify any affected institutions.\u201d<\/p>\n<h2>instructor&#8217;s response<\/h2>\n<p>It is not known whether Instruct has communicated with the ShinyHunters. The instructor said he is currently &#8220;not seeing any unauthorized activity.&#8221;<\/p>\n<p><strong>Too: <\/strong><strong>This critical Linux vulnerability is putting millions of systems at risk &#8211; how to protect yourself<\/strong><\/p>\n<p>The company has revoked privileged credentials and access tokens associated with the affected systems, deployed security patches \u2013 though no related vulnerabilities have been disclosed yet \u2013 and rotated security keys. Instructor said it has also increased monitoring across all its platforms. <\/p>\n<p>&#8220;As a precaution, we recommend customers follow security best practices, including enforcing MFA on privileged accounts, reviewing administrator access, and rotating API tokens or keys where applicable,&#8221; the company said. <\/p>\n<h2>6 steps to take immediately<\/h2>\n<ol>\n<li><strong>School Update: <\/strong>As this security incident appears to affect thousands of schools and educational institutions, contact your institution or visit its website and communication channels for updates. <\/li>\n<li><strong>passwords<\/strong>: Whenever you suspect that you are involved in a data breach, the first thing you should do is change the password you use to access your account. If you&#8217;re using the same password to access other online services, change those passwords as well. If the ransomware group releases the stolen data and manages to capture the credentials, those credentials could be made public. You should consider using a password manager to create complex passwords and receive leak alerts. <\/li>\n<li><strong>Have I been taken hostage?<\/strong>: It is too early to record this data breach and any subsequent data leaks <a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/haveibeenpwned.com\/\" class=\"c-regularLink\">Have I been taken hostage?<\/a>But we recommend visiting this website frequently to check if you have been involved in any online data breach. It&#8217;s free, and all you need to do is search for your email address. <\/li>\n<li><strong>Enable 2FA\/MFA<\/strong>: If you haven&#8217;t already done so, enable two-factor or multi-factor authentication on your affiliate accounts. <\/li>\n<li><strong>Keep an eye on your email<\/strong>: If Canvas follows proper procedures, it should notify users if their information has been exposed \u2013 keep an eye out for any updates. <\/li>\n<li><strong>Beware of phishing<\/strong>: However, if stolen email addresses or contact details are leaked online, they could be used in targeted phishing campaigns, so be careful if you receive correspondence that appears to be from your school or Canvas. If there are any signs of a phishing attempt \u2013 such as strange grammar, fake email addresses, or requests to click on unofficial links or open attachments \u2013 first verify it by phone or some other means. <\/li>\n<\/ol>\n<p><strong>Too: <\/strong><strong>These 5 important Windows Defender settings are turned off by default \u2013 turn them on ASAP<\/strong><\/p>\n<p><em>ZDNET has contacted Instructables and will update if we hear back. <\/em><\/p>\n<\/div>\n<p><script type=\"text\/javascript\">\n      (function() {\n        window.zdconsent = window.zdconsent || {run:(),cmd:(),useractioncomplete:(),analytics:(),functional:(),social:()};\n        window.zdconsent.cmd = window.zdconsent.cmd || ();\n        window.zdconsent.cmd.push(function() {\n          !function(f,b,e,v,n,t,s)\n          {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n          n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n          if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n          n.queue=();t=b.createElement(e);t.async=!0;\n          t.src=v;s=b.getElementsByTagName(e)(0);\n          s.parentNode.insertBefore(t,s)}(window, document,'script',\n          'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n          fbq('set', 'autoConfig', false, '789754228632403');\n          fbq('init', '789754228632403');\n        });\n      })();\n    <\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Outflow Design\/iStock\/Getty Images Plus via Getty Images Follow ZDNET: Add us as a favorite source On Google. ZDNET Highlights Canvas was disrupted by a cyberattack this week. Many students are unable to access popular educational portals. Instructor says data was stolen; What should Canvas users do next? Canvas is at the center of an ongoing<\/p>\n","protected":false},"author":1,"featured_media":126676,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[26203,520,3352,1051,140,4491,4338],"class_list":["post-126673","post","type-post","status-publish","format-standard","has-post-thumbnail","category-devotionals","tag-canvas","tag-country","tag-disrupted","tag-due","tag-schools","tag-steps","tag-violations"],"_links":{"self":[{"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/posts\/126673","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/comments?post=126673"}],"version-history":[{"count":1,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/posts\/126673\/revisions"}],"predecessor-version":[{"id":126677,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/posts\/126673\/revisions\/126677"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/media\/126676"}],"wp:attachment":[{"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/media?parent=126673"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/categories?post=126673"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/christiancorner.us\/index.php\/wp-json\/wp\/v2\/tags?post=126673"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}