Canvas breach spotlights cybercriminal appetite for student data

https://cdn.nextgov.com/media/img/cd/2026/05/11/20260511_Canvas_Oscar_Wong-1/open-graph.jpg

Oscar Wong via Getty Images

ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

May 11, 2026 12:00 PM ET

Cyberattacks on widely used third-party services like Canvas can expose sensitive data that hackers can later weaponize. Higher education institutions are often a prime target.

A major cybercrime gang’s hack of Canvas is highlighting how education technology providers have become attractive targets for cybercriminals, whose access to student records, login credentials and other sensitive data can create opportunities for fraud, identity theft, extortion and future intrusions.

ShinyHunters on Thursday claimed responsibility for a hack into Instructure’s Canvas platform that facilitates course materials and class management for thousands of institutions. An extensive document posted by the hackers and obtained by Route Fiftylists some 9,000 customers apparently impacted in the breach, including Georgetown, Harvard and Cornell universities. It’s not clear whether all victims listed were accessed, or what data may have been...

Copyright of this story solely belongs to nextgov.com. To see the full text click HERE

Read more

https://cdn.arstechnica.net/wp-content/uploads/2026/06/GettyImages-1987915833-1152x648.jpg

Streaming services must comply with a California law that bans playing ads louder than the content being watched from July 1, but its implementation is unclear

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.