Skip to main content

Cyberattack hits Canvas system used by thousands of schools as finals loom

A system that thousands of schools and universities use was offline Thursday during a cyberattack, creating chaos as students tried to study for finals and underscoring education’s dependence on technology.

The hacking group named ShinyHunters claimed responsibility for the breach at Canvas, said Luke Connolly, a threat analyst at the cybersecurity firm Emisoft. Instructure, the company behind Canvas, didn’t immediately respond to a request for comment or questions about whether the system was taken down as a precaution or because the hackers knocked it offline.

Canvas is used to manage grades, course notes, assignments, lecture videos and more. The hacking group posted online that nearly 9,000 schools worldwide were affected, with billions of private messages and other records accessed, Connolly said.

Students quickly took to social media to ask if others were unable to access Canvas, with many panicking that they could no longer view course materials housed within the platform to study for their final exams.

Screen shots Connolly provided showed that the group began threatening Sunday to leak the trove of data, giving deadlines of Thursday and May 12. Connolly said the later date indicates that discussions regarding extortion payments may be ongoing.

Rich in digitized data, the nation’s schools are prime targets for far-flung criminal hackers, who are assiduously locating and scooping up sensitive files that not long ago were committed to paper in locked cabinets. Past attacks have hit Minneapolis Public Schools and the Los Angeles Unified School District.

Instructure has not posted about the attack on its social media.

Connolly said the Canvas attack is strikingly similar to a breach at PowerSchool, which also offers learning management tools. In that case a Massachusetts college student was charged.

Connolly described ShinyHunters as a loose affiliation of teenagers and young adults based in the U.S. and the United Kingdom. The group also has been tied to a other attacks, including one aimed at Live Nation’s Ticketmaster subsidiary.

Universities and school districts quickly began notifying students and parents.

“This is being reported as a national-level cyber-security incident,” the director of information technology at the University of Iowa’s College of Public Health wrote in announcing that the school’s online system was down. “Hopefully we will have a resolution soon.”

Virginia Tech acknowledged in a notice to students that the administration was aware of the effect on final exams and other end-of-semester activities. The University of New Mexico sent a similar message to the campus community, and the University of Florida urged students to stay alert for any phishing messages that appear to be from Canvas.

Teachers say they are having to find workarounds to help students study for exams and submit final assignments.

Damon Linker, a senior lecturer in the political science department at the University of Pennsylvania, said in a post on the social media platform X that his students had been relying on Canvas to access every reading from the semester and all of his lecture slides before their Monday final exams. The outage leaves students and faculty “dead in the water here in academia right now,” he said.

The student newspaper at Harvard reported that the system there was down as well. Students at Johns Hopkins University simply got an error message when trying to view their final grades on the platform Thursday. And public school districts also sought to reassure parents, with officials in Spokane, Washington, writing that they aren’t “aware of any sensitive data contained in this breach.”

Some schools, such as the University of Texas at San Antonio, announced they were pushing back finals scheduled for Friday in response to the outage.

___

This story has been corrected to attribute a quote to the director of information technology at the University of Iowa’s College of Public Health, not the university’s broader information technology lead.

___

Associated Press journalist Hannah Schoenbaum in Salt Lake City contributed.

Ohio State trustees OK $100M settlement with hundreds of former students abused by doctor

COLUMBUS, Ohio (AP) — Ohio State University agreed Wednesday to pay approximately $100 million to settle legal claims from hundreds of former student athletes who said they were sexually abused decades ago by a doctor at the university. The school has fought lawsuits in federal court since 2018 brought by former student athletes against the university over its failure to stop abuse by Dr. Richard Strauss. Strauss worked at the school from 1978 to 1998 and also ran an off-campus clinic. He died in 2005. During a meeting Wednesday, the school's Board of Trustees approved a preliminary agreement with all but one of the 280 survivors with claims still involved in pending litigation. Once finalized, the settlement could mark the end of a lengthy legal battle and close a painful chapter in the school's history. “The survivors of the Strauss abuse are all Buckeyes, will always be a part of our family and our community, and I firmly believe that,” the school's president, Ravi Bellamkonda, said during the meeting. “We continue to be very grateful to them for their courage in coming forward, and reaching a final resolution is very important to us and is an important step forward.”
Read Next Story