Several Canadian varsities suffer Canvas cyberattack, students’ information leaked

Several tertiary institutions in Canada, including the University of Toronto, the University of British Columbia and the University of Alberta, are experiencing cyber glitches, following a targeted attack at Canvas and Quercus, two digital learning platforms managed by Instructure.
A Canada-based newspaper, Global News, reported that the University of Toronto on Friday shutdown Quercus, one of the affected digital platforms as a precautionary measure to prevent further attacks.
“Instructure, the third-party provider that provides Quercus, is currently experiencing an ongoing cybersecurity incident. There is currently no evidence to suggest that other University of Toronto systems or assets have been compromised,” the university said.
Similarly, the University of Alberta on Friday warned its students from attempting to log into Canvas, following reports that some users saw unauthorised messages on the site.
Also, the University of British Columbia on Thursday urged students not to log into Canvas and instructed those already signed in to log out immediately and change their passwords.
The school in an Instagram post stated that Canvas, an online classroom platform, was “unavailable due to a cyber breach.”
The Global News also reported that other educational institutions such as Simon Fraser University and OCAD University experienced similar disruptions in their use of the learning platforms.
According to a statement published on its official website, Instructure said it discovered that an unauthorised actor made changes to some pages on the platforms.
The company said the hacker tampered with the Free-For-Teacher accounts, which had since been temporarily shut down until safety could be guaranteed.
“On April 29, 2026, we detected unauthorised activity in Canvas. We immediately revoked the unauthorised party’s access, started an investigation, and engaged outside forensic experts,” the company stated.
“On May 7, 2026, we identified additional unauthorised activity tied to the same incident. The unauthorised actor made changes to the pages that appeared when some students and teachers were logged in through Canvas.
“Out of caution, we temporarily took Canvas offline into maintenance mode to contain the activity, investigate, and apply additional safeguards,” it said.
The company disclosed that personal information including names, email addresses, student ID numbers and messages were breached during the cyber attack.
Instructure stated, “Based on the investigation so far, the data taken in the April 29 incident includes certain personal information of users at affected organizations. That includes names, email addresses, student ID numbers, and messages among Canvas users.”
The company added that it found no evidence that passwords, dates of birth, government identifiers or financial information were involved.”
It noted that it had informed law enforcement agencies, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and other international agencies about the incident.
An education news platform, Inside Higher Ed, reported that a hacking group, ShinyHunters, claimed responsibility for the cyber breach in messages sent to Canvas users.
The group threatened to release personal data obtained from the platform unless a deal was reached.
“ShinyHunters have breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some “security patches,” the group stated.
“If any of the schools affected in the list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.”
“You have till the end of the day by 12 May 2026 before everything is leaked. Instructure still has until EOD 12 May 2026 to contact us,” it said.
We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.
More from Peoples Gazette

Agriculture
FG tasks ECOWAS on leveraging financing strategies for agroecology
The federal government has urged stakeholders in the agriculture and finance sectors in the West Africa region to leverage financing strategies to enhance agroecology practices

Politics
Katsina youths pledge to deliver over 2 million votes to Atiku
“Katsina State is Atiku’s political base because it is his second home.”

Heading 4
Venezuela Earthquake: Death toll rises to 1,430
About 3,238 injuries were also reported following Wednesday’s 7.2 and 7.5 magnitude earthquakes.

States
Soludo’s wife urges stronger support for MSMEs to drive economic growth
She stated that thriving small businesses were essential to prosperous and inclusive communities.

Economy
Nigeria must focus on cassava processing, not just production, expert says
He said that while Nigeria remains the world’s largest cassava producer, with an annual output of 60 million metric tonnes, this has yet to translate into economic prosperity.

States
Oyo lifts curfew imposed on 10 LGs, assures residents of safety
The Commissioner for Information and Civic Orientation, Dotun Oyelade, said residents can now resume their normal activities.

World
Texas mandates bible stories in public schools
The policy introduces a diverse array of selected Bible texts into classrooms starting in 2030, beginning with elementary schools in the state.

States
Gowon calls for peace, unity as Benue marks 50th anniversary
Mr Gowon urged leaders across ethnic and political divides to foster inclusiveness, fairness and mutual respect.






