Monday, June 15, 2026

Several Canadian varsities suffer Canvas cyberattack, students’ information leaked

A hacking group, ShinyHunters, claimed responsibility for the cyber breach in messages sent to Canvas users.

• May 9, 2026
Canadian flag (credit: Konga)
Canadian flag (credit: Konga)

Several tertiary institutions in Canada, including the University of Toronto, the University of British Columbia and the University of Alberta, are experiencing cyber glitches, following a targeted attack at Canvas and Quercus, two digital learning platforms managed by Instructure.

A Canada-based newspaper, Global News, reported that the University of Toronto on Friday shutdown Quercus, one of the affected digital platforms as a precautionary measure to prevent further attacks.

“Instructure, the third-party provider that provides Quercus, is currently experiencing an ongoing cybersecurity incident. There is currently no evidence to suggest that other University of Toronto systems or assets have been compromised,” the university said.

Similarly, the University of Alberta on Friday warned its students from attempting to log into Canvas, following reports that some users saw unauthorised messages on the site.

Also, the University of British Columbia on Thursday urged students not to log into Canvas and instructed those already signed in to log out immediately and change their passwords.

The school in an Instagram post stated that Canvas, an online classroom platform, was “unavailable due to a cyber breach.”

The Global News also reported that other educational institutions such as Simon Fraser University and OCAD University experienced similar disruptions in their use of the learning platforms.

According to a statement published on its official website, Instructure said it discovered that an unauthorised actor made changes to some pages on the platforms.

The company said the hacker tampered with the Free-For-Teacher accounts, which had since been temporarily shut down until safety could be guaranteed.

“On April 29, 2026, we detected unauthorised activity in Canvas. We immediately revoked the unauthorised party’s access, started an investigation, and engaged outside forensic experts,” the company stated.

“On May 7, 2026, we identified additional unauthorised activity tied to the same incident. The unauthorised actor made changes to the pages that appeared when some students and teachers were logged in through Canvas.

“Out of caution, we temporarily took Canvas offline into maintenance mode to contain the activity, investigate, and apply additional safeguards,” it said.

The company disclosed that personal information including names, email addresses, student ID numbers and messages were breached during the cyber attack. 

Instructure stated, “Based on the investigation so far, the data taken in the April 29 incident includes certain personal information of users at affected organizations. That includes names, email addresses, student ID numbers, and messages among Canvas users.”

The company added that it found no evidence that passwords, dates of birth, government identifiers or financial information were involved.”

It noted that it had informed law enforcement agencies, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and other international agencies about the incident.

An education news platform, Inside Higher Ed, reported that a hacking group, ShinyHunters, claimed responsibility for the cyber breach in messages sent to Canvas users.

The group threatened to release personal data obtained from the platform unless a deal was reached.

“ShinyHunters have breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some “security patches,” the group stated.

“If any of the schools affected in the list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.”

“You have till the end of the day by 12 May 2026 before everything is leaked. Instructure still has until EOD 12 May 2026 to contact us,” it said.

We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.

More from Peoples Gazette

farmers

Agriculture

FG tasks ECOWAS on leveraging financing strategies for agroecology

The federal government has urged stakeholders in the agriculture and finance sectors in the West Africa region to leverage financing strategies to enhance agroecology practices

Katsina State

Politics

Katsina youths pledge to deliver over 2 million votes to Atiku

“Katsina State is Atiku’s political base because it is his second home.”

Nigerian Army logo

NationWide

Warrant officers, SNCOs backbones of any professional army: Commander

According to him, warrant officers and SNCOs provide the leadership and technical expertise required for successful military operations.

Police

Abuja

FCT police nab four suspects for alleged kidnapping, banditry 

She said preliminary investigations showed the suspects were part of a criminal network involved in kidnapping and banditry within the FCT and neighbouring states.

World

FBI captures one of America’s most wanted fraudsters Said Abdullahi Ereg

Ereg, a 48-year-old Somalian, was declared wanted for wire fraud and money laundering.

FBI information flyer

World

FBI offers $10,000 for information on killer of 12-years old girl

According to the FBI, at approximately 1:20 a.m., on June 13, 2025, Ms Darby was shot in the head and killed while sleeping in her home in Milwaukee, Wisconsin.

Ademola Aderinto (Oyo commissioner for environment)

States

Oyo holds three-day review on climate action policy

Mr Aderinto said the growing impact of climate change demanded urgent, coordinated action from all stakeholders.

Security checkpoint

Lagos

Lagos police impound 50 vehicles in crackdown on covered, unmarked number plates

The commissioner said the operation forms part of renewed efforts to strengthen security and improve vehicle identification across the state.