Top
Best
New

Posted by stefanpie 14 hours ago

Canvas is down as ShinyHunters threatens to leak schools’ data(www.theverge.com)
https://thetech.com/2026/05/07/canvas-breach-26

https://techcrunch.com/2026/05/07/hackers-deface-school-logi...

721 points | 435 commentspage 3
tptacek 11 hours ago|
The boy is a biochem PhD student at UIUC and reports that all their finals are now cancelled. "Is this good news?" I ask. "Yes. Everything coming up Milhouse."
robertritz 11 hours ago||
I'm shocked universities don't host their own LMS? At least large universities have the IT departments to do this. They host compute clusters, so they can certainly host an LMS.
oezi 10 hours ago|
The same reason hospitals don't have their own Patient Information System but all use Epic. The amount of customization you need and continuous churn due to changing curricula and regulatory requirements makes it hard to keep up without scale.
tech234a 11 hours ago||
A post on the official Canvas forum: https://community.instructure.com/en/discussion/666027/ranso...
bumblehean 10 hours ago||
Hugs going out to the teams at Instructure working to fix this. I've been through a similar Ransomware attack (national news stories, lots of customers dead in the water, etc.), and it's about as bad a situation you can wind up in.
orourke 11 hours ago||
My son was in the middle of an exam and then his screen went black and it showed the message from ShinyHunters. Hasn’t been able to get back in since.
OsrsNeedsf2P 12 hours ago||
Somehow I have less distaste for ShinyHunters than I do for the companies who don't secure user data
rixed 8 hours ago|
When you picture the attacker, don't picture a bored nerdy teanager. Picture a selfish, $$ motivated psychopath.

Let's not side with the parasites.

chrisjj 3 hours ago||
And lets not side with Canvas PR.
altcognito 27 minutes ago||
He didn't really side with Canvas PR, he just said these were not good people. They aren't.

What did Canvas PR do except do a poor job? Doing a poor job of PR is a whole, whole lot less worse than actively destroying people's lives for profit.

corvad 11 hours ago||
Just learned the defacement page was hosted from instructure's own aws bucket so seems pretty bad.
copperx 14 hours ago||
https://archive.is/5v693
xp84 9 hours ago|
What are we even coming to when even internet blogs are paywalled. Verge? Next thing Gizmodo is gonna be paywalled.
alexalx666 3 hours ago||
Respect to Canvas sales team, its like microsoft level platform lock-in into low sec infra
stevenjgarner 1 hour ago|
No paywall : https://archive.ph/fLR71
More comments...