ShinyHunters Ransom Messages Disrupt Canvas, Affecting 275 Million Students in U.S. and Canada
Image: tv5monde

ShinyHunters Ransom Messages Disrupt Canvas, Affecting 275 Million Students in U.S. and Canada

04 June, 2026.Technology and Science.7 sources

The story in 15 seconds

  • ShinyHunters attributed as the Canvas breach's attacker.
  • Canvas outage disrupted access for thousands of schools globally.
  • Universities across North America affected, including Canadian and US institutions.

The divide · 1 of 3

Cause and evidentiary status of the Bezos phone hack

Shifts reader trust by emphasizing UN evidence vs contesting its concreteness.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
7 sources
Western Mainstream
5
Other
2

Western Mainstream

Ars Technica
Ars Technica

My SSN was exposed in a breach at Columbia—a school I have no connection with

04 June, 2026

Read the original →
BFM
BFM

9,000 institutions affected and 275 million student records compromised in the United States and Canada, in “the largest cyberattack in the sector.”

03 June, 2026

Read the original →
La Libre.be
La Libre.be

Unease within the U.S. Immigration and Customs Enforcement (ICE): an internal leak reveals the identities of thousands of agents

04 June, 2026

Read the original →
La Razón
La Razón

The myth of the 'expert user': knowing a lot about technology makes you a more worried person.

04 June, 2026

Read the original →
tv5monde
tv5monde

Cyber espionage: Jeff Bezos's mobile phone allegedly hacked by Saudi Arabia.

04 June, 2026

Read the original →

Other

Cubadebate
Cubadebate

Cyberattack compromises data of students and teachers on the Canvas learning platform.

03 June, 2026

Read the original →
ELHERALDO.CO
ELHERALDO.CO

What happened to Canvas? The hack affected Harvard, MIT, Columbia, and other universities.

04 June, 2026

Read the original →

Full story

Canvas outage and ransom

A massive cyberattack against Canvas left thousands of students in the United States without access to assignments, grades, and academic materials during final exam season, after students tried to log in and found ransom messages posted by the attackers.

A weird text from my dad in February sent me on a months-long quest to solve a mystery that has been troubling an odd group of victims from a Columbia University data breach last year

Ars TechnicaArs Technica

The outage began to be reported on Thursday, and the platform is owned by Instructure, which said it had more than 30 million active users worldwide.

Image from Ars Technica
Ars TechnicaArs Technica

Instructure said the hacker group ShinyHunters had already carried out another attack on May 1, compromising data such as usernames, email addresses, and student identification numbers.

In the United States and Canada, BFM reported that nearly 9,000 institutions and 275 million people would have been affected, with the hacker group ‘ShinyHunters’ claiming responsibility and demanding payment.

Radio-Canada also reported that the culprit was a flaw affecting the Canvas platform, which is widely used to deliver courses, share resources, and manage assessments.

Who was hit and what data

In universities, colleges, and some K-12 schools, teachers use Canvas to share notes and assignments, and Instructure said the data involved may include full names, email addresses, student numbers, and personal messages.

Instructure detected unauthorized activity on April 29 through a particular type of teacher account, revoked that access, and took the platform offline to investigate on Thursday when additional activity was detected.

Image from BFM
BFMBFM

Instructure also said it has found no evidence that passwords, financial information, or government-issued identification data have been compromised.

Luke Connolly, a threat intelligence analyst in Ottawa with cybersecurity firm Emsisoft, said the breach was concerning because there are all kinds of ways the information can be misused.

Robert Falzon, head of engineering at Check Point Software for Canada, said the information could be combined with data leaked elsewhere to create profiles for false identities used in financial crimes.

Broader distrust and calls for action

Beyond Canvas, La Libre.be described an internal leak tied to ICE that provided to an independent organization the identities of about 4,500 ICE agents and former ICE and border police officers, which it said would be the largest data leak ever recorded within that department.

Cyberattack compromising data of students and teachers on the Canvas learning platform

CubadebateCubadebate

Dominick Skinner, founder of the ICE List site, said the leak was "the sign of generalized discontent within the American government," and the article linked that distrust to the death of Renee Nicole Good in Minneapolis.

In the same reporting, the United Nations called for the opening of a "swift and independent" investigation into Renee Nicole Good's death, while protests erupted in several major cities targeting ICE and also the FBI.

In the Canvas incident, David Shipley, CEO of Beauceron Security in Fredericton, estimated it could be the "largest cyberattack ever carried out in the education sector," describing an "incredibly destructive" attack.

Falzon said it is "not enough to run cybersecurity audits from time to time," arguing that breaches occur daily now and that schools and external providers must shorten those cycles and involve the community.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science