Harvard, Princeton, Columbia And Georgetown Received A Ransom Note By ShinyHunters Where Their Classroom Portal Used To Be And The Deadline Is May 12
The timing could not have been worse. Millions of students were logging into Canvas to submit final assignments and prepare for exams when a message from a criminal hacking group greeted them instead.
According to CNN, WRAL, ABC7, Cybernews, TechCrunch and Harvard Crimson, on May 7, 2026, Canvas, the cloud-based learning platform used by more than 30 million active users across over 8,000 institutions globally was taken offline after the cybercriminal group ShinyHunters claimed responsibility for breaching its parent company Instructure, replacing school login pages with an extortion demand.
The breach could affect up to 275 million individuals across nearly 9,000 institutions, with the group claiming it obtained several billion private messages exchanged within the platform; conversations between students, faculty and administrators.
The attack began on April 30, when hackers exploited a vulnerability to gain access to Instructure’s systems, forcing the company to shut down Canvas Data 2 and Canvas Beta and disrupting third-party integrations relying on API keys.
Instructure stated that the exposed data appeared to include names, email addresses, student ID numbers and messages among users, but found no evidence that passwords, dates of birth, government identifiers or financial information was involved.
ShinyHunters gave affected schools until May 12 to negotiate a settlement, warning that all stolen data would be publicly released if no agreement was reached. The group described Instructure’s earlier security patches as an attempt to ignore their demands.
The University of Illinois postponed all final exams and assignments. Schools across California, Florida, Georgia, North Carolina, Washington and Wisconsin reported disruptions.
For millions of students, finals week just got a lot more complicated. Like this Cybersecurity oriented article? Read our previous article here.

