Vista elenco

Canvas Breach Disrupts Schools & Colleges Nationwide

8 Maggio 2026 ore 04:58

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions.

A screenshot shared by a reader showing the extortion message that was shown on the Canvas login page today.

Canvas parent firm Instructure responded to today’s defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students.

Instructure acknowledged a data breach earlier this week, after the cybercrime group ShinyHunters claimed responsibility and said they would leak data on tens of millions of students and faculty unless paid a ransom. The stated deadline for payment was initially set at May 6, but it was later pushed back to May 12.

In a statement on May 6, Instructure said the investigation so far shows the stolen information includes “certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as as messages among users.” The company said it found no evidence the breached data included more sensitive information, such as passwords, dates of birth, government identifiers or financial information.

The May 6 update stated that Canvas was fully operational, and that Instructure was not seeing any ongoing unauthorized activity on their platform. “At this stage, we believe the incident has been contained,” Instructure wrote.

However, by mid-day on Thursday, May 7, students and faculty at dozens of schools and universities were flooding social media sites with comments saying that a ransom demand from ShinyHunters had replaced the usual Canvas login page. Instructure responded by pulling Canvas offline and replacing the portal with the message, “Canvas is currently undergoing scheduled maintenance. Check back soon.”

“We anticipate being up soon, and will provide updates as soon as possible,” reads the current message on Instructure’s status page.

While the data stolen by ShinyHunters may or may not contain particularly sensitive information (ShinyHunters claims it includes several billion private messages among students and teachers, as well as names, phone numbers and email addresses), this attack could hardly have come at a worse time for Instructure: Many of the affected schools and universities are in the middle of final exams, and a prolonged outage could be highly damaging for the company.

The extortion message that greeted countless Canvas users today advised the affected schools to negotiate their own ransom payments to prevent the publication of their data — regardless of whether Instructure decides to pay.

“ShinyHunters has breached Instructure (again),” the extortion message read. “Instead of contacting us to resolve it they ignored us and did some ‘security patches.'”

A source close to the investigation who was not authorized to speak to the press told KrebsOnSecurity that a number of universities have already approached the cybercrime group about paying. The same source also pointed out that the ShinyHunters data leak blog no longer lists Instructure among its current extortion victims, and that the samples of data stolen from Canvas customers were removed as well. Data extortion groups like ShinyHunters will typically only remove victims from their leak sites after receiving an extortion payment or after a victim agrees to negotiate.

Dipan Mann, founder and CEO of the security firm Cloudskope, slammed Instructure for referring to today’s outage as a “scheduled maintenance” event on its status page. Mann said Shiny Hunters first demonstrated they’d breached Instructure on May 1, prompting Instructure’s Chief Information Security Officer Steve Proud to declare the following day that the incident had been contained. But Mann said today’s attack is at least the third time in the past eight months that Instructure has been breached by ShinyHunters.

In a blog post today, Mann noted that in September 2025, ShinyHunters released thousands of internal University of Pennsylvania files — donor records, internal memos, and other confidential materials — through what the Daily Pennsylvanian and other outlets later determined was, in part, a Canvas/Instructure-mediated access path.

“Penn was the named victim,” Mann wrote. “Instructure was the mechanism. The incident was treated as a Penn-specific story by most of the national press and quietly handled by Instructure as a customer-specific matter. That framing was wrong then. It is dramatically more wrong in light of the May 2026 events, which now look like the planned escalation of an attack pattern that ShinyHunters had been working against Instructure’s environment for at least eight months prior. The September 2025 Penn breach was the proof of concept. The May 1, 2026 incident was the production run. The May 7, 2026 recompromise was ShinyHunters demonstrating publicly that the May 2 ‘containment’ did not happen.”

In February, a ShinyHunters spokesperson told The Daily Pennsylvanian that Penn failed to pay a $1 million ransom demand. On March 5, ShinyHunters published 461 megabytes worth of data stolen from Penn, including thousands of files such as donor records and internal memos.

ShinyHunters is a prolific and fluid cybercriminal group that specializes in data theft and extortion. They typically gain access to companies through voice phishing and social engineering attacks that often involve impersonating IT personnel or other trusted members of a targeted organization.

Last month, ShinyHunters relieved the home security giant ADT of personal information on 5.5 million customers. The extortion group told BleepingComputer they breached the company by compromising an employee’s Okta single sign-on account in a voice phishing attack that enabled access to ADT’s Salesforce instance. BleepingComputer says ShinyHunters recently has taken credit for a number of extortion attacks against high-profile organizations, including Medtronic, Rockstar Games, McGraw Hill, 7-Eleven and the cruise line operator Carnival.

The attack on Canvas customers is just one of several major cybercrime campaigns being launched by ShinyHunters at the moment, said Charles Carmakal, chief technology officer at the Google-owned Mandiant Consulting. Carmakal declined to comment specifically on the Canvas breach, but said “there are multiple concurrent and discrete ShinyHunters intrusion and extortion campaigns happening right now.”

Cloudskope’s Mann said what happens next depends largely on whether Instructure’s customers — the universities, K-12 districts, and education ministries paying for Canvas — choose to apply pressure or absorb the breach quietly.

“The history of education-vendor incidents suggests the path of least resistance is the second one,” he concluded.

Update, May 8, 11:05 a.m. ET: Instructure has published an incident update page that includes more information about the breach. Instructure said its Canvas portal is functioning normally again, and that the hackers exploited an issue related to Free-for-Teacher accounts.

“This is the same issue that led to the unauthorized access the prior week,” Instructure wrote. “As a result, we have made the difficult decision to temporarily shut down Free-for-Teacher accounts. These accounts have been a core part of our platform, and we’re committed to resolving the issues with these accounts.”

Instructure said affected organizations were notified on May 6.

“If your organization is affected, Instructure will contact your organization’s primary contacts directly,” the update states. “Please don’t rely on third-party lists or social media posts naming potentially affected organizations as those lists aren’t verified. Instructure will confirm validated information through direct outreach to all affected organizations.”

Update, May 11, 10:16 p.m. ET: Instructure posted an update saying they paid their extortionists in exchange for a promise to destroy the stolen data. “The data was returned to us,” the update reads. “We received digital confirmation of data destruction (shred logs). We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.”

Meet the Fleet: NASA Armstrong Continues Legacy of Flight Research

8 Maggio 2026 ore 01:45

3 min read

Preparations for Next Moonwalk Simulations Underway (and Underwater)

NASA’s X-59 flies above the Mojave Desert with a NASA F/A-18 chase aircraft nearby.
NASA’s X-59 quiet supersonic research aircraft flies above Palmdale and Edwards, California, during its first flight Tuesday, Oct. 28, 2025, accompanied by a NASA F/A-18 research aircraft serving as chase.
NASA/Jim Ross

NASA’s home for experimental flight is welcoming more flyers to its already high-performing fleet as it continues to support science and aeronautics test missions – continuing the legacy of pioneers like Neil Armstrong.

NASA’s Armstrong Flight Research Center in Edwards, California, added multiple aircraft this year: two F-15s supersonic jets, a Pilatus PC-12 utility plane, and a T-34 turboprop trainer, which the center will use to support the agency’s advancement of aerospace research.

Throughout the center’s history, pilots have flown everything from large aircraft like the 747 Shuttle Carrier Aircraft and rocket-powered airplanes like the X-15 to high-speed repurposed fighter jets like the F-18. And after almost 80 years, flight research is still going strong in the desert today.

“Armstrong has a rich history of flight research, but it’s the multidimensional skills of the people we have here, and the knowledge they’ve built to handle very unique aircraft maintenance and modifications, that stands out,” said Darren Cole, capabilities manager for the Flight Demonstrations and Capabilities project at NASA Armstrong.

Armstrong has a rich history of flight research, but it’s the multidimensional skills of the people we have here … that stands out.

Darren Cole

Darren Cole

Capabilities Manager at NASA Armstrong

The center plays a pivotal role in worldwide airborne science missions, flying scientists and equipment from NASA, other government agencies, industry, and academia to collect measurements such as air pollution levels, glacier melt trends, and wildland fire mapping.

Scientists can manage experiments in real time aboard flying laboratories like the NASA ER-2, to collect important data with the help of Armstrong’s pilots and airborne science team.

“We all come together to make the science happen,” said Matt Berry, airborne research platforms branch chief at NASA Armstrong. “It is the agility of the Armstrong team that allows us to collaborate with scientists, get their equipment onboard, and to fly them to areas where they need to collect data.”

The center sits on Rogers Dry Lake, a 44-square-mile slat flat area used for aviation research and test operations. Rogers and the adjacent Rosamond Dry Lake have seen everything from space shuttle landings to emergency test flight recoveries. The Rogers lakebed continues to serve as an important piece of Armstrong’s test missions.

For NASA Armstrong, it all started with the first attempt by a human to fly faster than the speed of sound in the Bell X-1. In 1946, 13 employees from NASA’s predecessor agency, the National Advisory Committee for Aeronautics (NACA), arrived at what was then known as Muroc Army Airfield to prepare for the X-1 tests. A year later, NACA’s Muroc Flight Test Unit was established as a permanent facility at the airfield.

The center has gone by several names over the years, most recently changing from NASA’s Dryden Flight Research Center to NASA Armstrong in 2014. But its legacy has never shifted: The Bell X-1E, the last of the X-1 series of aircraft, now sits in front of NASA Armstrong, welcoming the newest test pilots, engineers, scientists, explorers, and dreamers. And they’re using the aircraft of today to break new barriers.

“I don’t think there is another place in the world with a more diverse fleet of aircraft. We have everything from a low-altitude powered glider to ER-2s, which are flying at high altitudes, and a multitude of aircraft in between,” Cole said.

From sourcing rare components to machining custom parts in-house, NASA Armstrong’s teams transform these aircraft into research workhorses. The center continues its crucial role in leading aeronautics testing, Earth science research, and supporting government and industry partners.

❌