27 ms·
Canvas online again as ShinyHunters threatens to leak schools’ data
https://thetech.com/2026/05/07/canvas-breach-26 https://thetech.com/2026/05/07/canvas-breach-26
https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/ https://techcrunch.com/2026/05/07/hackers-deface-school-logi...
- krupan 5mo agoA college student I know just sent me a screenshot, he can't access canvas for his school at all
- yesiamyourdad 5mo agoSame, my daughter just sent a screenshot, she was trying to study for finals.
- exprez135 5mo agoThe Canvas instance at the nearby university is now down (May 7, 4 PM Eastern), but was briefly displaying the message in this screenshot (1). The ransom message implies that today's problem is the second wave in an attack on Instructure after ignoring their first breach in recent days. 1: https://ibb.co/r29RjdnH https://ibb.co/r29RjdnH
- HDBaseT 5mo agoYeah, this is ongoing. We received communication that Canvas is down for "Under Maintenance" although it seems ShineyHunters have compromised Canvas again with that message you posted. We do not see that message anymore, although all instrucuture.com URLs are down. The list of schools in the ShinyHunters publication can be found here: https://web.archive.org/web/20260507042014/http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt https://web.archive.org/web/20260507042014/http://91.215.85....
- nebula8804 5mo agoSeems like Canvas instances of schools not listed are also down (at least my alma mater is)
- HDBaseT 5mo ago[dead]
- goldenskye 5mo agoYes, I work for an Australian online school. We’re down “for scheduled maintenance” (I question how “scheduled” it was given this is within school hours on a school day), but we’re not on the list published by ShinyHunters.
- GaryBluto 5mo agohttps://web.archive.org/web/20260507042014fw_/http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt https://web.archive.org/web/20260507042014fw_/http://91.215.... Original now shows 404.
- bigfatkitten 5mo agoI use Canvas for some postgraduate studies, and my teenage daughter uses it at her high school. We already bond over how awful the Canvas UX is (and she has a bunch of Chrome extensions to improve it.) Now we’ve got something else to gripe over together.
- copperx 5mo agoI vibecoded a pretty extensive CLI for Canvas and using it is very pleasant. Joyful, even, when combined with an LLM. Especially when compared to the developer hostile Blackboard Ultra.
- auxiliarymoose 5mo agoIt is open source, so you could send pull requests with improvements: https://github.com/instructure/canvas-lms https://github.com/instructure/canvas-lms
- scratchyone 5mo agohttps://github.com/instructure/canvas-lms/pulls?q=is%3Apr+is%3Amerged+ https://github.com/instructure/canvas-lms/pulls?q=is%3Apr+is... haha i went to go check and they haven't merged a PR since 2017
- gareim 5mo agoLook by is:closed instead. They don't merge the PR directly.
- j027 5mo agoCanvas seems like it’s not that great. But if you then use Blackboard Ultra it makes canvas look amazing.
- plasma_beam 5mo agoOur public school system here in Maryland got hit, ransom screen.
- daledavies 5mo agoEek I bet there are a few people at Instructure who won't be getting much sleep tonight!
- kristianp 5mo agoQld, Australia was also affected: https://www.itnews.com.au/news/qld-gov-says-students-staff-caught-in-canvas-cyber-incident-625664 https://www.itnews.com.au/news/qld-gov-says-students-staff-c...
- protocolture 5mo agoQLD Government vendor selection is always terrible.
- skeaker 5mo agoPretty cruel to do this right around finals.
- crazygringo 5mo agoEven more incentive to pay up. I wonder if the timing was intentional or just coincidental.
- enceladus06 5mo agoThat is the point. Get an extra million or two $ in btc from Instructure.
- kelnos 5mo agoThat's exactly the point, I'm sure.
- incomplete 5mo agoyep, i work for a major university and our canvas instance is down. this is really, really bad. edit: here's the list of impacted universities (unsure if they all have their canvas instances offline, but i'd be surprised if not): http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt http://91.215.85.103/pay_or_leak/instructure_affected_school...
- mrsvanwinkle 5mo ago[dead]
- 12_throw_away 5mo agotbh this has me wondering if canvas "instances" are actually as isolated and segregated from each other as they're supposed to be.
- wky 5mo agoIt's possible that Instructure's servers got compromised: dig canvas.ucdavis.edu [...] ;; ANSWER SECTION: canvas.ucdavis.edu. 1974 IN CNAME ucdavis-vanity.instructure.com. ucdavis-vanity.instructure.com. 60 IN A 18.173.121.125 ucdavis-vanity.instructure.com. 60 IN A 18.173.121.103 ucdavis-vanity.instructure.com. 60 IN A 18.173.121.15 ucdavis-vanity.instructure.com. 60 IN A 18.173.121.18 dig canvas.duke.edu ;; ANSWER SECTION: canvas.duke.edu. 300 IN CNAME duke-vanity.instructure.com. duke-vanity.instructure.com. 60 IN A 18.173.121.125 duke-vanity.instructure.com. 60 IN A 18.173.121.18 duke-vanity.instructure.com. 60 IN A 18.173.121.103 duke-vanity.instructure.com. 60 IN A 18.173.121.15
- mrsvanwinkle 5mo agothat's what the screenshot says. They rooted Instructure servers.
- javawizard 5mo agoDefine "as they're supposed to be". Back when I worked for Instructure ~10 years ago, Canvas was effectively a single, giant, monolithic multitenant app with one instance backed by several thousand app servers and ~100 separate Postgres database clusters that any app server could talk to. Schools were grouped onto pools of app severs and Postgres database clusters more or less according to locality and cluster availability. I want to say a handful of the largest schools got their own clusters, but I'm not certain, and at any rate their clusters could certainly all talk to each other. It was actually kind of neat from a technical perspective: any Rails model across the entire Canvas world could have a "foreign key" pointing to any other Rails model anywhere else. Among other things, this allowed for users who could administer multiple Canvas organizations, even if those organizations resided on different Postgres clusters. https://github.com/instructure/switchman https://github.com/instructure/switchman is their gem that made that all work. (I put "foreign key" in quotes because the whole thing was implemented in software, not with actual database FKs, for obvious reasons.) --- Of course, the massive downside to that sort of thing is that if you manage to pop one Canvas app server, you have the keys to the kingdom. I wonder if they'll sharpen the edges between clusters in response to this... --- (Disclaimer: I left Instructure back in 2017; much could have changed since then, and my memory could be faulty about the specifics. Caveat emptor.)
- podiki 5mo agoAnd grades are due in the next week or so for many of these (usually a quick deadline at the end of the semester due to graduation happening)...
- SoftTalker 5mo agoGraduation is just a ceremony. The actual credential award depends on whether you finished all your coursework and is not time-boxed by that event. Of course if you can't complete your exams because of this, that's more of an issue!
- enjo 5mo agoMy wife’s grades are due tomorrow. She was in the middle of finishing exams when it happened. She can’t even access the exams to grade by hand. Total mess.
- quiint 5mo ago[dead]
- deleted 5mo ago[deleted]
- tom1337 5mo ago> Canvas is currently undergoing scheduled maintenance doesn't seem that scheduled to me
- podiki 5mo agoI thought the same. The "scheduled" part of the message is gone now, at least on the instance I use.
- anematode 5mo agoWell, scheduled by whom? :)
- mystraline 5mo agoWhoever it is, is likely defended by Cloudflare. They seem to like the booters. https://news.ycombinator.com/item?id=48025001 https://news.ycombinator.com/item?id=48025001
- deleted 5mo ago[deleted]
- javawizard 5mo agoex-Instructure employee here (though it's been about 10 years since I worked for them). That's just the quickest page/status update to throw up; it was a one-liner to push it live back when I was on the deploy rotation. I'd hazard a guess they have more important things to worry about right now than exact status page messaging ;)
- chrisjj 5mo ago> That's just the quickest page/status update to throw up Funny how a lie is always quicker than the truth...
- javawizard 5mo agoOh for god's sake. In the 99% of cases where this status page is used, it is in fact the truth: we'd throw it up when we had e.g. data migrations to do as part of a rollout that wouldn't allow for our normal zero-downtime deploys. So no, lies are not always quicker than the truth. There's plenty to criticize Instructure about; let's not go reaching for straw men in the process.
- SoftTalker 5mo agoSo many universities used to run homegrown or on-prem student systems. This is the downside of consolidating in the cloud. If the infrastructure is compromised, it affects everyone, not just isolated or single installations. I wonder how they are feeling about that decision now? I guess they can say "not our fault" so they might be feeling better than if it was a vulnerability in their own system.
- crazygringo 5mo agoIf an exploit is found in the software, hackers will often be able to attack hundreds of separate institutional installations in an automated way just as easily. And depending on the exploit, potentially more easily if on-prem admins fail to take all recommended security steps. I'm actually much more interested if there is any financial liability for Instructure here? It's interesting that it's the universities being ransomed, while the technical failure was Instructure's. We're used to uptime SLA's -- what about security breach SLA's?
- poopmonster 5mo agoMy guess is that they believe by maximizing their attack coverage, the odds are greatest that some of the institutions will pay up. And otherwise, they can still make a bit of money by selling the data. Don't ransom all your eggs in one basket
- harikb 5mo ago> It's interesting that it's the universities being ransomed, while the technical failure was Instructure's. My guess would be they get likelihood of getting paid when blackmailing 9,000 schools (at least a few would pay up) than blackmailing Canvas/Instructure. I don't think any SLA/terms would change who gets to feel the pain.
- dylan604 5mo agoYeah, if they had spent the time and money to roll their own that got hacked, they'd be responsible. Now, they can just clap their hands and show them palms up to you like a black jack dealer and walk away from the table with no responsibility. Probably one of the biggest benefits of using a product instead of building your own.
- copperx 5mo agohttps://archive.is/5v693 https://archive.is/5v693
- xp84 5mo agoWhat are we even coming to when even internet blogs are paywalled. Verge? Next thing Gizmodo is gonna be paywalled.
- cocoacat 5mo agoAlso here: https://news.ycombinator.com/item?id=48054386 https://news.ycombinator.com/item?id=48054386
- vinni2 5mo agoI hate Canvas. I would rather run a course on GitHub. But our university forces it on us. And now this.
- crazygringo 5mo agoDo you remember how Canvas was a gigantic improvement over Blackboard? And GitHub doesn't provide a way to record grades that remain private per student last I checked, much less sync them to the university, or 99% of other things Canvas does. I don't love Canvas, but it's far, far preferable to a world without it.
- poopmonster 5mo agoIt is really convenient and stays out of the way. As much as I'm enjoying the mess, I am forced to appreciate its value.
- bombcar 5mo ago> remain private per student last I checked last I checked it appears grades remain private per planet or so ...
- deleted 5mo ago[deleted]
- bombcar 5mo agoHow does Canvas compare to things like Moodle? Or is it an entirely different class of beast?
- frollogaston 5mo agoWow, I last used Moodle in 7th grade, 2008. It seemed like a similar thing.
- wmoxam 5mo agoI've written a bunch of LMS integrations so I've had the opportunity to use all of the major LMSs. Basically, all LMS systems are rather user unfriendly and complicated with a ton of customization options hidden under layers of sub-menus/configuration settings. At their core they provide a grade book, student management tools, and some basic CMS type functionality for posting class messages/coursework/etc. They've all adopted a standard for interacting with external tools (LTI). Canvas generally is the 'easiest' to use, and the 'cleanest' looking one although D2L Brightspace is pretty good too. Moodle out of the box is pretty confusing and ugly, but I've seen some heavily customized instances that look a lot better. Blackboard is the worst of the bunch IMO.
- danso 5mo agoI wonder how much old data Canvas keeps around? Are students who graduated in 2016 going to be at risk of having their academic data leaked?
- Fumblenuts 5mo agoI bet it depends on the institution and the IT team behind said institution, but at least for my university we apparently don't delete old course shells or anything. I'm friends with a professor who complained to me a couple times about how sometimes he will need to scroll through pages and pages of courses he taught in the past. He also mentioned that profs aren't able to delete their own course shells either.
- Telaneo 5mo agoIt wouldn't surprise me if most of it is still around. The amounts of data are probably fairly small, and thus unless intentionally deleted, it's probably still there (maybe unis in Europe are more likely to bother to click the relevant buttons as to comply with the GDPR?). I can't imagine storage becoming an issue unless you've got a huge uni or classes that deal with video (and even then, those probably end up on Youtube as private videos, or only as really small clips).
- goryramsy 5mo agoDown for all students at my University… it’s going to be a headache for all professors to deal with extending due assignments.
- vondur 5mo agoIt looks like every CSU System is on the list (California State University). Surprised this hasn't hit the front page yet.
- DaSHacka 5mo agoPossibly because they haven't released the data yet? I'm honestly surprised more people aren't talking about this.
- gigel82 5mo agoDamn, all schools in our district in Washington moved to Instructure last year. They moved away from Teams because it objectively sucked, but I haven't heard of widespread compromises like this in Microsoft's systems so...
- ghqst 5mo agoWell instructure is slightly better than the somehow legal torture of having to use the "product" Microsoft Teams
- eatmyshorts 5mo agoMy daughter says that Northeastern is also affected. Is it more widespread? Did they infect all SaaS Canvas universities?
- parable 5mo agoYes, all 8000+ institutions that use Canvas.
- thecatapps 5mo agoI remember when I was in high school (2016? 2017?), I found a super simple XSS in the assignment submission form and told the programming teacher. Canvas then proceeded to lock my account and got me my first (only?) detention. Good times.
- frollogaston 5mo agoUh, did you tell the teacher by exploiting the vuln?
- somebudyelse 5mo agoSomewhat similar vein, the school's blocking software would block YouTube and embeds unless they came from Canvas. They were smart enough to disable the HTML editor for posting discussion comments, but forgot that since it was a rich text editor, you could just copy-paste in an embed by putting the code in data:text/html, then copying the element as formatted html. I also ran the entire DOMPurify sample XSS and managed to find one way to download custom content onto someone's computer.
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- ThrowawayR2 5mo agoI wonder when the public is going to start calling for corporate liability for malpractice in software development and corporate liability for malpractice in IT deployments. Even if the tech industry fights it, it probably won't be that much longer.
- berti 5mo agoThat is already happening in the EU [1][2]. Most of the world will catch up soon I suspect, with some notable exceptions. [1] https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... [2] https://ec.europa.eu/commission/presscorner/detail/en/ip_22_5807 https://ec.europa.eu/commission/presscorner/detail/en/ip_22_...
- brendanyounger 5mo agoI'll never understand this point of view. If someone would please explain how to create perfectly secure software, I will gladly start writing perfectly secure software. Only after, if it's clear I ignored obviously correct advice, should there be malpractice penalties. Consider surgery instead of software development. There are general best practices, but the difference between a good surgeon and a poor one is a small number of deaths. Malpractice insurance is high. Litigation is constant. And patients still die on the operating table. It's unclear what all the malpractice tort law actually gets you in the end.
- harikb 5mo agoWell, you don't know how many more would have died if doctors and hospital didn't care about their insurance going higher???
- cortesoft 5mo ago> Only after, if it's clear I ignored obviously correct advice, should there be malpractice penalties. In most of these cases, the companies involved did NOT follow standard security practices. I am pretty sure that is what people mean when they say "held responsible", they mean "held responsible for failing to follow standard security practices", not for the actual act of getting hacked.
- bagels 5mo agoIt's been a long time since I was in school. What does this software do?
- Jtsummers 5mo agoGrades, lessons, quizzes, exams, homework submission, rosters, messaging platform. Lots of things.
- adampunk 5mo agoIf you’re a student or teacher: nearly everything that matters. Homework, materials, lectures, grades. It’s all on canvas.
- kzrdude 5mo agoFor my uni: mostly only lecture notes and materials.
- windows_hater_7 5mo agoIt’s a “learning management system.” It replaces a course website in most instances. It’s also used for course grades and you can submit assignments or take quizzes.
- mbreese 5mo agoIt is how classes (even in person ones) are organized. Assignments, quizzes, links to online textbooks, discussion boards, student/teacher messaging, student group messaging, etc. From the teacher side, I'm not sure if there is a backup copy for things like grades outside of Canvas. It's that pervasive. Everything from middle school up to grad school. It's a particularly interesting time to have this happen too -- many finals going on now.
- flashman 5mo agoWhat's in the files they've already released? Some of them are > 800GB.
- poopmonster 5mo agoI'm guessing loads of student work? If so, it'll be great for anyone who wants to research AI usage in papers.
- DauntingPear7 5mo agoGrades, records, etc I would assume. Someone else pointed out that they recently acquired https://www.parchment.com/ https://www.parchment.com/ so they may have also been able to scoop up those records too
- emmelaich 5mo agoAlso discussions between students and teaching staff.
- HDBaseT 5mo agoWhere are you getting that information from? I'm under the impression files are getting released 12th May. I don't see any reporting on 800GB?
- poopmonster 5mo agoStudent at an impacted university here. Our whole testing center is down. This is inconvenient, but mainly it's amusing. I swear strangers are talking to each other more. I'm noticing people just sitting in the sun and relaxing. Nature is healing. (Of course, plenty of people have also just finished their exams, so it's hard to know the cause.) Any idea what data Instructure-and-also-now-ShinyHunters even purport to have beyond names, profile photos, pronouns, homework assignments, school communications, phone numbers, and email addresses? i.e. What makes this threat so different from what any old data brokers have already scraped? What leverage besides aura farming do the ShinyHunters really have? All I can think of that's really valuable is passwords. And private communications in Canvas DMs. But if you're being at all intimate over your school email, that's kinda on you. Anyway surely Instructure only stores user public keys or something? Alternate history question: If they just sold the data, never revealed the hack, and didn't make a scene, from a customer perspective, how different would this be from business as usual?
- matthewfcarlson 5mo agoI remember circa 2010 a friend of mine at college was like “blackboard sucks, let’s build something new”. At the time I poo pood the idea and lo and behold canvas came out a year later. Outside looking in, they been crushing it.
- HPMOR 5mo agoOne of my mentors created Blackboard. It used to be very very good, but he sold it to private equity, and they immediately fired all of the customer support and developers, 3xd prices overnight leading to the 'blackboard sucks' problem. This gave the opening for Canvas to eventually come on to the scene and dominate.
- rolandog 5mo agoMy wife and I each have to use it as we're both following an online master's at the same university... it's definitely gone downhill (compared to the days where I originally used it ~20 yrs ago in college; tracker-riddled, slow); surprisingly, a recent change made it so that you can only attend online lessons in Chrome (haven't had time to see if this is just a user-agent thing).
- corvad 5mo agoI believe Canvas was also sold to private equity pretty recently too. https://www.instructure.com/press-release/instructure-to-be-acquired-by-KKR https://www.instructure.com/press-release/instructure-to-be-...
- whoahwio 5mo agocanvas was bought by PE for the first time in 2020 https://www.thomabravo.com/portfolio/instructure https://www.thomabravo.com/portfolio/instructure
- redwood 5mo ago..and be acquired by PE so the cycle can continue.. https://www.instructure.com/press-release/instructure-to-be-acquired-by-KKR https://www.instructure.com/press-release/instructure-to-be-... sigh. Barbarians at the gate probably didn't double down on security
- sharkweek 5mo agoMy wife is in grad school at a major university and is dealing with this right now the week of midterms for spring quarter. I totally understand why a university wouldn’t want to bake their own learning portals but just feels like such a single point of risk to use third party solutions for something like this. Back in my day… all we had was a school email via on-premise services. I guess we registered for classes in a web portal but that’s about it. The idea of online class was entirely foreign at the time. Ain’t nobody hacking a blue book.
- jagged-chisel 5mo ago> Ain’t nobody hacking a blue book. Well not with that attitude
- asdff 5mo agoUniversities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.
- afavour 5mo agoIn fairness in the era where universities did it themselves the tech requirements and expectations were dramatically lower.
- clipsy 5mo agoHave these dramatically higher tech requirements and expectations improved the quality of education whatsoever?
- asdff 5mo agoTech requirements are the same as they always were. One needs to ask whether they need so many frameworks to host some files on the internet and submit some files and perform spreadsheet calculations. We still used one of those First Age 1990s websites for sort of pre lab quizzes this one class when I was going through it, and it might have looked a little "old" but I mean it did the thing and worked for years and will continue to do the thing and work for years.
- rahidz 5mo agoGoddammit. Anyone in the know, know if Parchment was also impacted by this potentially? They were acquired by Instructure a few years ago, and deal with a LOT of transcripts. Edit: https://status.parchment.com/ https://status.parchment.com/ says "While Canvas, Canvas Beta and Canvas test are currently unavailable, we are simultaneously monitoring all of our other product environments, including Parchment. We continue to see no reason to believe any Parchment resources have been impacted."
- boxingdog 5mo ago[dead]
- avs733 5mo agoIt is absolute chaos at my institution. This is the last day of finals and grades are due Monday morning. Most faculty are spending today, tomorrow, and through the weekend finalizing grades. What we don't have access to includes: * Already graded work * Ungraded work * overall adn assignment grades * lists of students and student emails from the course * messages from students that are often sent through gradescope Just...complete implosion.
- pesus 5mo agoWhat happens if the system isn't back up in time for grades to be submitted? Just a delay?
- OsrsNeedsf2P 5mo agoSomehow I have less distaste for ShinyHunters than I do for the companies who don't secure user data
- rixed 5mo agoWhen you picture the attacker, don't picture a bored nerdy teanager. Picture a selfish, $$ motivated psychopath. Let's not side with the parasites.
- chrisjj 5mo agoAnd lets not side with Canvas PR.
- altcognito 5mo agoHe didn't really side with Canvas PR, he just said these were not good people. They aren't. What did Canvas PR do except do a poor job? Doing a poor job of PR is a whole, whole lot less worse than actively destroying people's lives for profit.
- artificialLimbs 5mo ago[flagged]
- somebudyelse 5mo agoIt looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.
- myrandomcomment 5mo ago1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security investment. Every attack should be investigate if the company met an agreed industry standards best practices and staffing, etc. The penalties for not meeting the requirements should be punitive.
- bombcar 5mo agoYour "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.
- Kostchei 5mo agointerestingly, having actually done the law enforcement side of these investigations, 50% of them are local. And I understand that this is not 100% solution, but neither is any form of law enforcement, but that doesn't mean we should fail to attempt it. Kids from the local uni having a lark, stalkers, vindictive ex employees, local gangs, criminals who understand their victims because they hail from the same community. These are your local hackers. Sift them from the nation states and international crime groups, then deal with the International as a matter of diplomacy. Because we do this so poorly locally, we have little ammunition to when it comes to diplomacy. "reduce attacks by your crime groups and we buy your natural gas, seel you wheat etc" Want more motivation?- 75% of the local attacks by volume send funds back to terrorist or separatist organizations. It is not an in-soluble problem. Sentences are a fraction of the answer, effective and receptive reporting processes are more important, then government backing for investigation and enforcement, then policy around home-team activities (ie don't do the bad things yourselves Mr Gov). Deterrence comes after all that.
- hluska 5mo ago50% of ransomware attacks are local to where? You’ll need to cite some sources because I don’t believe that is possible.
- cindyllm 5mo ago[dead]
- jrm4 5mo agoCanvas shouldn't exist in its current form, and neither should have Blackboard. It's always been as stupid as requiring that your chalkboard, chalk, chairs, bluebooks, pens, paper, gradebook etc etc all come from the same company. I, for one, am very much looking forward to my IT Gov council meeting tomorrow.
- corvad 5mo agoCanvas is handling this terrible. No communication, no status updates, etc. Also looks pretty bad their whole platform was compromised and not a single real report for the breach that already had happened. Wonder how long it will take for SLA violations and lawsuits to manifest, especially with most U.S. schooling having finals right now.
- user3939382 5mo agoLot of experience dealing with Canvas/Instructure. Tech is o-k. Culture seems to be full of themselves due to market position.
- corvad 5mo agoYeah like their page says "Scheduled Maintenance" which is total B.S. Talking to people at my university's IT side of things Canvas has said nothing to any clients.
- javawizard 5mo agoThe "scheduled maintenance" thing is likely just because that's the easiest maintenance page to throw up site wide, or at least it was back when I was on the Canvas deploy rotation back at Instructure ~10 years ago. That doesn't excuse any of their other messaging though.
- nobleach 5mo agoWere you expecting "Got hacked, BRB"? I'm sure that page is their default circuit breaker.
- jeffwask 5mo agoFixed it for you. Also looks pretty bad their whole platform was compromised by the same hacker group again.
- kelnos 5mo agoA friend who teaches at MIT said they were hit by this. I found it ironic and a little sad that a place like MIT doesn't have an IT staff that can maintain their own on-prem solutions for things like this. But it turns out that MIT used to have their own homegrown system, and recently switched to Canvas. Bet they're regretting that now. The build vs. buy decision seems to have swung very hard toward buy in the last decade, and I think that's a shame. Yes, orgs need to focus on their core competency, and sometimes that means outsourcing things that aren't core competencies to third parties. But there are always downsides.
- mingus88 5mo agoI started my tech career in EDU. I’m not at all surprised. IT staff who are ambitious and talented don’t last long in education. The pay is very low compared to industry. Where I worked, you could retire with a comfortable pension after a number of service years, so the IT staff outsourced as much as possible so they needed to take zero risks to their nest egg. Blame all the problems on the consultants and do as little as possible. It’s literally where dreams go to die. MIT is known for the brilliant professors and students but at the end of the day, running a university is pretty standard stuff. They don’t need a genius rockstar to admin the courseware servers.
- royal__ 5mo agoHomegrown systems are expensive to maintain and usually still fail to match up to the commercial options available at this point. LMS's are also just really complicated pieces of software. I worked on my university's own version as an undergrad.
- deathanatos 5mo ago… so? My highschool, for a while, had a website, which was eventually replaces by a large corporate CMS. Was the website as complicated or complex as the CMS? No, you would have needed to know HTML to publish to it. The CMS was no doubt "more user friendly", I suppose. But … the original site had a soul. It was unique to the school. There was a student directory! All lost, because the CMS meant utter standardization between all the schools using it (their pages were all identical, except for each got like a different picture of the school as the banner at the top) and the CMS did not do directory anything. Of course, the directory largely didn't matter in the end. (This was when you needed people's landlines! Quite laughable nowadays…) But it was still sad to see it lost, and several of us students worked on it, which provided us with some early real-world experience. A large number of my college professors published their own sites, too, where they'd put their lecture notes, homework, etc. I loved those far more than I loved "Canvas" or whatever the ugly LMS we used was.
- BooneJS 5mo agoMy kids are in the middle of their finals week. What a mess. Universities know nothing, Canvas claims to be in a "scheduled maintenance", and one Prof claims to "not have any copies of material offline" which seems pretty negligent. Sounds like one section of a popular class will be doing paper exams while other sections had Canvas-based "half points for 2nd attempt"-type exams earlier today. How soon before names & grades appear in data dumps? This would be like TurboTax "scheduling maintenance" on April 14th in the US.
- corvad 5mo agoThe "Scheduled Maintenance" is just total B.S. and just honestly makes them look worse. Apparently according to their status pages this is what 99.996% uptime looks like. Pay attention lol.
- HDBaseT 5mo agoIt has been over 5 hours now and there has not been any communication about this being an attack, despite many of us seeing the ShinyHunters message on the login page. There is a lot of people who likely are unaware the latest outage is because they were compromised again. Them marking the incident as 'Under Maintenance' means the status page isn't reporting this as an outage and adding to downtime%.
- corvad 5mo agoOnce we hit 8h 45m SLA has been broken. https://uptime.is/99.9 https://uptime.is/99.9 https://www.instructure.com/trust-center/availability https://www.instructure.com/trust-center/availability
- anakaine 5mo agoCompromised again? This is a separate in ident to the one seen yesterday?
- rupx 5mo agoCorrect. The incident yesterday was technically from April 28th, with most communications coming out on the 2nd and 3rd, with it being "Resolved" yesterday. This incident is the second attack, because they failed to secure their infra again. Everything being reported is a bit delayed, which makes it seem like this is a single attack, not technically two instances.
- SilverElfin 5mo agoTerrible that this affects children and that their information may be ultimately leaked. They need to be greater consequences in the law for security breaches.
- robertritz 5mo agoI'm shocked universities don't host their own LMS? At least large universities have the IT departments to do this. They host compute clusters, so they can certainly host an LMS.
- oezi 5mo agoThe same reason hospitals don't have their own Patient Information System but all use Epic. The amount of customization you need and continuous churn due to changing curricula and regulatory requirements makes it hard to keep up without scale.
- swatson741 5mo agoI saw this happen to my Canvas account today. At first I thought it was a prank from the school or Instructure. The message was sent to students which makes no sense. Second, the message that was sent basically implies that ShinyHunter is actively getting patched out, and no one is ever going to give into their demands. They're basically saying that they're done and desperate. It's a strange message for ShinyHunter to send, but I think they were trying to pull off a psyop / FUD. Looking into the payload they sent me this is how they hijacked the screen. Everything in the payload is unchanged except for one line of code: <link rel="stylesheet" href="https://instructure-uploads.s3.amazonaws.com/account_93630000000000001/attachments/90359187/canvas-override.css https://instructure-uploads.s3.amazonaws.com/account_9363000..." media="all"/> This links to the following styling sheet: @import url('https://fonts.googleapis.com/css2?family=Orbitron:wght@500;700&family=Rajdhani:wght@600&family=Fira+Code:wght@400;600&family=Share+Tech+Mono&display=swap https://fonts.googleapis.com/css2?family=Orbitron:wght@500;7...'); html, body { height: 100% !important; overflow: hidden !important; margin: 0 !important; padding: 0 !important; } body > * { display: none !important; } body { display: flex !important; align-items: center !important; justify-content: center !important; background: #07080c !important; } body::before { content: "" !important; position: fixed !important; inset: 0 !important; z-index: 999998 !important; background: radial-gradient(ellipse at 50% 20%, rgba(255,59,59,.06), transparent 55%), radial-gradient(ellipse at 50% 85%, rgba(125,70,152,.04), transparent 45%), repeating-linear-gradient(0deg, rgba(255,255,255,.035), rgba(255,255,255,.035) 1px, transparent 1px, transparent 3px), #07080c !important; pointer-events: none !important; } body::after { content: "\A\A" "S H I N Y H U N T E R S" "\A" "rooting your systems since '19 ;)" "\A\A\A" "ShinyHunters has breached Instructure (again)." "\A" "Instead of contacting us to resolve it they" "\A" "ignored us and did some \201Csecurity patches\201D." "\A\A" "\26A0 W A R N I N G" "\A\A" "If any of the schools in the affected list are" "\A" "interested in preventing the release of their" "\A" "data, please consult with a cyber advisory firm" "\A" "and contact us privately at TOX to negotiate a" "\A" "settlement. You have till the end of the day by" "\A" "12 May 2026 before everything is leaked." "\A\A" "Instructure still has until EOD 12 May 2026" "\A" "to contact us." "\A\A" " \25BC DOWNLOAD AFFECTED_SCHOOLS.TXT \25BC" "\A" "91.215.85.103/pay_or_leak/" "\A" "instructure_affected_schools_list.txt" "\A\A" "visit us: shnyhntww34phqoa6dcgnvps2yu7dlwzmy5" "\A" "lkvejwjdo6z7bmgshzayd.onion" !important; position: fixed !important; z-index: 999999 !important; top: 50% !important; left: 50% !important; transform: translate(-50%, -50%) !important; white-space: pre !important; text-align: center !important; font-family: 'Fira Code', 'Share Tech Mono', monospace !important; font-size: clamp(10px, 1.4vw, 14px) !important; line-height: 1.55 !important; color: #c8dce8 !important; background: linear-gradient(180deg, rgba(255,255,255,.05) 0%, rgba(255,255,255,.01) 3.2%, transparent 3.2%) !important; background-color: #0d0f16 !important; border: 2px solid #ff3b3b !important; border-radius: 14px !important; padding: 16px 32px !important; overflow: hidden !important; box-shadow: 0 0 35px rgba(255,59,59,.2), 0 40px 90px rgba(0,0,0,.65), inset 0 0 0 1px rgba(255,255,255,.06), inset 0 0 50px rgba(255,59,59,.03) !important; animation: pulseWarn 2.5s infinite ease-in-out !important; max-width: 94vw !important; text-shadow: 0 0 6px rgba(200,220,232,.15) !important; } @keyframes pulseWarn { 0% { box-shadow: 0 0 20px rgba(255,59,59,.15), 0 40px 90px rgba(0,0,0,.65), inset 0 0 0 1px rgba(255,255,255,.06); } 50% { box-shadow: 0 0 55px rgba(255,59,59,.4), 0 40px 90px rgba(0,0,0,.65), inset 0 0 0 1px rgba(255,255,255,.06); } 100% { box-shadow: 0 0 20px rgba(255,59,59,.15), 0 40px 90px rgba(0,0,0,.65), inset 0 0 0 1px rgba(255,255,255,.06); } } The hack is crude, and it seems unlikely that they have any access to Instructure's developer tools.
- deleted 5mo ago[deleted]
- corvad 5mo agoJust learned the defacement page was hosted from instructure's own aws bucket so seems pretty bad.
- tech234a 5mo agoA post on the official Canvas forum: https://community.instructure.com/en/discussion/666027/ransomware-notice-in-our-canvas?tab=all https://community.instructure.com/en/discussion/666027/ranso...
- orourke 5mo agoMy son was in the middle of an exam and then his screen went black and it showed the message from ShinyHunters. Hasn’t been able to get back in since.
- tptacek 5mo agoThe boy is a biochem PhD student at UIUC and reports that all their finals are now cancelled. "Is this good news?" I ask. "Yes. Everything coming up Milhouse."
- blahedo 5mo agoPerspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide shutdown" and "cybersecurity attacks", no further detail). I don't get a sense that they know much more than that, not that I would expect them to. A perhaps telling detail: they're instructing us to have students email us directly with any work that had been submitted via Canvas. That suggests that they have no particular confidence that it will come back up soon. I personally am only slightly affected; as a CS professor a lot of my students' work is done on department machines, and submitted that way, and I do the actual exams on paper. More importantly, I've never liked or trusted Canvas's gradebook, and so although I do upload grades to Canvas so students can see them, my primary gradebook is always a spreadsheet I maintain locally. But I have a lot of colleagues for whom this is catastrophic at a level of "the whole building burnt down with all my exams and gradebooks in it"---even many of those that teach 100% in person have shifted much or all of their assessment into Canvas (using the Canvas "quiz" feature for everything up to and including final exams), and use the Canvas gradebook as their source-of-truth record. We've been encouraged to do so by our administration ("it makes submitting grades easier"). For faculty in that situation, they have few or zero artifacts that the students have produced, the students themselves don't have the artifacts to resubmit via email because they were done in Canvas in the first place, and they have no record of student grades or even attendance (because they managed that all inside Canvas). I guess they have access to the advisory midterm grades from March, if they submitted them (most do, some don't), but that might be it. My gut feeling on this is that this is either resolved in hours (they have airgapped backups and can be working as soon as they can spin up new servers), or weeks (they don't). Very little in-between. And if that's true and we wake up tomorrow with this unresolved, I really have no idea what a lot of professors at my university and across the country are going to do to submit grades that are fair and reasonable. In the extreme case, they may have to revert to something we did in the pandemic semester (and before that, at my school, in the semester that two major academic buildings actually did burn to the ground a week before finals): let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do? (Well, one thing you can do is not put your eggs all in one basket, and not trust "the cloud" quite so much, but that ship's already sailed. I do wonder if in the longer term, anybody learns any lessons from this....) UPDATE: As of 11:45pm EDT, my university's canvas instance is up and running! Here's hoping it stays (but I'll be downloading some stuff just in case...)
- infrapilot 5mo ago[flagged]
- starkrights 5mo agoWhere did you find information on the nature of the attack?
- mudkipdev 5mo agoThis is an AI bot
- poopmonster 5mo agoHow did you identify it?
- wg0 5mo agoYou learn all the technical details only to harm people like that instead of making a modest and honest living. Shame on your existence basically.
- owlboy 5mo agoI’m not surprised. Canvas kind of sucks. And their development is slow. And they are poor at communicating during mundane events.
- stringfood 5mo agoThey're also apparently poor at communication during highly interesting events as well
- Gabriel54 5mo agoI'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, without exception, due to ADA compliance regulations. It is explicitly forbidden for professors to, e.g., refer to pdfs posted on a personal website. Other commentators here seem not to understand that many faculty also do not enjoy being forced to use Canvas.
- Loughla 5mo ago[flagged]
- Gabriel54 5mo agoAccessibility regulations, implemented with feedback from faculty and with the support of university resources, are certainly a good thing. But that is not what is happening in my experience.
- sellyme 5mo agoPutting aside the "So you hate waffles?" non-sequitur, surely the entire topic of this thread should be a bit of a hint that this misguided policy has not, in fact, "[made sure] courses are fully accessible".
- Gabriel54 5mo agoWell, to be fair, it has made every course hosted on Canvas equally accessible to everyone. ;)
- yard2010 5mo agoNot GP, Incompetent policy makers are the bad thing.
- SoftTalker 5mo ago
- corvad 5mo agoSome instances seem to be recovering. I wonder if a ransom was paid.
- somebudyelse 5mo agoIt looks like Instructure has been removed from the ShinyHunters website. Both the entry and the list of schools has been removed.
- bumblehean 5mo agoHugs going out to the teams at Instructure working to fix this. I've been through a similar Ransomware attack (national news stories, lots of customers dead in the water, etc.), and it's about as bad a situation you can wind up in.
- incomplete 5mo agoi work tech at a university that's impacted by this. while it doesn't impact me directly, many many other staff and instructors i know are heavily affected by this outage. the students are absolutely outraged, mostly because the university hasn't been providing updates as quickly as they'd like, but since the staff/admin are waiting on word from instructure -- and there hasn't been a lot from them, it just generally sucks for all of us. this is really, really, REALLY bad. it's not great that names/emails/etc will potentially be leaked, but also private messages between students and instructors. and since many of the campus systems rely on canvas integration, things have pretty much ground to a halt a week before finals. after they were breached on the 1st of this month, instructure had an announcement yesterday that "everything is great! we're good! hackers are gone! we've rotated our keys!". no. nothing is great. we are not good.
- eiiot 5mo agoI'm a student at Stanford — this is hitting the whole school hard. Unlike a lot of schools on the east coast that are affected (Brown, Harvard, MIT) we are on the quarter system so we're just ending Midterms right now. We're also lucky enough to have our CS department entirely independent from Canvas, but most of my humanities classes are not so lucky. One art history class is having us submit our midterm papers by uploading to a google drive folder—another is pausing weekly quizzes. The main thing this has revealed is just how dependent students and teachers are on Canvas... I hope that this re-prompts discussions about moving off of a platform that was already (from a student perspective) not very good.
- zuzululu 5mo agoI really feel like SH fucked up by sinking this low hitting students and Americas young minds like this.... One thing to target coroporations but leave the students alone....
- noitpmeder 5mo agoAnd what's your opinion on the em dash?
- eiiot 5mo agoThat it tends to provoke unproductive comments like this one. https://news.ycombinator.com/newsguidelines.html#comments https://news.ycombinator.com/newsguidelines.html#comments
- Telaneo 5mo agoGreat. More data gone astray. Given Canvas' handling of the situation, I doubt they're going to learn much. The timing probably isn't a coincidence. Great time to stress out students and staff alike. Hopefully it doesn't affect them too much in the end, but I imagine it will.
- deleted 5mo ago[deleted]
- rosie54 5mo agoTbh this is extremely annoying for high school/college students too. High schools are in the middle of AP tests, and many universities have yet to finalize grades, so overall this is a terrible time for this to happen. After the first issue a few weeks ago Canvas should have upped their security and prepared for another attack. They also should provide better communication. If Canvas is down for more than a few days, many schools and universities will have a lot of trouble when it comes time to publish course grades.
- acomjean 5mo agoI used canvas for some Harvard extension classes 10 to 5ish years ago. It worked Ok. Work distributed, grades posted. I didn't realized so many schools used it, or that it was all schools on one instance, which seems kind of nuts. I lost access when I left as it was tied to my work email. I downloaded a lot, but there was still some useful stuff on the boards. I wonder what the havkers found out about me. Perhaps the class notes will be lifted to train AI, higher quality than a lot thats on the internet anyway.
- Gigachad 5mo agoI discovered one of my old school assignments ended up on some homework help website. I had never posted this document publicly and had only uploaded it to the schools work submission page. Presumably at that point it was shared with multiple third parties for plagiarism checking and such. And then was exposed to a data breach years later and ended up on the public internet.
- SeanAnderson 5mo agohttps://status.instructure.com/ https://status.instructure.com/ implies Canvas became available again about thirty minutes ago from the time of this post. Is this accurate? Or is this still an ongoing issue?
- podiki 5mo agoOngoing. It is not "down" but purposefully offline for "maintenance." Main status does show the LMS (all the course stuff) down, and my instance shows "up" but that's because (I assume) you can reach it and the maintenance page. But that's not useful, if technically not "down."
- SeanAnderson 5mo agoThanks
- boldi 5mo agoCanvas LMS is the core service that universities rely on. I assume they're trying to develop a fix and that's why the service is labeled "Under Maintenance". I'm a Berkeley student and can confirm that our instance (bcourses.berkeley.edu) is still down.
- owlboy 5mo agoFederated logins appear to now be broken for the campus I’m affiliated with. So more action is needed.
- spmartin823 5mo agoOne thing I remember from my days in the LMS world is that obfuscated copies of prod tenants were used for testing. Almost every dev had at least one tenant from prod on their local computer. So with some de-obfuscation at least some of the data is plausibly retrievable. Whether that data is also public depends on how the negotiations go.
- nektro 5mo agogoing after systems that affect students is beyond bad taste
- 0xbadcafebee 5mo agoNothing to see here folks. Just another predicable data breach from allowing companies to do whatever the hell they want with sensitive personal information. This will keep happening, more and more, and never stop, until we create a software building code and legally require it for all online businesses. Universities, Parents: ya'll actually have the political and economic power to get a software building code passed. This incident isn't the last.
- thatxliner 5mo agoI remember this group did something else a while back too.
- aaronsung 5mo agoAt the same time, Aussie tech giant pauses work, devotes entire week to AI Design software giant Canva has halted normal operations across its 5300-strong global workforce for five days of nothing but AI learning and hackathons, bucking the global wave of technology giants that have slashed jobs, citing the technology. https://www.smh.com.au/technology/aussie-tech-giant-pauses-work-devotes-entire-week-to-ai-20260507-p5zup7.html https://www.smh.com.au/technology/aussie-tech-giant-pauses-w...
- Torn 5mo agoCanvas is not Canva. Is this a bot reply
- aibudaev 5mo ago[dead]
- alexalx666 5mo agoRespect to Canvas sales team, its like microsoft level platform lock-in into low sec infra
- asdefghyk 5mo agoHundreds of 1,000s of students affected by this hack in Australia ( and no doubt other countries around the world ...) Its more than the 10,000s Australian students mentioned in article below ... https://www.abc.net.au/news/2026-05-08/students-lose-access-to-canvas-receive-ransom-messages/106657440 https://www.abc.net.au/news/2026-05-08/students-lose-access-...
- stevenjgarner 5mo agoSo all these top universities using Canvas as a core part of their infrastructure somewhat begs the question : why would a technology degree from them have any real value if they can't even have their infrastructure built and maintained by students themselves? If their education is really worth that much money, why can't they build their own infrastructure?
- dopidopHN2 5mo agoHave you look at student generated code ? I mean, maybe it changed in the last 10 years. But I was a TA grading CS majors for a while. Their C capstone or what have you. Some were decent but naively coded. Most were pile of shit half hazardly put together so it output what is needed to get passing grade. But I agree with you in spirit!
- stevenjgarner 5mo agoNo paywall : https://archive.ph/fLR71 https://archive.ph/fLR71
- echelon 5mo ago> ShinyHunters Is that a Pokemon reference?
- tabarnacle 5mo agoYes
- mobeigi 5mo agoI enjoyed the reference more than the story itself :)
- kelvinjps10 5mo agoAt the beginning I thought it was the design tool
- nxobject 5mo agoI'll be shocked if Canvas ever gets held publicly accountable for this. I believe FERPA's PII provisions apply to Canvas and contractors handing PII in general (at least as interpreted by the Department of Education). Now, will Canvas be held accountable by ED in this administration? Hah – DOGE probably ran that through the shredder as well.
- 1970-01-01 5mo agoDepends on how bad it gets. Most likely nothing will happen however if they leak the PII of enough of the rich and powerful then you can expect lawsuits.
- xd1936 5mo agoOfficial cybersecurity insurance company required FAQ: https://www.instructure.com/incident_update https://www.instructure.com/incident_update
- owlboy 5mo agoThe way they describe it as an issue with free accounts seems vague and misleading. Why would _any_ account have this broad of access? Why would free ones be uniquely insecure vs official ones? This suggests a bad actor at any institution could do the same thing done here. No?
- lazystar 5mo ago> Earlier in October, an Amazon Web Services incident resulted in Canvas and Piazza outages that lasted around 12 hours. ...what does that DDB DNS issue have to do with anything?
- mensetmanusman 5mo agoIt's interesting how delta-function-esque security issues are, which makes it nearly impossible for young organizations to properly risk asses.
- jshaqaw 5mo agoShaking down schools with kids' data. Losers.
- Michael666 5mo ago[dead]
- waltbosz 5mo agoFor a more technical write up https://www.dataminr.com/resources/intel-brief/shinyhunters-claims-instructure-canvas-breach/ https://www.dataminr.com/resources/intel-brief/shinyhunters-... I'm a software dev who was affected by the outage. I was working on an app that connects to the Canvas SAML endpoints. One minute I was able to run my code, the next I couldn't. This was a little after 17:00 EST.
- SoftTalker 5mo ago> ShinyHunters ... said its data leak site contains 9,000 schools, including data belonging to 275 million students Brought up a question I've had every time I read about these leaks... what kind of pipes do these shadowy groups have that they can grab all this data? I've spent days waiting just downloading a few 100 of GB from OneDrive. How do they grab all this data, are they just slowly gathering it for months via a compromised desktop somewhere, or if not, are the companies not monitoring for unexpected massive amounts of outbound traffic from their database or file servers?
- organsnyder 5mo agoI'd assume they have a botnet to parallelize it. Though depending on where you live (not that they'd be using their own machines) fast pipes are fairly common—I have a 5gbps symmetrical fiber connection to my home in Michigan.
- owenpalmer 5mo agoI tried to become a contributor to Canvas (it's open source), but I couldn't even get a development environment setup because of their storage space requirements. https://github.com/instructure/canvas-lms/wiki/Quick-Start https://github.com/instructure/canvas-lms/wiki/Quick-Start > It is recommended that you have at least 150GB of available hard drive space, 8GB of RAM, and a quad-core CPU to use this script. As far as I can tell, this is not for running a production environment with assets. This is just the development environment.
- dlcarrier 5mo agoI long for the days when FPGA development environments were an order of magnitude more bloated than software development environments. I've tried, on multiple occasions, to build an open-source Android application, and each time I've given up after a few hours of trying to get all the bloat working together well enough to even compile something already written.
- mammamia1 5mo ago[dead]
- ahdorman 5mo agoI loki don't care about the canvas hack because it only has a LITTLE bit of my information¯\_(ツ)_/¯
- ahdorman 5mo agoyo
- ahdorman 5mo agoyp
- ahdorman 5mo agohopefully I don't get kidnapped idk
- ahdorman 5mo ago[dead]
- ahdorman 5mo agoewnwehiu
- HDBaseT 5mo agoCanvas has paid the ransom. QUOTE To our Instructure Community, We know that for many of our customers, concerns about the potential publication of data related to this incident remain top of mind. We want to acknowledge those concerns directly – we understand how unsettling situations like this can be, and protecting our community is also a top priority for us. With that responsibility in mind, we reached an agreement with the unauthorized actor involved in this incident. As part of that agreement, the data was returned to us, we received assurances that it will not be further shared on the dark web or elsewhere, and we received proof that any copies of that data were deleted. Further, we have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise. While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give our customers additional peace of mind, to the extent possible. We are sharing this update in the continued interest of transparency and so that our customers know that we have addressed this element of the incident directly. To reiterate, the agreement covered all of our customers, and there is no need for individual customers to attempt to engage with the unauthorized actor. We appreciate your patience and trust as we continue to respond to this incident thoughtfully and comprehensively. We remain committed to providing meaningful updates as our work progresses. Regards, Steve Daly, CEO, Instructure" END QUOTE