Campus ID News
Card, mobile credential, payment and security
FEATURED
PARTNERS
Warning message from hackers to Canvas users

Student ID numbers exposed in Canvas cyberattack

Massive breach of the learning platform exposed sensitive student data, reignites concerns over cybersecurity in education

Anna Bullock   ||   May 19, 2026  ||   ,

Canvas, a learning management system used by schools and universities worldwide, fell victim to a major cyberattack that disrupted access for millions of students during finals week. Students and educators across North America suddenly found themselves unable to access assignments, exams, grades, and course communication at one of the busiest times of the semester.

The hacker group ShinyHunters claimed responsibility for the attack claiming it stole data connected to nearly 9,000 institutions globally. The group reportedly threatened to release stolen information unless a ransom agreement was reached with Instructure, the company that owns Canvas.

The breach quickly became more than just a temporary outage.

Commentary from Stefanie Schappert, Senior Journalist at Cybernews, described the situation as “something much bigger – a test of whether the more than 8,000 schools caught up in the hack can trust a hacker group’s word that stolen student data was actually destroyed.”

Impact on students and schools

Among other data elements, student ID numbers were exposed in the Canvas cyberattack. Additionally, the breach reportedly included student names, email addresses, enrollment data, and private messages exchanged between students and teachers. Schappert says that the attack may have involved “billions of private messages” stored on the platform.

The attack caused widespread outages, with many schools temporarily shutting down Canvas access or switching to alternative communication methods.

The disruption came during an especially stressful time for students, as many colleges and universities were in the middle of final exams, assignment deadlines, and graduation activities. Students expressed frustration and panic because they could not access study materials, submit assignments, or contact professors during this critical period.

Canvas is no longer just a homework portal. It functions as the classroom, gradebook, assignment tracker, messaging hub, exam platform, and student records pipeline all rolled into one.

Some schools opted to delay or cancel final exams altogether after outages prevented access to course materials and testing systems.

The University of Illinois postponed its final exams and assignments.

Penn State canceled certain exams scheduled for Thursday and Friday night, saying it was working with faculty to "determine next steps for final grading." They urged students to check their emails – not Canvas – regularly in the meantime.

Baylor University delayed its Friday exams and asked all faculty to send study materials from their local computers directly to students via email.

Attack reignites cybersecurity concerns on campus

This incident highlights the dependency schools have on centralized online learning platforms such as Canvas and the risk this brings.

Canvas is “no longer just a homework portal,” Schappert says. For many schools, it functions as “the classroom, gradebook, assignment tracker, messaging hub, exam platform, and student records pipeline all rolled into one.”

As outages spread, the breach demonstrated how a cyberattack on one education platform can affect millions of students and educators at the same time.

Schools heavily rely on platforms like Canvas to store sensitive student information. Once schools depend entirely on one system, outages and cyberattacks can quickly escalate into widespread academic disruptions.

Once student data is stolen, control is gone, even if hackers later claim the information was deleted after payment agreements were reached.

Stolen data could still be copied, shared among affiliates, or resurface months later despite promises of destruction. And, it can still be used for phishing scams or identity-related fraud, even if financial information isn’t leaked.

Though students may seem like unlikely targets, education-related breaches are not uncommon. Young people rarely track their own credit, use credit monitoring services, or setup credit bureau locks and flags. This means that it can take years for them to notice fraudulent loans, credit cards, or other forms of identity theft.

Questions about paying the hackers

Instructure later announced it had reached an agreement with the hackers, saying the stolen data was returned and verified as destroyed. Still, it is questionable whether there is a reliable way to fully confirm that copies of the data were not retained elsewhere.

Stolen student data could still be valuable for phishing scams, identity-related fraud, and targeted social engineering attacks, even with Canvas back online.

The situation drew comparisons to the 2024 PowerSchool breach, where hackers allegedly continued extortion attempts even after receiving payment and promising to delete stolen information.

The incident raised concerns about whether paying ransomware demands actually protects victims or simply delays future risks. Schools and students may still face long-term consequences even after ransom agreements are made.

Subscribe to our weekly newsletter

RECENT ARTICLES

George Davey, Grubhub, video interview
Jun 12, 26 / ,

Grubhub serves more than 400 campuses with partnership-first approach to dining

In this episode of CampusIDNews Chats, George Davey, Partnerships Director at Grubhub Campus, discusses how the company’s campus dining platform is designed around partnership, flexibility, and convenience for both institutions and students. The company now partners with more than 400 campuses nationwide and continues expanding its capabilities in 2026, with improvements to offline functionality and […]
Florida State University entrance building
Jun 11, 26 /

OpenAI facing lawsuits following Florida State dining hall shooting

Last year’s tragic shooting at Florida State University, which killed two and injured five, has led to a wave of legal action against technology giant OpenAI. The first lawsuit was filed on May 10 in Florida’s northern federal district court by the family of Tiru Chabba, a 45-year-old husband and father of two who worked […]
University of Utah UCard video intro screen
Jun 10, 26 / ,

Best of 2026 campus card awards presented for marketing, innovative tech, and leadership

Each year at the NACCU Annual Conference, a series of awards are presented to individuals and institutions for innovation and dedication to the profession. At the 2026 Annual Conference in Covington, Kentucky, three institutions and five individuals were recognized. Congratulations to all the winners and nominees. Best Video Award: University of Utah The University of […]
CIDN logo reversed
The only publication dedicated to the use of campus cards, mobile credentials, identity and security technology in the education market. CampusIDNews – formerly CR80News – has served more than 6,500 subscribers for more than two decades.
Twitter

Great inverview on the Public Key Open Credential (PKOC) standard with ELATEC's Jason Ouellette, Chairman of the Board for the @PSIAlliance.

Attn: friends in the biometrics space. Nominations close Friday for the annual Women in Biometrics Awards. Take five minutes to recognize a colleague or even yourself. http://WomenInBiometrics.com

Load More...
Contact
CampusIDNews is published by AVISIAN Publishing
315 E. Georgia St.
Tallahassee, FL 32301
www.AVISIAN.com[email protected]
Use our contact form to submit tips, corrections, or questions to our team.
©2026 CampusIDNews. All rights reserved.