
Global Canvas Hack Wreaks Havoc on Finals as ShinyHunters Presses Extortion
A ransomware attack on the learning platform Canvas has paralysed thousands of universities and schools worldwide, derailing final exams and leaking personal data.
The digital backbone of higher education snapped this week when ShinyHunters, a hacking collective known for its aggressive “pay or leak” campaigns, breached the cloud-based learning platform Canvas, forcing an emergency shutdown that threw final examinations into chaos across three continents. Instructure, the ed-tech giant that owns Canvas, confirmed that an intruder exploited a vulnerability in its free-teacher accounts to access systems used by more than 30 million users — half of all North American institutions of higher learning, alongside universities in Australia, Sweden, Canada and Britain. The outage struck at the worst possible moment: the high-stakes end-of-year season when students are submitting final projects and sitting for exams.
Viewed from Washington, the attack has reignited a bitter debate about the Trump administration’s earlier dismantling of federal cyberdefence programmes, a decision analysts now describe as a catastrophic miscalculation given the sophistication of groups like ShinyHunters. In Europe, regulators at Sweden’s Integrity Protection Authority received breach notifications from 49 universities within hours, while Queensland’s education minister scrambled to reassure parents that no financial data had been stolen — though names, email addresses and internal messages had been exfiltrated. The hackers left a taunting message on the Canvas login page: “Make a deal before everything is leaked,” giving institutions until 12 May to negotiate.
Instructure chose not to pay the ransom, instead forcing a global platform shutdown that restored most services by Friday, but the disruption had already cascaded through campuses. Mississippi State University postponed exams; Rutgers students spoke of “literally everything” being inaccessible; and a Swedish university convened crisis meetings for two consecutive days. The incident exposes a deeper vulnerability, analysts in London note: the consolidation of academic infrastructure into a single, centralised digital platform creates a single point of failure that ransomware groups are increasingly eager to exploit.
ShinyHunters, a network tied to the broader “Com” ecosystem of young, crypto-obsessed hackers, has already claimed attacks on Pornhub and Vimeo, and is now pivoting toward the education sector — where the pressure to restore normalcy during finals week makes institutions particularly reluctant to resist extortion demands. As universities across the globe scramble to reassess their reliance on outsourced courseware, the brief moment of digital paralysis this week may prove to be a harbinger of far more severe disruptions ahead.
Broaden your view
Iran and Oman finalise Hormuz shipping route deal, reopening hinges on US
2 languages · 47 outlets
From Economy & MarketsOil majors post bumper Q2 profits as Iran conflict drives price surge
2 languages · 21 outlets
From TechnologyApple briefly removes Telegram from App Store over child abuse content
3 languages · 27 outlets