Last updated 1 month ago
Canvas, an education technology platform serving nearly 9,000 educational institutions across the United States, suffered a data extortion attack that disrupted classes and coursework nationwide. The breach was disclosed on May 1, 2026, with the threat actor defacing the service's login page and demanding a ransom, threatening to leak data from 275 million students and faculty.
The attack involved unauthorized access to Canvas systems, leading to the defacement of the login page with a ransom demand. The threat actor claimed to have exfiltrated data on 275 million individuals, though the specific data types compromised have not been detailed. No initial access vector or exploitation technique has been confirmed, and no threat actor has been attributed.
No post-incident developments have been reported regarding regulatory involvement, litigation, ransom payment, or remediation milestones.
Defacement of login page with ransom demand and threat to leak data
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector