The digital infrastructure of higher education in Ontario is reeling after a massive cybersecurity breach hit Canvas, the widely used learning management software. The incident has impacted thousands of educational institutions globally, including some of Canada’s most prestigious universities, raising urgent questions about the vulnerability of student data in an increasingly digitized academic landscape.
Among the affected institutions are the University of Toronto, OCAD University, Ontario Tech University, Mohawk College, and Western University’s Ivey Business School. While the breach has not disrupted the completion of winter terms for several of these schools, the scale of the intrusion has prompted precautionary shutdowns of critical systems and warnings to thousands of students and faculty members regarding potential phishing attacks.
The breach, which targeted the U.S.-based parent company Instructure, appears to be one of the most expansive attacks on educational IT infrastructure in history. According to David Shipley, CEO of Beauceron Security, the event is “incredibly destructive,” characterized by a sophisticated effort to extract data and extort payments from educational entities.
The Anatomy of a Global Breach
The crisis first became public on May 1, when Instructure posted a notice regarding a breach by a “criminal threat actor.” By May 2, the company clarified that the compromised data included identifying information such as names, email addresses, student ID numbers, and internal messages. Crucially, Steve Proud, Instructure’s chief information security officer, stated there was no evidence that passwords, government-issued identification, or financial information were stolen.
The vulnerability was later traced back to a specific entry point. Brian Watkins, a spokesperson for Instructure, confirmed that the unauthorized actor exploited an issue related to “Free-For-Teacher” accounts. These accounts, designed to allow educators to use Canvas independently of an institutional license, served as the gateway for the hackers. In response, Instructure temporarily shut down all Free-For-Teacher accounts to seal the leak and restore the integrity of the rest of the system.
The timeline of the incident reveals a volatile sequence of events where the system was restored, only for hackers to seemingly return and cause further disruption.
| Date | Event | Impact/Action |
|---|---|---|
| May 1 | Initial Breach Notice | Instructure reports “criminal threat actor” access. |
| May 2 | Data Identification | Names, emails, and student IDs confirmed as potentially impacted. |
| May 8 (Wed) | Initial Restoration | Instructure declares Canvas fully operational. |
| May 9 (Thu) | Secondary Attack | Reports of defaced login pages and renewed system outages. |
| May 10 (Fri) | Root Cause Identified | Free-For-Teacher accounts disabled. systems restored globally. |
Local Impact: U of T and Ontario Campuses
In Toronto, the University of Toronto took aggressive precautionary measures by halting access to Quercus, the university’s specific implementation of the Canvas software. The administration advised students and staff not to attempt to access the program while the school worked with Instructure to resolve the incident. U of T has since reported the breach to the Information and Privacy Commissioner of Ontario, underscoring the legal gravity of the data exposure.
Similarly, OCAD University informed its community of service disruptions to the Canvas Cloud program. While access has since been restored, the university issued a stern warning to its students to be vigilant against phishing messages—fraudulent emails that often mimic official communications to trick users into revealing passwords or personal details.
Ontario Tech University and Mohawk College also confirmed they were impacted. Ontario Tech’s IT department noted that while course-related messages and institutional IDs were involved, there was no indication that broader university systems were compromised. The sentiment across these campuses has been one of cautious restoration, with administrators emphasizing that since the winter terms had concluded, the academic impact was minimized.
The Adversary: ShinyHunters and Data Extortion
The breach has been attributed to a hacking group known as “ShinyHunters.” According to Luke Connolly, a threat analyst with cybersecurity firm Emisoft, the group is a loose affiliation of young adults based primarily in the United States and the United Kingdom. Far from being amateur hackers, ShinyHunters are described as a “data extortion gang” with a history of high-profile attacks, including breaches of Telus and the UK retailer Marks and Spencer.
The scale of the ShinyHunters’ claim is staggering. A ransom letter shared via Ransomware.live, a site that tracks cybercriminal activity, alleged that data from over 275 million people across 9,000 schools was accessed. The group set strict deadlines for payment, threatening to leak the massive trove of data if their demands were not met.
This pattern of “double extortion”—where data is both stolen and encrypted or threatened with release—has become a hallmark of modern cybercrime. By targeting educational institutions, which often hold vast amounts of personal data but may have varying levels of cybersecurity budgets, these groups find high-leverage targets.
Mitigating Future Risks
While Instructure has restored access to Canvas, cybersecurity experts warn that the danger does not end when the software comes back online. The stolen “identifying information”—names and institutional emails—provides a roadmap for future, more targeted attacks. When hackers possess a student’s ID and their professor’s email, they can craft highly convincing phishing emails that appear legitimate, potentially leading to the theft of actual passwords or financial data.

Students and faculty are encouraged to take the following steps to secure their digital identities:
- Enable Multi-Factor Authentication (MFA): Ensure all university and personal accounts require a second form of verification.
- Scrutinize Unsolicited Emails: Be wary of any message asking for login credentials, even if it appears to come from a university domain.
- Update Passwords: While passwords were not reported stolen in this breach, updating credentials for related accounts is a standard security best practice.
- Report Suspicious Activity: Use official university IT service desks to report any unusual account behavior.
The industry is now looking toward May 12, a deadline previously mentioned by the ShinyHunters group regarding the potential leak of stolen data. University administrators and cybersecurity specialists will be monitoring data dump sites to determine if the extortionists follow through with their threats or if negotiations have reached a resolution.
We invite our readers to share their experiences with campus cybersecurity in the comments below or contact our newsroom with tips.
Related reading
