Students at some universities, colleges, and K-12 school districts across California — and the nation — are unable to access Canvas, the online learning management platform used for class assignments, tests, and more, amid an apparent large-scale data breach of the platform.
Instructure, the company that manages Canvas, initially reported a cybersecurity incident involving a “criminal threat actor” on May 1. While the company has since taken steps to secure its systems, colleges using Canvas across the nation began reporting that the platform was inaccessible on Thursday, May 7.
The California State University system, which serves more than 470,000 students at 23 campuses across the state, said on Thursday that Canvas was down for all of its users at all campuses and at the CSU Chancellor’s Office, which is headquartered in Long Beach.
“Instructure is working diligently to gather more information and get systems restored,” the CSU wrote on its website. “This situation is fluid, and we are working with Instructure to determine the full scope of impact and will provide updates as soon as they are available.”

This message from an apparent cybercriminal group dubbed “Shiny Hunters” was shown to some CSUN students attempting to access Canvas on Thursday, May 7. (Courtesy photo).

A message from CSUN’s Information Security Officer regarding the ongoing Canvas cyber incident sent to students on Thursday, May 7. (Courtesy photo).
Show Caption
1 of 2
This message from an apparent cybercriminal group dubbed “Shiny Hunters” was shown to some CSUN students attempting to access Canvas on Thursday, May 7. (Courtesy photo).
Instructure, in an incident report log posted on May 6, said that some information potential at risk on account of the security breach includes identifying information including names, email addresses, student ID numbers, and messages between Canvas users.
“At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. If that changes, we will notify any impacted institutions,” the Instructure log said.
Some social media users posted online Thursday, May 7, reporting that their access to Canvas had been blocked — and instead, they were shown messages from the apparent perpetrator of the attack, a group that identified itself as “Shiny Hunters.”
The message, apparently from Shiny Hunters, claims that it will release the data it obtained from affected schools on May 12, 2026, unless Instructure or any of the impacted schools “consult with a cyber advisory firm” and contact Shiny Hunters “privately” to “negotiate a settlement.”
None of the impacted colleges or universities, nor Instructure, have confirmed the identity of the perpetrator of the attack as of around 4 p.m. on Thursday, May 7.
All 116 colleges governed by California Community Colleges — including Long Beach City College, Coast Community College District’s Orange Coast, Goldenwest, and Coastline Colleges, and more — have been impacted, according to California Community Colleges officials.
“Canvas is currently down for the California Community Colleges system. Instructure, the provider of Canvas, is actively working to resolve this most recent security issue,” a Thursday statement from LBCC officials said. “LBCC Information Technology Services, the Chancellor’s Office, and the California Community Colleges Security Center are monitoring this situation and will provide updates when possible.”
California Community Colleges have also advised that some of their Canvas users have reported receiving emails from the hacker group, and advising anyone who has received the email to ignore it.
“The email claims hackers have been monitoring the user’s activity on web browsers and seeks payment in Bitcoin within 48 hours to have any compromising information deleted,” the CCC said on its website. “This is a scam and anyone receiving such a message should delete it immediately. Do not click on any links, open any attachments, download files, or respond.”
Officials from the Rancho Santiago Canyon Community College District advised its Canvas users to reset their passwords if they accessed the platform anytime after 12 p.m. on Thursday, “out of an abundance of caution.”
University of California campuses also appear to be impacted by the cybersecurity incident.
Maryam Qazi, a UC Irvine student studying art history, was in an afternoon class when her professor alerted her to an “issue” with Canvas.
“I tried to open Canvas, but it’s just inaccessible, you just can’t open it,” Qazi said. “The whole campus is going through it. Everyone is talking about it.”
Canvas, Qazi said, is the “crux” of how UCI students get their work done. A portal for submitting assignments, adding discussion posts, taking tests and quizzes and even viewing grades, professor feedback and course syllabi — ”all of that is so specific to Canvas,” Qazi said.
And for UCI students, who operate under the quarter system, “we are just finishing up midterm week, so there’s still stuff needing to be done,” she added.
“I have another paper due this Saturday,” she said, “so even if it’s down for another 24 hours, we are going to have a bunch of problems.”
UC San Diego also issued a statement to its community on Thursday, saying that the cyberattack is impacting users “globally,” and advising users to avoid attempting to access Canvas in any way.
“We recognize that this disruption will affect academic programs. Students should wait for instructions from their instructors on temporary measures for submitting course assignments and accessing materials until this situation can be resolved,” the UCSD statement said. “Updates will be provided to the campus as more information becomes available.”
Long Beach Unified School District, in a statement posted to its website on Thursday, said that it is aware of the cybersecurity incident and has restricted access to Canvas for its students as a result.
“We are closely monitoring this situation and will provide additional information as available,” LBUSD said.
The CSU and California Community Colleges, meanwhile, have established websites to provide updates on the incident.
They can be accessed at lts.calstate.edu/csu-canvas-incident-reports and cccsecuritycenter.org/updates/canvas.php.
This is a breaking story. Check back for updates.