TAMPA, Fla. — A major cyberattack involving the popular learning management platform Canvas by Instructure is affecting schools and universities across the Tampa Bay area, and has raised concerns about the security of student and teacher data.
Institutions like Hillsborough County Public Schools, Pinellas County Schools, the University of South Florida and St. Petersburg College widely use the platform.
According to the group claiming responsibility for the breach, around 275 million records tied to students and teachers were stolen during the attack.
The compromised information reportedly includes names, email addresses, student ID numbers and private messages exchanged through Canvas.
Hackers also claim they will release the stolen data unless a ransom is paid by next Tuesday.
While the company says the breach has now been contained, concerns remain over the amount of potentially sensitive information that may have been exposed.
Following notification of the cyberattack, both the University of South Florida and Hillsborough County Public Schools temporarily disabled access to Canvas as a precaution.
Officials emphasized that no Social Security numbers, passwords, or financial information appear to have been stolen. However, thousands of sensitive communications between students, teachers, and parents may have been accessed.
Hillsborough County Public Schools sent out a message to families saying:
“Our district, along with thousands of other schools and universities across the country, has been affected by a cybersecurity incident involving Canvas.
Out of an abundance of caution, we have temporarily inactivated Canvas from all district devices. We also strongly caution you not to access Canvas from a home or personal device or from the app.
We want to stress there is no indication of a new active threat, but we are taking this step to ensure the continued protection for student, family, and staff information.
Our schools and administrators are aware that Canvas has been taken offline, and our Technology and Security teams are actively working with the vendor and are monitoring developments closely.
We understand the importance of Canvas for instruction and communication and will provide updates as more information becomes available and when it is appropriate to safely restore access.”
The district also stated that “no action is required by students, families, or staff. The Hillsborough County Public Schools’ IT Security team is actively engaged in this incident.”
Meanwhile, the University of South Florida acknowledged the disruption during a critical academic period, noting that students are still completing final exams and coursework.
University officials said final grades are not due until May 12 and added that alternative solutions are being explored for affected users.
Instructure representatives say the breach was discovered on May 1, and the company is now working with law enforcement agencies and outside cybersecurity experts as the investigation continues.
The company has not disclosed how long hackers may have had access to its systems before the breach was detected.
This marks the second known cyberattack involving Instructure since last summer, adding to growing concerns about cybersecurity threats targeting educational technology platforms.