BitDepthFeatured

What the Canvas hack tells us about higher education software

7 Mins read
  • • UTT experienced a temporary LMS outage and deferred academic activities as a precautionary measure following the breach.
  • • Matt Pittinsky's return could position Blackboard as a strong alternative to Canvas
  • • Instructure prioritized PR over the security and trust of its customers, failing to address the impact of the breach

Above: Illustration by wafi99d/DepositPhotos

BitDepth 1563 for May 18, 2026

On April 29, according to a statement on the website of Instructure, the creators and hosts of the Canvas Learning Management System (LMS), the company became aware of a cybersecurity incident.

Instructure made an initial statement about it on May 02.
“Instructure recently experienced a cybersecurity incident perpetrated by a criminal threat actor,” Steve Proud, Chief Information Security Officer wrote.
“We are actively investigating this incident with the help of outside forensics experts.”

On May 06, Proud updated his notification: “While our investigation continues alongside our outside forensics experts, at this stage we believe the incident has been contained.”

“Here are the steps we have taken since we became aware of the incident. We have:
– Revoked privileged credentials and access tokens associated with affected systems
– Deployed patches to enhance system security
– Out of an abundance of caution, we rotated certain keys, even though there is no evidence they were misused
Implemented increased monitoring across all platforms.”

On May 06, Proud issued what was described as the company’s “final statement” on the matter.
“Canvas is fully operational, and we are not seeing any ongoing unauthorized activity. As a precaution, we recommend customers follow security best practices, including enforcing MFA on privileged accounts, reviewing admin access, and rotating API tokens or keys where applicable.”

On May 07, the proverbial poop hit the fan.

A ransomware group, ShinyHunters, posted a hack notice on Canvas systems pointing out the pappyshow of a full week’s worth of empty promises by Instructure: “ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some security patches”

The graphic notifying Canvas users of the hack invited schools to review an online list of affected institutions and to make their own arrangements to pay a ransomware fee.
The deadline? May 12, 2026.

Instructure immediately shut down Canvas globally.

Canvas, which delivers an end-to-end hosting service, is used by half of all colleges and universities in North America.

Instructure CEO Steve Daly, ShinyHunter’s System Hack message.

ShinyHunters claimed to have accessed, in a 3.6 terabyte exfiltration, data affecting a wide swath of the 275 million users whose data has been captured by the platform (30 million are active users) and 9,000 schools that use the LMS globally.

Instructure’s response to the issue was unusually lax, particularly given that they had been targeted by ShinyHunters in 2025 when their SalesForce service was attacked.

On May 11, company CEO Steve Daly issued the following statement.
“We know that concerns about the potential publication of data related to this incident remain top of mind for many customers. We understand how unsettling situations like this can be, and protecting our community remains our top priority.”

“With that responsibility in mind, Instructure reached an agreement with the unauthorized actor involved in this incident. As part of that agreement:
The data was returned to us.
We received digital confirmation of data destruction (shred logs).
We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.
This agreement covers all impacted Instructure customers, and there is no need for individual customers to attempt to engage with the unauthorized actor.”

Instructure has not revealed what the size of the ransomware demand was nor how much was paid to secure this outcome.

It should be noted that ultimately, Instructure is depending, as does anyone dealing with a ransomware group, on the honesty of thieves and terrorists.

How do these issues affect Trinidad and Tobago, or more specifically, the University of Trinidad and Tobago (UTT) which was affected by a brief outage of Canvas services and deferred activities requiring the service for a week?

In response to questions, UTT’s Senior Manager, Corporate Communications, Sandra Ganness, responded that, “Canvas by Instructure is used by UTT as its Learning Management System (LMS).”

“UTT does not use Canvas as its primary authentication platform. User authentication is managed through the University’s Single Sign-On (SSO) environment, where multi-factor authentication (MFA) is enforced for institutional access.”

“The University also maintains established cybersecurity controls and continuously reviews its digital systems and security practices in keeping with operational and academic requirements.”

“The selection of a Learning Management System is based on a range of factors including teaching and learning requirements, scalability, support, reliability, cybersecurity considerations, integration capabilities, and total cost of ownership.”

“UTT adopted Canvas following a formal institutional review process and after previously utilizing Blackboard. Moodle was evaluated during earlier reviews but was not selected at that time based on the University’s operational requirements.”

“Like many modern universities, UTT utilizes a combination of internally developed systems and established external platforms, depending on the nature, complexity, support requirements and strategic importance of the service being delivered.”

A section of Moodle’s extensive collection of plug-ins

I’m familiar with BlackBoard’s Collaborate, having taught using the platform for the two years of covid-19 lockdowns. UTT’s decision to drop Blackboard was mirrored by UWI’s St Augustine campus soon after the return to in-person teaching.

Higher education software is an unusual proposition that demands flexibility and agility in development to meet education needs that are more dynamic today than at any time in the last century.

Blackboard hit its inflection point relative to Canvas in the first quarter of 2019, when uptake of Canvas overtook declining use of Blackboard’s LMS.
The open-source solution, Moodle, continues to be an option, but Canvas now boasts more active users than its three closest competitors combined.

It is the gorilla in the room of higher education software and that beast has now been shown to be careless, having taken inadequate mediation and attack surface hardening after the 2025 incident and seems vulnerable, having paid for a likely cosplay of data destruction.

In the wake of the 2024 PowerSchool breach, that company paid a ransom, but that didn’t stop ransomware demands continuing as schools which used the Student Information System continued to receive threats to release their specific information.

The trove of user information from Canvas, is likely to be turned to use as a resource for improving the quality of phishing emails and used to power next level scams that make use of the names, emails and student-teacher messages that are believed to form the corpus of the exfiltrated data.

There are good reasons why law enforcement and cybersecurity professionals advise against trying to strike deals with criminals.

UTT’s stated response to the impact of the breach was: “The direct operational impact experienced by UTT was a temporary interruption in LMS availability for approximately four hours.”

“Although service was subsequently restored, the University took the precautionary decision to defer LMS-related academic activities scheduled for that day by one week to minimize disruption to students and faculty.”

“Relevant updates have been communicated through established internal channels and the University will continue to provide further information as appropriate.”

“UTT continuously reviews and strengthens its technology environment as part of its established governance and risk management processes. Independent of this incident, the University had already initiated a review for its Learning Management System through the Centre for Teaching, Learning and Instructional Support (TLIS).”

“That process remains ongoing. The University will continue to assess both internal and external technology solutions to ensure that systems supporting teaching and learning remain secure, reliable and aligned with institutional requirements.”

Blackboard, which has been in decline for years after its acquisition by Anthology has fought its way back from 14 months in Chapter 11 bankruptcy as a reset organisation with US$70 million in financing and a mandate to completely reassess its position in the higher education software market.

LMS Market share, 2016-2025, chart courtesy edutechnica

Matt Pittinsky, a co-founder of Blackboard went on to lead Parchment, an academic credentials management company, which was bought by Instructure in October 2023, placing him on the company’s board.

Pittinsky will take up his role at the rejuvenated Blackboard after a non-compete cooling off period. Phil Hill, who writes on Ed Tech, describes the whole dance that led to Blackboard’s return to competition.

Pittinsky would be crazy not to position the reemergent Blackboard as an alternative to Canvas staking the ground that Instructure has showed little interest in defending. His first mission will be to move Blackboard from legacy-product-in-decline status to becoming a contender in the space again.

Moodle, apart from being open-source, is also self-hosted and is starting to look like a viable contender to some universities stung by the data breach. The University of British Columbia deployed the open source software as a backup and alternative to Canvas in the wake of the breach, but switching would be a multi-year, wrenching prospect.

The formal public response of the 16-year-old company to two consecutive breaches of its infrastructure was, demonstrably, that of a cybersecurity neophyte with no real feel for its real-world responsibility to the education community it has so successfully courted.

The “deal” will probably stop dark web publication of the data cache that ShinyHunters exfiltrated, but only a fool would proceed as if that data was actually destroyed.

Instructure has handled the entire incident, beginning with its first understanding of a vulnerability on April 29, like a software vendor trying to manage a hack and fumbling it badly.

But the company is managing a very different proposition than most software vendors do. It has positioned itself as an education partner, managing a wide range of integrations with education software tools, presenting its services as a seamless integration of pedagogy and digital engagement.

When students found themselves locked out of their educational software during an exam week, when the company suffered the most extensive ransomware hack of an education software system on record, it chose a very different voice. It fell back on service provider speak.

To date, Instructure has not explained the details of its “deal” with ShinyHunters. It has offered only platitudes to its customers, discussing the issue in the vaguest possible terms while its cybersecurity was clearly in a state of major compromise, wasting fragile trust on counterclaims about the size of the exfiltration while demonstrating little affinity for the reality of schools locked out of the virtual backbone of their teaching systems.

Instructure has been good about parroting all the current doublespeak about the future of education, but when it counted, the company was mute about the integrity of the systems it asked millions of students to trust.

What the Canvas hack tells us about higher education software

What the Canvas hack tells us about higher education software

Instructure is managing a very different proposition than most software vendors do. It has positioned itself as an education partner managing a wide range of integrations with education software tools.
Read More
Ghost women in AI? Hardly!

Ghost women in AI? Hardly!

"When I first came out of university a million years ago, everybody was like, why build something here? Just take what's in Europe, lift and shift. That has been the...
Read More
IShowSpeed: Here and gone

IShowSpeed: Here and gone

Watkins has 53 million subscribers on YouTube and his Trinidad and Tobago visit alone clocked 4.8 million views for a five hour and 47 minute stream.
Read More
How TT journalists can turn modern media realities to advantage

How TT journalists can turn modern media realities to advantage

The faceless, anonymized journalist adhering to a house style holds little value for this next generation audience.
Read More
Reuters report on young news readers holds no surprises

Reuters report on young news readers holds no surprises

The critical 18-34 age group recorded a decline in enthusiasm for daily news from 79 percent in 2017 to 64 percent in 2025
Read More
The state of ransomware in the Caribbean

The state of ransomware in the Caribbean

The report counted 21 confirmed dumps of information to the dark web, but Parasram estimates that twice that number were breached.
Read More
Digital döstädning

Digital döstädning

You may not care after you're gone, but a computer desktop littered with file icons is nobody's idea of a good time.
Read More
The garbage infesting my in-box

The garbage infesting my in-box

Do not click on links before fully investigating them. Do not call given phone numbers.
Read More
TSTT’s payments problem (updated)

TSTT’s payments problem (updated)

Something seems to have collapsed in what should be an efficient, all-digital payment and verification loop.
Read More
Is Apple’s Neo the One?

Is Apple’s Neo the One?

Ease of repair puts a firm hand on the scale in favour of the Neo for parents looking for a laptop suitable for use in education.
Read More
Privacy and your travel information

Privacy and your travel information

A privacy notice to let individuals understand what data is being collected, the legal reasons, retention period, security to protect data and a contact for any questions should have been...
Read More
TATT announces ambitious three-year strategic plan

TATT announces ambitious three-year strategic plan

The authority's two-decade-old arguments for a fee from over-the-top (OTT) providers has consistently drawn a blank, but it remains on the strategic agenda.
Read More
Samsung’s S26 leans in hard on AI

Samsung’s S26 leans in hard on AI

Some users including those with data that requires above average security, may not greet these agentic AI advancements with enthusiasm.
Read More
A 2026 manifesto for Carnival

A 2026 manifesto for Carnival

The idea of Carnival, the spark of the individual, rebellious, expressed as boldly inventive creation still catches fire.
Read More
A hiss from a rose

A hiss from a rose

There is likely to be a need for sex re-education to deprogram children who see sex as a wrestling match.
Read More
News is a niche until it’s not

News is a niche until it’s not

The New York Times produced approximately 230 pieces of content per day on average; The Washington Post, more than 500 per day in 2016
Read More
FT’s second Next Gen News report offers deeper insights

FT’s second Next Gen News report offers deeper insights

Successful producers are reversing the journalism process, dismantling the inverted pyramid of news structure
Read More
Ransomware report notes fourth quarter 2025 attack surge

Ransomware report notes fourth quarter 2025 attack surge

"The year 2026 will likely see continued convergence of criminal innovation and AI capabilities, demanding that defenders adopt equally sophisticated technologies and intelligence-led approaches."
Read More
Hands-on with Apple’s Creator Studio as a non-subscriber

Hands-on with Apple’s Creator Studio as a non-subscriber

It’s not hard to imagine someone in a hurry clicking madly along only to find themselves a subscriber through haste.
Read More
Apple flirts with subscription software

Apple flirts with subscription software

Are we all being coaxed and tranquilized into accepting as a norm, the idea that the computing tools we pay for are not things we own anymore?
Read More
What the Canvas hack tells us about higher education software What the Canvas hack tells us...
Ghost women in AI? Hardly! Ghost women in AI? Hardly!
IShowSpeed: Here and gone IShowSpeed: Here and gone
How TT journalists can turn modern media realities to advantage How TT journalists can turn modern...
Reuters report on young news readers holds no surprises Reuters report on young news readers...
The state of ransomware in the Caribbean The state of ransomware in the...
Digital döstädning Digital döstädning
The garbage infesting my in-box The garbage infesting my in-box
TSTT’s payments problem (updated) TSTT’s payments problem (updated)
Is Apple’s Neo the One? Is Apple’s Neo the One?
Privacy and your travel information Privacy and your travel information
TATT announces ambitious three-year strategic plan TATT announces ambitious three-year strategic plan
Samsung’s S26 leans in hard on AI Samsung’s S26 leans in hard on...
A 2026 manifesto for Carnival A 2026 manifesto for Carnival
A hiss from a rose A hiss from a rose
News is a niche until it’s not News is a niche until it’s...
FT’s second Next Gen News report offers deeper insights FT’s second Next Gen News report...
Ransomware report notes fourth quarter 2025 attack surge Ransomware report notes fourth quarter 2025...
Hands-on with Apple’s Creator Studio as a non-subscriber Hands-on with Apple’s Creator Studio as...
Apple flirts with subscription software Apple flirts with subscription software

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Possible UI Glitch. Click top right corner to dismiss 👉

Get Connected!

A once weekly email notification of new stories on TechNewsTT.

Just that. No spam.

Related posts
BitDepthFeatured

The state of ransomware in the Caribbean

4 Mins read
The report counted 21 confirmed dumps of information to the dark web, but Parasram estimates that twice that number were breached.
BitDepthFeatured

Ransomware report notes fourth quarter 2025 attack surge

4 Mins read
“The year 2026 will likely see continued convergence of criminal innovation and AI capabilities, demanding that defenders adopt equally sophisticated technologies and intelligence-led approaches.”
BitDepthFeatured

Cyberedge reports on cybersecurity trends

3 Mins read
Mobile and web application vulnerabilities affect 90.9 per cent of respondents in the 2025 report and these weaknesses are contributing to the areas of greatest cybersecurity concern.
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
×
BitDepthFeatured

The state of ransomware in the Caribbean

0
Share your perspective in the comments!x
()
x