Menu
Browse

Cyber Incident Victim: Duke University

Date:

May 2026

Location:

United States of America

Summary

Duke University was notified by Canvas of a cybersecurity incident involving unauthorized access to its learning management system. The breach, attributed to the hacking group ShinyHunters, exposed names, email addresses, student ID numbers and private messages while passwords, dates of birth, government identifiers and financial information remained unaffected. Canvas experienced an outage and displayed ransom notes demanding contact to negotiate a settlement, prompting the university to monitor the situation and advise users to avoid interacting with the messages. Instructure revoked the unauthorized party's access, brought in forensic experts and temporarily disabled Free-For-Teacher accounts to contain the activity.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

Instructure detected unauthorized activity in the Canvas learning management system on April 29 2026 and immediately revoked the intruder’s access, launched an investigation and engaged outside forensic experts. On May 7 2026 the company identified additional unauthorized activity linked to the same incident and observed that the attacker had modified pages displayed to some users logged into Canvas. As a precaution, Instructure placed Canvas into maintenance mode, temporarily taking the platform offline to contain the activity, apply safeguards and conduct further analysis. The outage coincided with finals week, affecting students and instructors at institutions that rely on Canvas for assignments, grades, messages and exam instructions. Among the schools reporting access problems were Harvard, the University of Pennsylvania, Duke University, UCLA and the University of Nebraska.

Cyber Incident Image

The unauthorized actor exploited a vulnerability associated with Free‑For‑Teacher accounts, prompting Instructure to temporarily shut down those accounts while restoring general Canvas access. A hacking group called ShinyHunters claimed responsibility for the breach and posted a ransom note that appeared as a pop‑up message for users who logged into Canvas on May 7, demanding contact by the end of May 12 2026 to negotiate a settlement or face public leakage of personal data. The message stated that names, email addresses, student ID numbers and private messages could be exposed, but Instructure said it found no evidence that passwords, dates of birth, government identifiers or financial information were compromised. Duke University’s chief information security officer confirmed that the university had been notified by Canvas of the unauthorized access affecting thousands of institutions, including Duke, and that its IT Security Office was monitoring the incident with no indication of compromised passwords or financial data. Wake County schools issued similar statements, advising families not to respond to the ransom pop‑up and noting that personal data of staff and students may have been accessed without evidence of password or financial data theft.

Instructure later reported that Canvas was fully back online, though Free‑For‑Teacher accounts remained temporarily disabled. The company said it had revoked compromised credentials, deployed additional protections and enhanced monitoring to prevent further unauthorized activity. Affected institutions, including Duke and the University of North Carolina‑Chapel Hill, continued to assess any impact on grade submissions and other academic processes, with some universities rescheduling exams originally planned for May 8 to later dates. The incident remained under active review by the affected organizations’ security teams, which pledged to provide updates as new information became available. No further details about attacker motives, payment demands or potential data leakage beyond the stated scope were disclosed in the available sources.

Sources
Sources available to members
3 sources