CSIDB logo
Incident

University of Idaho

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 21:48

Linked entities

Victim
University of Idaho
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack on Instructure, the cloud-based learning management system provider used by multiple higher education institutions, compromised the data of approximately 275 million users across more than 8,000 institutions, including the University of Iowa. The breach, which involved a criminal threat actor, exposed student information such as usernames, email addresses, and enrollment data, though no passwords, dates of birth, government identifiers, or financial information were initially found to be involved. Instructure temporarily shut down its systems at the close of the spring semester, disrupting operations at the affected institutions before ultimately paying the attackers to recover its data and secure a promise against further extortion of its customers. The university was formally notified of its compromised data in early May and later issued a request for qualifications to hire an external firm capable of providing rapid incident response and digital forensic services for future cybersecurity events.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In May 2026, cybercriminals breached the systems of Instructure, the global technology company that owns and operates the Canvas learning management platform, compromising data associated with approximately 275 million Instructure users across more than 8,000 educational institutions. The University of Iowa was among the affected organizations, along with Iowa State University and the Iowa City Community School District, all of which rely on Canvas or Canvas-based systems to support instruction and learning operations. The University of Iowa uses Canvas under the name ICON, having first piloted the platform in 2015 and rolled it out campuswide in 2016. Iowa State University adopted Instructure's services in June 2020 and has since spent approximately $9 million with the supplier, including an additional $432,700.36 on Parchment services following Instructure's February 2024 acquisition of the credential management platform. The University of Iowa has paid Instructure $4.1 million over the past decade and budgeted $451,588 for the 2026 budget year. At the time of the attack, Instructure officials acknowledged the concern caused by the incident and stated that protecting their community remained their top priority. They temporarily shut down their systems in early May, an action that disrupted operations at the close of the spring semester across the affected institutions.

Instructure first notified the University of Iowa of the breach at 4 p.m. on May 5 via email sent to Interim Senior IT Director Dave Long. The notification explained that a criminal threat actor had obtained data associated with the university's account and that, based on findings to date, the data involved appeared to include personal information. The compromised information reportedly included usernames, email addresses, and enrollment information, though Instructure indicated that there was no indication that passwords, dates of birth, government identifiers, or financial information were involved. Following the breach, Instructure negotiated with the attackers and paid a ransom to recover its data. As part of that arrangement, Instructure reportedly received digital confirmation of data return and a commitment that no Instructure customers would be extorted as a result of this incident.

In response to the breach, the University of Iowa began seeking external cybersecurity assistance. On August 24, 2026, the university issued a Request for Quotation to identify a qualified supplier capable of providing incident response and digital forensic services on short notice. The RFQ specified that the awarded supplier must demonstrate the ability to rapidly respond to cybersecurity events affecting university information systems, research environments, health care-related systems, cloud services, operational technology, and third-party hosted services. According to the RFQ, the selected vendor would be required to provide incident response services for both critical-severity and high-severity cybersecurity incidents, including ransomware events, data breach investigations, advanced threat activity, email and identity attacks, cloud security incidents, and other critical infrastructure incidents. Examples of critical-severity incidents include attacks threatening healthcare services, research activities, or causing widespread operational outages, while high-severity incidents involve material data exposure, compromised privileged accounts, or significant business impact. Medium-severity cases were described as suspicious activity without operational impact.

The RFQ outlined a phased incident response methodology. The initial triage phase is to involve assessing severity, establishing an incident command structure, guiding evidence preservation, developing a response strategy, and identifying required stakeholders. The containment phase is to include offering threat containment recommendations, identifying compromised systems, and supporting credential containment. The investigation phase is to encompass forensic acquisition, memory analysis, malware analysis, log analysis, cloud forensic review, email investigation, traffic analysis, threat actor timeline construction, and root cause analysis. Eradication and recovery is to involve eradication recommendations, recovery support, security control implementation, and threat removal. Post-incident activities are to include a debrief and lessons-learned workshop, along with recommended improvements and documentation.

Operational expectations in the RFQ require the successful supplier to provide an initial response to the university within four hours as a service level response time for critical and high-severity cybersecurity incidents, with 24-hour coverage during active incidents. Iowa State University similarly used Canvas and experienced service outages in May stemming from the same cyberattack that affected the University of Iowa. The Iowa City Community School District, also a Canvas user, experienced outages as well. The University of Iowa's pursuit of digital forensic services represents the institution's formal effort to strengthen its cybersecurity posture following the Instructure breach and to ensure preparedness for future incidents that may impact its systems, research environments, or third-party hosted services.

Sources

Sources available to members: 1 source.

CSIDB