California Community Colleges
Incident posture
Linked entities
- Victim
- California Community Colleges
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A cyberattack on the Canvas learning management system by the group ShinyHunters disrupted online instruction for the California Community Colleges, University of California, California State University and K-12 schools, locking users out of lectures, exams and assignment submissions. The breach exposed emails, student identification numbers and internal Canvas messages while leaving Social Security numbers, financial data and passwords unaffected, and the attackers demanded a settlement to prevent the release of the compromised information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On May 1, 2026, Instructure notified schools of a problem with the Canvas learning management system. By Thursday, the intrusion had become entrenched, preventing users who refreshed their login from regaining access. On Friday, May 8, the cyberattack entered its second day, locking thousands of students across California out of online lectures, exams, and assignment submissions. The disruption affected the University of California, California State University, the state’s 116 community colleges, and K‑12 schools, compromising emails, student identification numbers, and internal Canvas messages while leaving Social Security numbers, financial information, and passwords untouched. Attackers identifying themselves as “ShinyHunters” posted a message demanding a settlement and threatening to release personal data unless contacted by May 12.
Students described immediate academic hardship; a UC Berkeley computer science major said the inability to access assignments was stressful chiefly because of fear that personal information would be leaked. A graduate student in museum studies at San Francisco State could not submit a year‑end project documentation due Friday, jeopardizing graduation less than two weeks away. A UC Berkeley graduate student instructor noted that creating a Google Drive for study materials was useless without a way to mass‑email the link to students, forcing her to email individuals and ask them to share with peers. A microbiology student at UC Berkeley said the timing during “Dead Week” caused widespread panic as finals approached. The attackers’ on‑screen message warned that schools interested in preventing data release should consult a cyber advisory firm and contact them privately to negotiate a settlement.
In response, the California State University system announced that Canvas services were back online but that, out of caution, it had not yet fully reintegrated campus systems or data connections with the platform. The statewide community college system took a similarly gradual approach, with the chancellor’s office advising colleges to remain alert to potential phishing or scam attempts. The University of California characterized the breach as contained and remediated, stating that it was making risk‑based decisions about re‑opening Canvas and that by 2 p.m. UC Berkeley’s notice indicated Canvas had largely been restored and final exams would proceed as scheduled. Neither UC nor CSU publicly confirmed whether they had paid the ransom demanded by ShinyHunters. Throughout the incident, officials emphasized the operational disruption caused by reliance on a centralized platform during a critical academic period.
Sources
Sources available to members: 1 source.