Escambia County Public Schools
Incident posture
Linked entities
- Victim
- Escambia County Public Schools
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Escambia County Public Schools was among several institutions affected by a cybersecurity breach of the Canvas learning management system claimed by the hacking group ShinyHunters. The breach exposed names, email addresses, student identification numbers and internal Canvas messages while passwords, dates of birth, social security numbers and financial data remained uncompromised. In response, Instructure disabled certain Canvas components, temporarily shut down Free‑For‑Teacher accounts, revoked privileged credentials and tokens, added monitoring and platform protections, and restored service after implementing mitigations. Other impacted entities included Santa Rosa County School District, Pensacola Christian College, Northwest Florida State College and the Escambia County Sheriff's Office, all of which reported taking precautionary measures and monitoring the situation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On May 7, 2026, Santa Rosa County District Schools confirmed that it had been involved in the cyberattack on the Canvas platform, and on May 8 the platform was reported to have come back online around 8 a.m. CT according to Pensacola State College. Escambia County Public Schools was notified about the recent cyberattack and Instructure assured the district that it was actively addressing the issue. While Canvas remained operational, some components were disabled as a precautionary measure, and instructional staff were given access to several immediate instructional alternatives to mitigate any disruption to the educational process. The Escambia County Sheriff’s Office spokesperson stated that the office only uses Canvas for scoring its training modules and that its IT team was reviewing all related systems to ensure they were clear. Pensacola Christian College confirmed that the Canvas hack stemmed from an external vulnerability and that none of its internal student information had been impacted, noting that its network security teams continued to monitor the situation and remained in communication with Canvas. Northwest Florida State College was listed among the affected entities, though no further details about its specific experience were provided in the source material. Pensacola State College indicated that it was monitoring the situation and had found no indications that its own systems had been breached.
Instructure reported that the hacking group ShinyHunters claimed responsibility for the breach and that the attackers could have potentially accessed names, email addresses, student identification numbers, and Canvas messages and communications. The company emphasized that there was no indication that passwords, dates of birth, social security numbers, or financial information had been accessed. Instructure’s internal review found no evidence of unauthorized access, and it identified the underlying issue as being tied to Free‑For‑Teacher accounts, which it temporarily shut down to remove the access path used by the attacker. As part of its response, Instructure revoked privileged credentials and access tokens linked to the affected systems, deployed additional platform protections, rotated internal keys, restricted token creation pathways, and added monitoring across its platforms. The company stated that it would continue to monitor the situation closely while the investigation remained ongoing. Escambia County Public Schools’ public information officer noted that the district remained dedicated to safeguarding all student and staff information and would continue to provide updates as further information became available from Instructure.
Pensacola Christian College’s chief communications officer said that the college’s network security teams continued to monitor the situation closely, remained in communication with Canvas, and were taking proactive steps to maintain secure infrastructure and protect institutional systems while the vendor pursued its investigation and response efforts. The Escambia County Sheriff’s Office spokesperson added that its IT team was conducting a thorough review to confirm that no residual risk remained from the Canvas breach. Pensacola State College indicated that instructors were aware of the disruption and would provide guidance regarding any necessary deadline extensions or adjustments to accommodate the temporary platform changes. Throughout the incident, the affected institutions communicated their actions and status updates to their respective communities, focusing on factual reporting of the breach’s scope, the steps taken by the vendor, and the precautions implemented locally.
Sources
Sources available to members: 1 source.