Wake County school system
Incident posture
Linked entities
- Victim
- Wake County school system
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
The Wake County school system temporarily disabled access to the Canvas learning management system after users encountered a ransomware pop‑up demanding contact with the ShinyHunters group following a breach of Instructure. The breach, which also affected Duke University, UNC‑Chapel Hill and thousands of other schools, exposed personal information of staff and students though no passwords, birth dates, government IDs or financial data were reportedly compromised. Officials warned against clicking links or responding to the message while they monitored the situation and coordinated with Instructure and law enforcement.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Tuesday, Wake County school system learned of a data breach involving Instructure, the parent company of the Canvas learning management system, and notified families on Wednesday that personal data of current staff and students may have been accessed, though there was no indication that passwords, dates of birth, government identifiers, or financial information were involved. Over the weekend, Instructure was hacked by ShinyHunters, a criminal extortion group that had previously been linked to data breaches at three Ivy League institutions in late 2025. On May 7, 2026, students and educators who logged into Canvas received a pop‑up message purportedly from the hacking group ShinyHunters demanding that they contact the group to “negotiate a settlement” and warning that personal information would be exposed publicly if they did not comply by May 12. The message claimed that ShinyHunters had breached Instructure again, included a link purporting to show affected schools, and gave users until the end of the day on May 12 to make contact.
In response, Wake County school system announced on Thursday that it was temporarily shutting off access to Canvas and urged users not to log into the system, click any links, download files, or respond to the ransom threat. The pop‑up message was seen by at least some Wake users who accessed Canvas on Thursday, reinforcing the deadline and the claim that Instructure had until May 12 to pay a ransom. Similar ransomware demands were reported at Duke University and the University of North Carolina at Chapel Hill, where Canvas was also unavailable due to the same Instructure outage affecting thousands of institutions nationwide.
Instructure confirmed that Canvas was down because of a cybersecurity incident and stated that its investigation had found no indication that passwords, dates of birth, government identifiers, or financial information were compromised. Duke’s chief information security officer, Nick Tripp, said the university had been notified of unauthorized access to Canvas data from thousands of institutions, including Duke, and that its IT Security Office continued to monitor the situation and would provide updates as new information became available. UNC‑Chapel Hill noted that the Canvas outage did not affect spring semester finals, which had concluded on Thursday, but that the office was analyzing potential impacts on grade submissions due Monday, May 11 and would share further information with faculty and students as it became known.
Sources
Sources available to members: 1 source.