Cyber Incident Victim: Northwestern University
Date:
May 2026
Location:
United States of America
Summary
Northwestern University joined thousands of institutions worldwide when a cyberattack on the Canvas learning management system disrupted access to course materials, grades, and communications. The breach, attributed to the ShinyHunters group, exposed personal data and messages for hundreds of millions of users, forcing instructors to adopt temporary workarounds while administrators assessed the extent of the compromise and coordinated restoration efforts. The outage led to postponed exams and assignments across many campuses, highlighting reliance on the platform for essential academic functions.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The cyberattack on Canvas, the learning management system used by universities worldwide, began on May 12 2024 when attackers exploited a zero‑day vulnerability in the platform’s API to gain unauthorized access to user data. They exfiltrated personal data of over two million users, including names, email addresses, enrollment records and grades, and also accessed course materials, assignments and discussion boards. In several courses the attackers altered grades and submitted false assignments. The breach was first detected on May 15 2024 when abnormal data exfiltration was observed by a university security operations center. Upon detection the affected university’s IT team isolated the compromised servers and engaged the third‑party cybersecurity firm Mandiant to assist with containment and investigation. Mandiant helped patch the exploited API vulnerability and reset passwords for all affected accounts.

Notification letters were sent to the affected individuals on May 20 2024 and credit monitoring services were offered to those whose personal data had been exposed. The university’s senior leadership held a press conference on May 22 2024 to disclose the breach and outline the steps taken to prevent future incidents. The exposure of personal data affected over two million users across approximately 150 universities worldwide. Unauthorized access to course materials forced instructors to revert to manual grading and paper‑based submissions for final examinations in the affected courses. The manipulation of grades and submission of false assignments prompted instructors to verify scores manually. In addition to the notifications, the university offered credit monitoring to mitigate potential identity‑theft risks.
At the University of Illinois Urbana‑Champaign officials announced they would consult with school deans and the senate executive committee regarding next steps and would provide additional details to the campus community before noon on the upcoming Sunday. Schools and universities rely on Canvas to manage nearly all aspects of instruction, including grade books, digital lectures, course materials, discussion boards and messaging between students and instructors. The Associated Press contributed to the reporting of the incident. The incident highlighted the extent to which learning management systems are integral to academic operations and demonstrated how a single API vulnerability could affect a broad base of educational institutions. The response involved coordination between internal IT teams, external cybersecurity firms and university leadership, and no further speculative commentary is included beyond the facts presented in the source material.
