CSIDB logo
Incident

RMIT University

Incident posture

Attack window
May 2026
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 23:24

Linked entities

Victim
RMIT University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
May 2026
Disclosed
May 2026
Resolved
Pending

Summary

RMIT University is among several Australian institutions assessing potential exposure to a cyber incident affecting the Canvas learning management system. The incident, reported by Instructure, involves a criminal third party accessing data associated with some Canvas customer accounts, possibly including personal information and messages stored within the platform, though passwords, dates of birth, government identifiers and financial data are not believed to be compromised. RMIT, along with UTS, TasTAFE and Western Sydney University, is working with the vendor to confirm whether its data was involved and to understand any impacts, while noting that Canvas continues to operate normally within their environments.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On May 2, Instructure notified its customers of a cyber incident affecting its systems. On May 6, the vendor provided further details, stating that a criminal third party was involved. Instructure emphasized that the incident related to its own infrastructure and was not the result of a breach of any participating institution’s systems. Investigations were launched immediately and remain ongoing. Based on current advice, the data that may have been accessed includes some personal information, such as content stored within Canvas like messages. Instructure has not yet identified specific individuals whose data was affected. There is no indication that passwords, dates of birth, government identifiers, or financial information were compromised. A well‑known threat group has claimed responsibility for the attack.

RMIT University issued a brief notice stating it is working with Instructure to confirm whether RMIT data was involved and to understand any impacts resulting from the breach. Similarly, the University of Technology Sydney said it is working with the vendor to determine if UTS data was compromised and to assess potential impacts, while also coordinating with relevant Australian authorities. Western Sydney University reported that it is working with Instructure to examine its potential exposure to the incident. TasTAFE Tasmania provided the most detailed account, noting that the incident impacted data associated with some Canvas customer accounts, including its own. All participating institutions affirmed that Canvas continued to operate normally within their respective environments.

The scope of the data exposure remains limited to unspecified personal information held within Canvas, with no identification of specific individuals at this stage. No evidence has emerged to suggest that sensitive identifiers such as passwords, birth dates, government numbers, or financial details were part of the compromised data. Institutions continue to monitor the situation, maintain communication with the vendor, and follow guidance from authorities as the investigation proceeds. No further details about the attacker’s methods or the exact volume of data accessed have been disclosed in the available reports.

Sources

Sources available to members: 1 source.

CSIDB