CSIDB logo
Incident

University of North Carolina at Chapel Hill

Incident posture

Attack window
May 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 23:12

Linked entities

Victim
University of North Carolina at Chapel Hill
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2026
Discovered
May 2026
Disclosed
May 2026
Resolved
Pending

Summary

The University of North Carolina at Chapel Hill experienced disruption to its Canvas learning management system after a cyberattack on Instructure, the platform’s parent company, by the hacking group ShinyHunters. The breach triggered a ransomware pop‑up demanding payment to prevent the release of personal data, affecting students, faculty and staff at the university as well as numerous K‑12 districts and other colleges across the state. Officials confirmed that no passwords, birth dates, government identifiers or financial information were believed to be compromised, while they monitored the situation and worked to restore service and assess any impact on academic operations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

Over the weekend of May 2‑3 2026, the cyber extortion group ShinyHunters compromised Instructure, the parent company of the Canvas learning management system, gaining unauthorized access to data belonging to thousands of educational institutions worldwide. On Tuesday May 4, Wake County school officials learned of the breach and, on Wednesday May 5, notified families that personal data of current staff and students may have been accessed, though they noted there was no indication that passwords, dates of birth, government identifiers, or financial information were involved. The following Thursday May 7, students and educators who logged into Canvas encountered a pop‑up message purportedly from ShinyHunters demanding that recipients contact the group by the end of the day May 12 to negotiate a settlement, threatening to leak personal information if the deadline passed. The message included a link that the group claimed showed which schools were affected and reiterated the May 12 deadline for users to respond.

In response to the ransom demand, the Wake County school system announced on Thursday May 7 that it was temporarily disabling access to Canvas and advised users not to log in, click any links, download files, or reply to the pop‑up messages. Duke University’s chief information security officer confirmed that Duke had been notified by Canvas of a cybersecurity incident resulting in unauthorized access to data from thousands of institutions, including Duke, and stated that the university’s IT Security Office was monitoring the situation and assessing any impact on the community. The University of North Carolina at Chapel Hill reported that Canvas was unavailable due to a system outage caused by the Instructure cybersecurity incident, which affected approximately 9,000 universities and schools nationwide; UNC noted that spring semester finals had concluded on Thursday May 7, so there was no immediate impact on exams, but the office was analyzing how the outage might affect grade submissions due Monday May 11 and pledged to provide updates as more information became available. Both Duke and UNC emphasized that, according to notifications from Instructure, there was no evidence that passwords, dates of birth, government identifiers, or financial data had been compromised in the breach.

Throughout the incident, the IT security teams at Duke and UNC continued to monitor developments and await further details from Instructure regarding the scope of the data exposure and any potential mitigation steps. The ransom note’s demand for a settlement by May 12 created a limited window for affected institutions to decide whether to engage with the attackers, while the affected school districts and universities focused on maintaining operational continuity and communicating transparently with students, faculty, and staff. As of the article’s publication on May 8 2026, no further details about the attackers’ identity beyond the ShinyHunters attribution, the exact volume of data exfiltrated, or any subsequent actions taken by the threat group had been disclosed. The situation remained under active review by the involved institutions’ security offices.

Sources

Sources available to members: 1 source.

CSIDB