Canvas Data Breach Disrupts Major Canadian Universities
- By Tahani Elghazaly
- Published
Major Canadian universities are dealing with the fallout from a cybersecurity incident involving Canvas, a widely used learning management platform for coursework, assignments, grades, and communication between students and faculty.
The incident is linked to Instructure, the company behind Canvas, rather than separate attacks on individual universities. Instructure said the incident involved unauthorized access to part of its environment, with data fields such as usernames, email addresses, course names, enrollment information, and messages potentially involved. The company said core learning data, including course content, submissions, and credentials, was not compromised based on its current findings.
In Canada, Global News reported that institutions including the University of Toronto, the University of British Columbia, and the University of Alberta were affected by the fallout, along with Simon Fraser University and OCAD University. The University of Toronto took Quercus, its Canvas-based learning platform, offline as a precaution and said there was no current evidence that other university systems or assets had been compromised.
Instructure says Canvas is now fully operational again and that it is working with CrowdStrike to support its forensic analysis. The company has also brought in another specialist vendor to review the affected data, while warning that the full review could take weeks before institutions receive more specific findings.
The incident is especially sensitive because Canvas is not only used to post course materials. It can also hold enrollment details, academic messages, and other information connected to students’ daily academic lives. OCAD University warned students, faculty, and staff to watch for phishing messages claiming to come from Canvas, Instructure, or the university, especially messages asking users to click links, re-enter passwords, or provide personal information.
While Instructure says it has not found evidence so far that passwords, financial information, or government-issued identification were compromised, the practical risk remains serious. Names, emails, course information, and internal messages can be enough to make phishing attempts more convincing and harder for students and staff to detect.
The breach raises broader questions about how much post-secondary education now depends on centralized digital platforms that hold large amounts of academic and personal data. For now, students and staff are being urged to follow official university updates, avoid suspicious links, and never share passwords or personal information through email or text messages.
You May Also Like
Authors
-
Tahani Elghazaly5098 Posts
Popular Posts
Newsletter
Subscribe to our mailing list to get the new updates!