Updated May 9, 2026 at 6:30 p.m.
There is no indication that the cyberattack by ShinyHunters compromised any Northeastern-affiliated Canvas account information thus far, university security officials reported.
“At this time, Northeastern hasn’t observed compromised university accounts or activity outside of what Instructure has publicly shared, and details related to Canvas itself remain part of the vendor’s investigation,” said Jen Brant‑Gargan, Northeastern’s chief information officer, in an article published by Northeastern Global News, or NGN, the university-run media outlet.
The university also announced May 8 at around 10:50 p.m. that Canvas services have been “re-enabled” following the widespread cybersecurity breach affecting Instructure, Canvas’s parent company, according to a May 8 email sent by the Office of the Provost. Instructure
“Northeastern IT teams will continue to monitor and engage with the vendor Instructure. As the platform continues to stabilize, intermittent service disruptions may occur,” the May 8 email reads.
The NGN article said the university learned about the ransom attack against Instructure “about a week ago.” In response, Northeastern disconnected Canvas from its “single sign-on integration” system, the authentication mechanism that allows users to access multiple applications with their university credentials.
The university said it monitored Canvas for “anomalous activity” such as “spikes in log in attempts or unusual log in behavior” to identify if the cyberattack compromised any university credentials.
Previously, the group ShinyHunters has claimed responsibility for attacks against other education technology platforms, including Infinite Campus, McGraw-Hill, and Salesforce, which works with Instructure. Most notably, the group breached Ticketaster in 2024, claiming it stole the details of 560 million customers.
“The university is still conducting its own review of the incident alongside Instructure and third-party forensic responders,” the NGN report reads.
It is unclear how much ransom ShinyHunters is demanding. Engin Kirda, a Northeastern professor of computer science and engineering, told NGN that “these attacks can be extremely profitable.”
The cyberattack impacted around 9,000 universities, colleges and K-12 schools across the U.S and occurred amid finals season for several institutions. The University of Illinois at Urbana-Champaign suspended final exams and Arizona State University canceled all final exams scheduled for Canvas on Friday and Saturday, according to an Inside Higher Ed report.
Updated May 7, 2026 at 10 p.m.
On Thursday afternoon, a cyberattack on Instructure locked Northeastern students out of Canvas, the university’s online platform for class assignments. Northeastern is among roughly 9,000 universities hacked by the criminal extortion group ShinyHunters, according to an Inside Higher Ed report.
“ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some ‘security patches,’” a message that appeared on Canvas reads. “If any of the schools in the affected list are interested in preventing the release of the data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.”
The message said Instructure has until May 12 to pay the ransom or “everything is leaked.” The ransom amount is unclear.
ShinyHunters claims the attack compromised the personal information of approximately 275 million people, including students, faculty and staff, across K-12 institutions, colleges and universities in the U.S., according to Inside Higher Ed.
The breach occurred just before the start of Northeastern’s summer class sessions, which began May 6. At around 7:20 p.m., the Office of the Provost sent an email to the university community about the outage.
“The university is developing continuity guidance for faculty to ensure teaching and learning can continue if the disruption is prolonged,” the email reads. “In the short term, faculty members should continue teaching courses and work to maintain educational continuity without Canvas.”
The university directed The Huntington News to the Office of the Provost’s announcement.
More than 40% of colleges and universities use Canvas to post learning materials such as assignments, course syllabi and quizzes, as well as post grades, according to Inside Higher Ed.
The attack on Instructure is not the first time ShinyHunters has preyed on an education-technology platform. Last fall, hackers affiliated with the group breached the customer relationship management platform Salesforce, stealing roughly 1 billion records from dozens of companies, including Instructure.
More recently, ShinyHunters claimed responsibility for hacking Infinite Campus, a K-12 information system designed to store, track and manage student data. In April, ShinyHunters claimed credit for breaching McGraw-Hill, an education resource company.
This story is developing.


