An infamous cyber gang has given U.S. colleges and universities until May 12 to either pay a ransom or face the leak of troves of sensitive information – including billions of private messages between students and their instructors – that the group hacked from the widely-used Canvas learning management system.
The breach impacted nearly 9,000 educational institutions worldwide, spanning both K-12 and higher education across the globe. Nir Kshetri, a business professor and cybercrime expert at the University of North Carolina at Greensboro, told The EDU Ledger, “Since the attack involves sensitive data, some might pay."
Here are five key things to know about the attack, which disrupted final exams, instruction, and coursework at scores of institutions of higher education in the U.S. and around the world just as they were trying to wind down the 2025-2026 academic year.
#1. The breach affected institutions that use Canvas
Canvas is a widely-used learning management system that is run by Instructure, a company that boasts of being the “O.G. champions of open edtech.”
Edutechnica reported in May 2025 that Canvas has the highest share of the learning management system market in the U.S.
“Thirty million users — including at half of the higher education institutions in North America — rely on Canvas to manage courses, submit assignments, view grades and facilitate communication,” observes NPR, citing information from Instructure.
















