Don’t wanna miss anything?
Please subscribe to our newsletter
Canvas is still offline.
Foto: UvA/Ilsoo van Dijk
actueel

Five questions about the Canvas hack

Daniël Hemmer Daniël Hemmer,
11 mei 2026 - 15:00

The digital learning environment Canvas has been hit by a large-scale cyberattack, in which personal data of students and staff has been stolen. As a precaution, the UvA has taken the system offline, temporarily disrupting education and communication. Five questions about the Canvas hack.

1. What has happened?

 

 

The digital learning environment Canvas has been hit by a large-scale cyberattack. Cybercriminals from the international hacking group ShinyHunters, previously responsible for the hack on telecom provider Odido, gained access to systems of Instructure, the company behind Canvas. As a result, various user data have been stolen.

 

Instructure originally reported the data breach on 1 May. On 6 May, the company stated that data from UvA students, lecturers, and staff were also involved in the breach. A day later, Instructure said the hackers would no longer have access to the system. However, at that time the hackers still appeared to have access to parts of the platform.

 

2. Which data has been leaked?

 

Based on information provided by Instructure to the Dutch university association UNL, basic user data has been leaked in the hack. This includes names, email addresses, and possibly Canvas IDs or student and staff numbers. According to the company, no passwords, dates of birth, identity documents, bank details, or other sensitive personal data have been exposed. However, it cannot be ruled out that messages exchanged within Canvas were also part of the leak.

 

3. Who has been affected?

 

The attack affects nearly 9,000 universities, colleges, and other educational institutions worldwide that use Canvas. In the Netherlands, in addition to the UvA, six other universities have been impacted by the hack.

 

In total, the hackers claim to have stolen around 3.65 terabytes (3,650 gigabytes) of data. This would amount to approximately 275 million stolen data items.

 

4. Why has Canvas been taken offline?

 

On 7 May, when Instructure believed the hackers no longer had access to the system, the ShinyHunters group posted a message claiming they still had access to Canvas systems. As a precaution, all Dutch universities using Canvas decided to disconnect the platform. Users were instructed to stop using Canvas until further notice.

 

Shutting down Canvas has consequences for teaching. Normally, Canvas is used for distributing course materials, required readings, lecture updates, and assignment submissions. Its temporary unavailability also makes it more difficult to use plagiarism detection software such as TurnItIn. In addition, previously submitted assignments are temporarily inaccessible to lecturers.

 

5. What should students and staff do now?

 

The most important point is that teaching will, in principle, continue as scheduled, even if Canvas remains unavailable. The UvA acknowledges that students and staff will experience limitations, but states that keeping Canvas offline is necessary because Instructure cannot yet sufficiently guarantee system security. The university has set up a dedicated webpage for lecturers with an action plan for “teaching without Canvas”.

 

Lecturers are advised to use Outlook as the primary communication channel. For distributing course materials and collecting assignments, the UvA recommends using SURFdrive. Plagiarism checks via TurnItIn remain possible, but must be carried out manually per assignment. Because of the problems, the university is asking lecturers to be more lenient with deadlines.

 

The UvA expects to provide a further update on the Canvas situation on Monday afternoon. BNR reports that the Dutch universiteiten will keep Canvas offline for at least another week.

 

Update: This article was updated on 11 May at 4:45 p.m.

website loading