April/May 2026 Global Canvas Incident FAQ
What is a high-level summary of what happened?
The University of Nebraska has been a customer of Instructure (parent company of Canvas) since 2017. In late April and early May 2026, Instructure suffered two incidents impacting their global customer base - a data breach and a system compromise/outage - both through the actions of the same criminal threat actor. The University of Nebraska and thousands of our national and B1G peers are customers who were impacted by these two unfortunate incidents at Instructure.
What is the timeline of events and when did we first know something was awry?
On May 1, 2026, at 5:46 pm, the University of Nebraska received its first email from Instructure (the parent company of Canvas) stating that Instructure had experienced a cybersecurity incident perpetuated by a criminal threat actor. Instructure indicated that they were actively investigating the incident. Over the following days, we received additional communication indicating that the criminal threat actor had gained access to the Instructure environment. At this time, the University of Nebraska did not yet know if or how it was impacted by this breach.
On May 5, 2026, at 4 pm, the University of Nebraska was notified that University-related data hosted within the Canvas environment was impacted by this data breach at Instructure, who shared that the data involved appeared to include personal information but did not appear to include passwords, dates of birth, government identifiers, or financial information. Instructure also informed the University that the data breach in their environment occurred between April 25 and April 30, 2026. During these six days, Instructure detected the attach, revoked the initial access, revoked additional suspicious access, and addressed underlying vulnerabilities. In this communication, Instructure let us know they found no indicators of an ongoing threat. At this time, Canvas environments nationwide and at the University of Nebraska were continuing to be fully operational.
Between May 1 and May 7, 2026, the University of Nebraska ITS division was notifying and informing general counsel, system and campus leadership of this data breach and Instructure’s ongoing monitoring activities.
On May 7, 2026, at 3 pm, the Canvas environments across the University of Nebraska (and globally) were first impacted in terms of use, with students and faculty quickly seeing a criminal threat actor webpage in lieu of Canvas login pages, Canvas content pages, and even Canvas exams. At this time, Canvas became inoperable at the University of Nebraska and at institutions across the country. Our incident teams in NU ITS quickly began work to understand the issue and communicate the outage, including parenting broadly on systemwide emails, webpage banners, etc. Several emails were sent to students, faculty and staff systemwide at NU including Thursday evening, Friday morning, and Friday afternoon.
Following discussions with system leadership, interactions with a third-party cyber risk firm, interactions with B1G and national peers, and the implementation of several key internal risk management strategies, on May 8 at noon, the University of Nebraska enabled access to Canvas for students, faculty and staff in a “limited” fashion. Key limitations included Canvas integrations with MS365, Zoom, the Unizin Data Platform (UDP), and the Canvas to PeopleSoft grade “pull” feature remained disabled out of an abundance of caution. After additional input and analysis from our third-party cyber risk firm, the Canvas to PeopleSoft grade “pull” feature was restored on May 14 at 10 am and the Zoom, MS365, and Unizin Data Platform integrations with Canvas were restored on May 20 at noon.
What key activities were disrupted as a result of the Canvas outage?
The Canvas outage, which lasted 21 hours, took place during finals week across the University of Nebraska campuses, which disrupted exams, as well as students’ ability to submit coursework and faculty members’ ability to grade coursework and update their Canvas grade book. In addition, preparation activities for the May 11 summer term courses were also disrupted.
Is my data safe? Was my data harvested?
On May 11, Instructure informed the University that it had reached an agreement with the threat actor and represented that the data obtained during the incident had been returned and deleted. As with any cybersecurity incident involving criminal actors, these representations cannot be independently guaranteed.
Simultaneously, the University of Nebraska is continuing to engage in a thorough review with our security forensics and third-party incident response firm as well as performing ongoing updates such as rotating product keys of Canvas and integrated tools. The security of the data of NU students, faculty, and staff is an absolute top priority, and working to maintain our already high standards is ongoing.
Do I need to change my password?
At this time, you do not need to change your password; however, if you would like to proactively change it, please do so via TrueYou here. University of Nebraska systems are also protected by two-factor authentication. If you receive a push notification when you are not logging in, you will need to change your password ASAP.
I feel worried that I might get an email from Canvas that isn’t legitimate. How will I know and what should I do if I’m unsure?
Canvas and instructors using Canvas regularly send correspondence that will appear in a student’s email inbox, depending on the student’s individual notification settings. Official messages from Canvas will always come from the address notifications@instructure.com even though the name of the sender may vary.
If you receive a suspicious email, you can always report it using the Report Phish option available in Outlook. This tool sends the message to the University of Nebraska IT Security Team for analysis and helps protect others by identifying and blocking phishing attempts. The option is available across Outlook desktop, web and mobile - just open the message and select Report Phish from the toolbar/menu. For full instructions, visit: https://nusupport.nebraska.edu/TDClient/33/Portal/KB/ArticleDet?ID=39.
Should we trust Canvas going forward?
Canvas (provided by Instructure) is a cloud-base SaaS (software as a service) used by K-12 and higher education institutions across the country. Canvas has over 8,000 institutional customers and over 30 million users around the globe. Internally, the University of Nebraska engaged in due diligence with its own cybersecurity team - in addition to partnering with NU Legal and NU Risk Management - to make a recommendation to NU leadership to reinstate Canvas on Friday, May 8, 2026. With the support of NU leadership, after having received assurance from Instructure and the company’s third-party forensics team, and through many discussions with our national and B1G peers, we developed confidence that the issue has been dealt with and the system can safely resume regular activities. At this time, Canvas is working as expected. We continue to do due diligence around integration points and data feeds.
What is NU’s view of Canvas now that a single point of failure caused considerable disruption to our campuses? What if an issue like this happens again?
Cybersecurity incidents are an unfortunate part of our personal and professional lives. It is important to put these types of incidents in the context of a changing world where technology is the epicenter of many common processes and practices across nearly every sector from education to government to corporate. The disruption of bad actors and issues of academic integrity have been present both with and without technology, and the University of Nebraska wants to be sure it is always evolving forward rather than falling behind.
The University of Nebraska will continue to engage in industry-recommended practices to keep our IT environments stable and secure, including:
-
Requiring single sign on services and multi-factor authentication in front of our enterprise platforms
-
Reviewing enterprise tools for cybersecurity standards and expectations prior to purchase
-
Supporting and training faculty, staff and students in understanding, operating, and maximizing enterprise systems for maximum value and minimized risk
-
Requiring IT security Bridge training each year for faculty and staff
In addition, the University of Nebraska IT division plans to collaborate with academic leaders across NU to update continuity plans related to common learning technologies.
As a NU student, faculty, staff or parent/family member, where should I go to get the latest information about the April/May 2026 cyber incidents at Instructure (parent company of Canvas)?
The University of Nebraska will continue to keep the most up-to-date status of this Canvas incident available at canvas.nebraska.edu. If additional updates or details are provided to us by Instructure, third party forensics experts, or other federal entities now engaged with this incident, we will be sure to keep NU students, faculty, and staff updated accordingly.
The incident left me feeling rattled and unsettled. Is there someone I can talk to about the stress this caused?
The campuses each have counseling services available. You can learn more of access resources at the following links: