• May 8, 2026

When Your Vendor Gets Hacked: Staying Grounded During the Canvas Incident

Big yellow sign that reads "Warning"

When Your Vendor Gets Hacked: Staying Grounded During the Canvas Incident

When Your Vendor Gets Hacked: Staying Grounded During the Canvas Incident 1024 614 Vantage Technology Consulting Group

Digital rendering of a shield. Text reads: "Insights. When Your Vendor Gets Hacked: Staying Grounded During the Canvas Incident"

It’s been a tough week for a lot of our clients in higher education. Instructure, the company behind the learning management system (LMS) Canvas experienced a major breach by the illicit hacking group “ShinyHunters.” Thousands of schools rely on this system, and the attack came at one of the worst possible moments. Finals, year-end K-12 testing, and family communications all stalled at exactly the wrong time. As someone who has dealt with my share of cybersecurity incidents in higher education, I keep coming back to a few thoughts I would like to share.

What You Can and Can’t Control

This is a third-party vendor incident. Your institution’s systems, networks, and security controls were not the proximate cause. While that distinction doesn’t relieve the pain your institution is feeling right now, it does affect how you respond to the incident and what you communicate to your community.

You aren’t running Instructure’s forensic investigation. You aren’t setting their remediation timeline. What you can control is how your institution responds to the impact, supports your community, and manages the risks that flow downstream to students, faculty, and staff.

That sounds obvious, but as cybersecurity leaders, we often have the impulse to try to do everything at once. Resist that urge. Prioritize the things you can actually address:

  • Academic continuity: With finals in progress, this is your first obligation to students
  • Data exposure follow-up: What does your community need to know about the names, emails, and student IDs that were part of this attack?
  • Vendor accountability: Your legal and procurement teams should be reviewing your contract now to determine your options

Overcommunicate

Communicate early, honestly, and often. When a major vendor goes down, your community will look to you for answers, even though you’re probably still trying to figure a lot out. It’s critical that you communicate as you sort through the mess. Your community is looking for reassurance that someone who knows what they’re doing is managing the crisis. Major points to address include:

  • Acknowledge the disruption and demonstrate empathy.
  • Explain what is known and what is not known (at this time): Point to where updates will live and consistently add updates as more is revealed and resolutions are put in place.
  • Commit to following up: Don’t communicate once and then go silent. In situations like these, it’s virtually impossible to provide too many updates.

It’s also worth noting: This is the third ShinyHunters breach of Instructure in roughly eight months. The October 2025 incident at the University of Pennsylvania that the press treated as a Penn-specific story now reads as a proof of concept for what happened this week. Instructure and Canvas represent a massive share of the higher education LMS market, but that level of vendor concentration creates widespread risk, as evidenced by this latest attack.

What To Do When the Dust Settles

When this stabilizes, run a candid post-incident review. You’ll need to answer these questions honestly to help protect your institution from future attacks and to be prepared when they do come:

  • Did your campus have a backup plan for Canvas being unavailable? If not, who will be responsible for developing that plan immediately?
  • Are vendor-incident scenarios part of your tabletop exercises? In an ideal world, your team will have rehearsed how to respond to scenarios like these.
  • Does your contract with Instructure give you the rights and remedies you need?

Vendor incidents are a routine feature of higher education’s technology landscape now. The Canvas breach is significant in scale, but the response principles are the same as for any cyber event: steady leadership, clear communication, and a focus on protecting your community.

Your institution did not cause this crisis; but as cybersecurity leaders, you must be responsible for how you respond to it.

Further reading: The Skills Campus Leaders Need During a Cybersecurity Crisis

This post was authored by Associate Vice President Hunter Ely, who combines 25+ years of experience in higher education with more than 7 years of specialized consulting to advise clients on information security issues.

Need Help?

Our Strategic team includes cybersecurity experts who can talk with you about what you should be doing now and how to protect your institution in the future.