By Sebastian Vasquez
New Mexico State University is one of nearly 9,000 institutions that have lost access to Canvas following a cyber-attack. On Friday, May 1, Instructure, the parent company of Canvas released a status update warning of a cybersecurity incident.
“Instructure recently experienced a cybersecurity incident perpetrated by a criminal threat actor,” the update stated. “We are actively investigating this incident with the help of outside forensics experts. We are working quickly to understand the extent of the incident and actively taking steps to minimize its impact. Maintaining your trust is our highest priority, and we are committed to transparency throughout this process. We will provide new information as it is confirmed.”
The following day, Instructure issued an update stating they took action against the hackers, revoking credentials, deploying security patches, and implementing increased monitoring of the situation. The company shared that users’ names, student IDs, email addresses, and private messages were all accessed.
On Sunday, May 3, cybercrime group ShinyHunters claimed credit for the breach, giving Instructure a deadline of May 7 pay a ransom, or all data would be released. In the past 5 years, ShinyHunters has claimed responsibility for data breaches of major companies such as Microsoft, Grubhub, AT&T, and Ticketmaster.
Thursday, May 7, at around 1:30 p.m., students at NMSU and other universities trying to access Canvas were redirected to a message from ShinyHunters.
“ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some “security patches.”
“If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by 12 May 2026 before everything is leaked.
“Instructure still has until (end of day) 12 May 2026 to contact us.”
At around 2:20 p.m. May 7, Canvas was updated to display a message “Canvas is currently undergoing scheduled maintenance. Check back soon.”
At 2:21 p.m. NMSU IT sent an email to all students and faculty warning them to not access Canvas until further notice.
This story is still developing.


