Wikiwand AI

Talk:2026 Canvas data breach

From Wikipedia, the free encyclopedia

More information Things you can help WikiProject Computer security with: ...
Close

Requested move 9 May 2026

The following is a closed discussion of a requested move. Please do not modify it. Subsequent comments should be made in a new section on the talk page. Editors desiring to contest the closing decision should consider a move review after discussing it on the closer's talk page. No further edits should be made to this discussion.

The result of the move request was: moved to 2026 Canvas data breach. The support for this has developed into a pretty overwhelming consensus, and I don't see a realistic chance for further consensus to overcome it. (closed by non-admin page mover)Maltazarian parleyinvestigate 22:46, 16 May 2026 (UTC)


2026 Canvas security incident2026 Canvas security breach2026 Canvas security breach – To match bold title on page. OrbitalVoid49 (talk) 17:22, 9 May 2026 (UTC)

  • Oppose not sure moving the article to a very close synonym is going to help. Stuartyeates (talk) 20:41, 9 May 2026 (UTC)

*:Counter-oppose Incident could mean a lot of things, breach is much more specific. | One Reaction was here. Got a complaint? 19:03, 12 May 2026 (UTC) (Removed via request on my talk page because this apparently seemed like bludgeoning. Please exclude this comment from consensus. | One Reaction was here. Got a complaint? 00:03, 13 May 2026 (UTC))

  • Support: Standardizing in this case is good. Rooves 13 (talk) 23:43, 9 May 2026 (UTC)
    yes ~2026-28120-59 (talk) 23:50, 9 May 2026 (UTC)
    Originally they were both identical, but BlkMtn changed it to security breach about 7 hours ago. Kibblebrain (talk) 02:39, 10 May 2026 (UTC)
    Usage of the word "incident" significantly minimizes the magnitude of this situation. "Instructure", the company who experienced this cybersecurity attack (AKA: Security Breach), naturally wants to diminish the enormity of the size and impact. Therefore, using the company's own downplayed terminology of "incident" to title this hacking is unnecessary. The correct terminology is "Security Breach". BlkMtn (talk) 15:09, 10 May 2026 (UTC)
    I think the timeline and context is important to why this article was likely originally named with “security incident”.
    This may be just my opinion, but Instructure was not forthcoming with much information at all during the May 7 outage. From the public’s point of view, it was unclear if this was the same actor as the April 25 (disclosed on May 1) breach (and most of the public was not aware that this happened at the time, based on news coverage and disruption to students). On May 7 it was clear that some sort of system was compromised, since ShinyHunters was able to post a message on the website, but it wasn’t yet clear whether PII had been accessed (the website can reside on a separate system). By now, it is clear that these were likely related incidents and PII was accessed.
    The cybersecurity industry uses “incident” as a broader term to encompass anything including DDoS attacks (which don’t usually affect data confidentiality). “Data breach” is a subset of incidents where there unauthorized access to data. It’s clear now that the latter occurred, so in the interest of specificity (using a term that also easily communicates the impact), it may be more appropriate.
    As you said, Instructure does have a motive to not use “breach” too. PR impact aside, that word carries certain legal implications, including formal notifications to customers and regulators (in some jurisdictions this is time-sensitive) and engagement with cyber insurance providers. However, I don’t think that was involved in the naming the article during its creation.
    TLDR: Support, at the time of the article’s creation I think “security incident” was appropriate, but with the info we have now, “data breach” is now more specific and still accurately communicates the situation. Nightowl33 (talk) 18:52, 16 May 2026 (UTC)
    I agree with standardization as a major priority in naming. Looking at other similar events, such as Aura data breach and Snowflake data breach (which were also done by the ShinyHunters group), it appears that there is a consistency in naming convention that should be recognized.
    Also, I added an entry for this hack to the List of data breaches table. Lets make sure it gets properly updated with whatever name gets decided. Deathstar3548 (talk) 11:20, 15 May 2026 (UTC)
  • Weak oppose Instructure called this event a 'security incident' in their report. However, most of the sources in the references use data breach in their title. In my opinion, security incident may fit better for the overall series of events, including the vandalism of the login page. It's probably better to leave things be and not make the current title a redirect in favor of a synonym since it already has 50 other articles linking to it. Kibblebrain (talk) 02:37, 10 May 2026 (UTC)
    If most sources call it a data breach, wouldn't that make it to where moving to 2026 Canvas data breach supported by WP:COMMONNAME? CabinetCavers----DEPOSIT OPINION, [valued customer] 15:31, 11 May 2026 (UTC)
    It would fit COMMONNAME, so weak support of alternate move to data breach. As LuniZunie points out, this chain of events involves two separate breaches of the security system, with at least the first breach leading to data exfiltration. The plural form is technically more precise. Kibblebrain (talk) 17:59, 11 May 2026 (UTC)
  • Oppose: Considering the group claimed that they extracted data from the servers, along with the fact this is essentially the climax of a week-long event with their security, I think that warrants a security incident rather than breach. Breach implies that they did this only once, but since it happened twice, it's not longer just a breach, rather, as the title implies, an incident. GaomonAndLucario (talk) 03:00, 10 May 2026 (UTC)
  • Oppose: For same reasons as Stuartyeates, Kibblebrain, and GaomonAndLucario -- Jtneill - Talk 04:49, 10 May 2026 (UTC)
  • Support name change but Oppose proposed name. The naming convention for events explains that event articles should be named for When, Where and What happened. The present title is imprecise and suggests there was a security incident at some place called Canvas, and is misleading or at least unclear. The title needs additional words to make it clear the article is about the Canvas online learning system (or platform). There appears to be no commonly recognizable name for this event but terms like cyberattack (8 sources) or data breach (7 sources) feature more in the headlines for this articles sources than either the one mention of the term security breach or the four mentions of security incident, which seem like a technical jargon being used by the software company, itself, to downplay and minimize what has happened. I don't think the majority of the article's sources support either the term security breach or security incident and a term that is more commonly used in the article's sources like cyberattack or perhaps data breach would probably be better, and perhaps more accurate. - Cameron Dewe (talk) 11:32, 10 May 2026 (UTC)
I concur. "Data breach" hits, and it's exact. kencf0618 (talk) 21:04, 10 May 2026 (UTC)
I absolutely agree, shifting my support to “data breach” Rooves 13 (talk) 04:15, 11 May 2026 (UTC)
Support the rename, though "data breach" would be more precise still. "Security incident" is an umbrella term encompassing phishing attempts, DDoS attacks, malware infections, lost devices, and physical intrusions, many of which involve no data exposure. "Data breach" is a defined term - see Data breach - and accurately characterises what happened here. ~2026-28329-10 (talk) 07:38, 11 May 2026 (UTC)
Support under a different name: The title you suggest is already present as a redirect, and I see others supporting a move to 2026 Canvas data breach, which I agree is a more accurate term for what happened. CabinetCavers----DEPOSIT OPINION, [valued customer] 12:01, 11 May 2026 (UTC)
  • Oppose As all new titles unduly focus on the data breach aspect when the same, if not more impact came from Canvas being down during finals week. Chorchapu (talk | edits) 12:10, 11 May 2026 (UTC)
    This puts the cart before the horse. ShinyHunters is not holding finals hostage, but the students' and teachers' data, some of which is bound to be of great sensitivity. kencf0618 (talk) 15:23, 11 May 2026 (UTC)
Oppose, “2026 Canvas data breach” would be better than either the current title or the title the move is to. A security incident or breach could be many things, from a physical attack on a facility to a data breach. - PhilDaBirdMan (Talk | Contribs) 13:34, 11 May 2026 (UTC)
Support "Security incident" is euphemism speak, but data breach assumes exfiltration which we don't know for sure happened. "Security breach" is fine, but it's nearly as euphemistic as incident. Corundum Conundrum (CC) 13:54, 11 May 2026 (UTC)
Turns out they paid ransom so it's almost certain something was exfiltrated. Corundum Conundrum (CC) 21:19, 12 May 2026 (UTC)
Support but with "data breach" because it's better sounding. BillyTheConqueror (talk) 14:21, 11 May 2026 (UTC)
  • Support "security breach" is a lot more precise. Though as stated above, "data breach" sounds better. Fortek67 (talk) 16:35, 11 May 2026 (UTC)
i've started a subsection sharing this as an alternative proposal. In other words, Support. | One Reaction was here. Got a complaint? 22:28, 11 May 2026 (UTC)
Comment from what I understand, there were multiple breaches in security (one occurred a week prior in which ShinyHunters told Instructure about the security issue and Instructure ignored them but pushed a small update). If that is that case, I would me more inclined to stick with security incident rather than data breach as there were multiple breaches. 2026 Canvas data breaches is another possibility, but it just sounds weird to me. LuniZunie(talk) 16:49, 11 May 2026 (UTC)
Support the word "incident" really doesn't capture what happened at all. Calling it an "incident" really downplays what happened here. Nearly 9,000 educational institutions were impacted, including my current institution. The scale of this incident is not very well encapsulated by "2026 Canvas security incident." While I would prefer "data breach," I think "security incident" is one of the weakest terms we can use for this data breach. MountainJew6150 (talk) 21:38, 11 May 2026 (UTC)
guess what? I've raised up "data breach" as an alternative proposal. | One Reaction was here. Got a complaint? 22:47, 11 May 2026 (UTC)
Weak oppose because it would be a breach or a leak if data were to be released, which as the company stated, would not happen until the end of day on May 12, and until then it should stay incident. Just my thinking because I’m not familiar with templates. Carlo2026 (talk) 22:55, 11 May 2026 (UTC)
except that it's may 12th now so | One Reaction was here. Got a complaint? 11:34, 12 May 2026 (UTC)
End of day on May 12. Not sure if that’s UTC or a diffeent timezone. - PhilDaBirdMan (Talk | Contribs) 11:35, 12 May 2026 (UTC)
I think it’s the time zone where ShinyHunters is based Carlo2026 (talk) 11:36, 12 May 2026 (UTC)
Support the current name does not show the magnitude of the situation at all, as someone who is a student of the Queensland education department it is a mess they have completely shut down Qlearn and I was told by a teacher that all staff were told to make OneNote notebooks since they may not reopen our instances of canvas. Rwils32 (talk) 23:28, 11 May 2026 (UTC)
Support/Oppose per Cameron Dewe drdr150 (they/she) (Yell at me Spy on me) 14:35, 12 May 2026 (UTC)
Keep: unclear changing around to a synonym with no clear benefit. As LuniZunie mentions, there were multiple incidents that occurred, not one. --signed, TheAuroraBorealis 21:32, 12 May 2026 (UTC)
very good point! Robloxguest3 (talk) 22:44, 12 May 2026 (UTC)
Strong oppose Aboslutely not needed. Security incident is just fine. Also, security incident is a lot more gripping. This is just an opinion, but I think that "Security incident" is a lot more intresting than "Security breach." 'Incident' sounds better and would hook the reader better than 'breach'. Finally, like @Stuartyeates: said, "not sure moving the article to a very close synonym is going to help."

Robloxguest3 (talk) 16:28, 12 May 2026 (UTC)

:Counter-oppose As per previously stated, "incident" can mean a lot of things, while "breach" is more specific. Also, not as to offend, but "Security Incident" already appears to have a snowball's chance in hell. | One Reaction was here. Got a complaint? 19:55, 12 May 2026 (UTC) (Removed via request on my talk page because this apparently seemed like bludgeoning. Please exclude this comment from consensus. | One Reaction was here. Got a complaint? 00:03, 13 May 2026 (UTC))

What is difficult about "incident"? Robloxguest3 (talk) 20:06, 12 May 2026 (UTC)
I believe they meant that, given the current scope of how the discussion has progressed, "security incident" seems to be extremely unlikely to become the consensus term. Red Shogun412 (talkcontribs) 20:09, 12 May 2026 (UTC)
oh. Robloxguest3 (talk) 20:20, 12 May 2026 (UTC)
he* | One Reaction was here. Got a complaint? 20:22, 12 May 2026 (UTC)
your tone sounds like you expect me to agree. I don't. | One Reaction was here. Got a complaint? 20:21, 12 May 2026 (UTC)
Like @TheAuroraBorealis: mentioned, there was more than 1 "incident". Robloxguest3 (talk) 22:46, 12 May 2026 (UTC)
I still don’t agree. Multiple incidents still seems to me like a breach. | One Reaction was here. Got a complaint? 22:48, 12 May 2026 (UTC)

Support In this context, "incident" is a weasel word.—Finell 18:56, 13 May 2026 (UTC)

Alternative Proposal: 2026 Canvas data breach

I feel this more accurately describes what the topic is, or, at least, may turn into. What are you all thinking? | One Reaction was here. Got a complaint? 22:24, 11 May 2026 (UTC)

  • Support after reading all the arguments, seems like this is the best choice. Kibblebrain (talk) 22:28, 11 May 2026 (UTC)
I did not actually realize this was such a popular demand before raising this alternate. wow. | One Reaction was here. Got a complaint? 22:30, 11 May 2026 (UTC)
Support just sounds better BillyTheConqueror (talk) 22:51, 11 May 2026 (UTC)
There are two aspects to the "incident":
  1. Data breach(es?)
  2. Outages caused by:
    1. Instructure (to patch vulnerability)
    2. Institutions disabling access
So, whatever title is used needs to cover the full scope.
-- Jtneill - Talk 00:03, 12 May 2026 (UTC)
This was also my initial concern. data breach looks to be a compromise of scope for precision and consistency. Kibblebrain (talk) 00:08, 12 May 2026 (UTC)
My concern is that “data breach” makes it sound as if data has been leaked, which I think at this point is not the case, although it may develop into one soon, I think as of right now “incident” makes the most sense. Carlo2026 (talk) 00:51, 12 May 2026 (UTC)
I don't think so, I mean, the data was breached. LuniZunie(talk) 00:54, 12 May 2026 (UTC)
Fair enough. Carlo2026 (talk) 01:26, 12 May 2026 (UTC)
Support. This is the best name (IMO) for the situation as the data is being breached. ~2026-27026-51 (talk) 06:41, 12 May 2026 (UTC)
It is a breach because systems were accessed by unauthorized actors (similar to how levees are breached and the water rushes in). Breaches do not require the data to be leaked on the Internet. That’s a breach AND a leak Nightowl33 (talk) 18:31, 16 May 2026 (UTC)
Support and idea addition: There is, in fact, a data breach (of course), and also, we need to add an "outage" line (since most institutes implemented an outage on canvas) Totallynottwotime (talk) 12:16, 12 May 2026 (UTC)
hmmm, good point! | One Reaction was here. Got a complaint? 13:58, 12 May 2026 (UTC)
Support, not only was the data breached, but the current title and the original proposed title are both vague and this assists in disambiguation. drdr150 (they/she) (Yell at me Spy on me) 14:36, 12 May 2026 (UTC)
Net support Nineteen Ninety-Four guy (talk) 14:56, 12 May 2026 (UTC)
Strongly support data breach or security breach. Just to muddy the waters a bit, today the United States Federal Trade Commission (FTC) released an article referring to it as "Canvas Cyberattack". https://consumer.ftc.gov/consumer-alerts/2026/05/what-know-after-canvas-cyberattack BlkMtn (talk) 17:21, 12 May 2026 (UTC)
  • Support, the proposed title change better summarizes the content of the article. SomeRailfan (talk) 18:18, 12 May 2026 (UTC)
Support - the data was being held ransom. ItzSwirlz (talk) 18:43, 12 May 2026 (UTC)
Support. "Data breach" is more WP:PRECISE than either "security breach/incident" or "cyberattack" and accurately conveys the substance of the event to readers looking for it. I would also look to the 2022 LastPass data breach as providing precedent for this change. "Security breach/incident" and "cyberattack" could still work as good redirects, but those terms typically cover a broader scope of events that usually involve more direct consequences in the physical world, such as incidents or breaches of physical and digital security perimeters or cyberattacks against critical infrastructure, neither of which corresponds to this sequence of events.
I also don't think the plural form is exactly necessary, considering that its the same group acting on a repeated pattern in a relatively short time span, it's sufficient enough to lump it together as a single, continuous event. Red Shogun412 (talkcontribs) 19:16, 12 May 2026 (UTC)
Not trying to offend, but WP:TLDR | One Reaction was here. Got a complaint? 22:46, 12 May 2026 (UTC)
@OneReaction5890: To sum up: "Data breach" is the most precise term. There is precedent with previous articles covering similar topics being titled as such. "Security breach/incident" and "cyberattack" are broader terms typically reserved for events with more real-world consequences (infrastructure attacks, physical perimeter breaches), which don't apply here. Red Shogun412 (talkcontribs) 00:02, 13 May 2026 (UTC)
is there a "Master of Logic Barnstar" by any chance? Because it's going to you after this. | One Reaction was here. Got a complaint? 00:06, 13 May 2026 (UTC)
Support. I believe it follows precedent better and is more precise compared to security incident/security breach. baba - t 19:49, 12 May 2026 (UTC)
Support. Oneequalsequalsone (talk | contribs) 21:58, 12 May 2026 (UTC)
Support I thank the name might stand out because it will meet up with the section "Breach and outage" ~ŤheŴubṂachine-840✒️ 22:51, 12 May 2026 (UTC)
Strong oppose: Per my reasoning above. If we're really going to go to fine-word-choice, "security breach" is far more descriptive than "data breach", which implies only one type of incident occurred instead of multiple events. --signed, TheAuroraBorealis 04:51, 13 May 2026 (UTC)
per what reasoning? you only said that moving to "security breach" was unclear. what was said about "data breach"? | One Reaction was here. Got a complaint? 19:02, 13 May 2026 (UTC)
That's not necessarily true, though. Nothing in the definition of "data breach" precludes it from referring to multiple, co-occurring instances of the same or similarly related nature. What evidence do you have that something more than what a "data breach" describes occurred here? How is your definition of "security breach" at all more descriptive when the primary collateral in this all is users' private data information that was specifically and broadly targeted and extracted? Red Shogun412 (talkcontribs) 19:50, 13 May 2026 (UTC)
Support. Seems like the best proposal to me and the best summation of what this event really was. It also seems like it will age well, considering that the data that was breached is of high importance down the road. Justdoingmybesttoedit (talk) 15:19, 15 May 2026 (UTC)
Oppose - "data breach" misrepresents the incident (or breach or $NAME) as strictly limited to data - while that may be the biggest impact, the attackers claimed some ongoing access to Instructure's infrastructure (hah) and used it to deploy a ransom note to thousands of schools' Canvas instances. Eyesinthefire (talk) 02:41, 16 May 2026 (UTC)
Support In the real world, "security breach" and "data breach" are synonymous.—Finell 18:56, 13 May 2026 (UTC)
Support. "incident" does not mean anything. And "data breach" seems to be more widely used (by Google search). Sun8908Talk 06:51, 15 May 2026 (UTC)
Support. In the field of cybersecurity, the terms "incident' and "breach" have distinct meanings. A breach is a particular and severe type of incident. Non-breach incidents do less harmful things like encrypt data, deface websites with embarrassing pictures, or make systems stop working for a while. Exposing private customer data - which is what a breach is - is just about the worst thing that can happen in cybersecurity, and that's why this is in the news. Using the term "incident" here would downplay its severity. Clayoquot (talk | contribs) 22:24, 15 May 2026 (UTC)
Support Initially I was sceptical but I have been convinced by Clayoquot's reasoning. Chorchapu (talk | edits) 00:56, 16 May 2026 (UTC)
As someone working in "the real world," I'd argue that the phrases are only synonymous when the scope of the attack is strictly limited to a data breach, with no continued compromise of systems. That's not the case here Eyesinthefire (talk) 02:44, 16 May 2026 (UTC)
The discussion above is closed. Please do not modify it. Subsequent comments should be made on the appropriate discussion page. No further edits should be made to this discussion.

Ongoing as of 11 May, or over by 8 May

There is a statement in the article that the incident is ongoing as of 11 May (The length of these outages varied by educational institution, ranging from one day to several days, with access to Canvas in some institutions still not restored after four days), when the infobox gives its end date as 8 May. Either the infobox should be changed to note that this is ongoing, or the (uncited) statement in the §Impact section should be removed/clarified. Renerpho (talk) 22:11, 11 May 2026 (UTC)

Apparently the issue was formally resolved a few hours ago, meaning the range would be May 1-11, though an argument could possibly be made that the Canvas outages count as "ongoing." I will say however that there's no guarantee that this issue is legitimately over, as who is to say that ShinyHunters doesn't have a copy sitting around somewhere? Though obviously it would damage their credibility a ton if they legitimately ignore their agreement with Instructure. All I'm saying is it's officially over, but an extension is not out of the realm of possibility. We aren't a crystal ball however so let's just assume it ended on May 11. MountainJew6150 (talk) 01:44, 12 May 2026 (UTC)
Sounds good to me (May 1-12 as of now, per reports of ongoing issues). Renerpho (talk) 08:43, 15 May 2026 (UTC)

Edit request: cite or remove migration of a university

Currently there's a migrations away from Canvas section claiming that The University of British Columbia started moving staff and courses to Canvas's open source competitor. However, the cited primary source is only about "Alternative Course Hosting", listing advice pages and workshops to migrate. It says "This page covers options for hosting courses outside of the primary Learning Management System (LMS)", which implies Canvas remains their primary system. The claim should be cited to a source that supports it, or it should be removed. Sophocrat (talk) (from a temporary account) 00:41, 16 May 2026 (UTC)

 Done, also given
@The Sophocrat would you mind confirming the authenticity of the above comment?
Best, Squawk7700 (talk) 16:30, 16 May 2026 (UTC)
That's me, I just couldn't edit on my account at the time. Thanks. Sophocrat (talk) 23:03, 19 May 2026 (UTC)

Background - add Sept. 2025 breach of salesforce

It's a little harder to find data on the earlier breach. However, it appears to be the precursor and directly related to the April/May breach. Some sources state that ShinyHunters remained persistent after the SalesForce breach and used data from that attack to facilitate the second attack. I'm putting this in talk and not the main page because I can't concretely document it. Can anyone confirm the connection? The first breach is definitely documented, although it's not possible to access Instructure's disclosures from before 2026 from their public facing pages.

Sentra.io claims that this is a pattern by ShinyHunters with previous victims. https://www.sentra.io/blog/the-instructure-breach-was-salesforce-again-heres-the-governance-problem-nobody-is-talking-about

At a minimum, I think the existence of the Sept 2025 breach should be included in background since the company suffered 2 attacks from the same entity twice in less than a year. Mamabear47 (talk) 03:58, 25 May 2026 (UTC)

Related Articles

Timelines

Top Qs

Fact Checks