A cybersecurity incident impacting the Canvas by Instructure platform, along with the subsequent Instructure and Ohio State response, resulted in a system-wide service interruption for Ohio State’s managed Canvas environments, including Carmen, Professional and Continuing Education, Central Ohio Technical College (COTC), Ohio Prison Education Exchange Project.
Incident Overview
On May 7, 2026, the Ohio State University experienced a complete outage of its managed Canvas environments. The disruption was caused by a cybersecurity event impacting Instructure, the Canvas vendor, and impacted thousands of schools and environments across their footprint. According to Instructure:
- Prior to the outage, on April 25, 2026, a threat actor exploited a cross-site scripting vulnerability in the Canvas platform.
- Between April 28, 2026, and April 30, 2026, the Threat Actor indicated they extracted user data from Canvas.
- Data may include usernames, email addresses, course names, enrollment information and messages, but does not include “core learning data” such as course content, assignment submissions, and user credentials.
- On May 7, 2026 the threat actors used a separate cross-site scripting vulnerability to insert a notice of the exposure and threat to release user data to some logged-in Canvas users, across multiple schools and environments.
- Within 30 minutes of the malicious message, Instructure took the Canvas system offline, displaying a maintenance page for all users.
OTDI staff, working with the University Registrar, Undergraduate Education, and A&P Communications, aligning with university leadership, updated the Campus Community of the outage through OTDI’s system status, key university and IT leader communications, mass email to the university community, social media and other OSU-hosted, non-vendor website updates. Ohio State proactively disconnected university authentication from managed Canvas systems, to prevent the university from regaining access to the system until a security review could be completed.
Instructure re-enabled Canvas from the vendor-side late in the evening of May 7, 2026. Ohio State elected to keep our Canvas instances offline until a security review could be completed. OTDI Security reviews of impacted environments showed no further indication of compromise, and Ohio State supported Canvas environments were brought back online, first CarmenCanvas late in the afternoon of May 8, followed by the remaining environments two hours later that evening.
Following the incident, Instructure has published their own overview and resource page regarding the events, shared the (still in-progress) findings of cyber security group CrowdStrike’s investigation to the event, and on May 11, 2026 Instructure CEO shared that they had reached an agreement with the threat actors that included the return of exposed data, assurances it would be no longer shared, and proof that copies of the data would be deleted. A portion of this message including those assurances was sent via mass email to the Ohio State university community.