Skip to main content
Back to overview
High

Iowa State University's Canvas Learning Platform Breached, Student Data Exposed

Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages.

Key points

  • Iowa State University's Canvas learning platform was breached on July 26, 2026.
  • A hacker message blocked access to the website and demanded a settlement.
  • The incident is part of a larger series of over 9,000 attacks affecting other schools.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Confidentiality impact

Possible insider activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jul 26, 2026
Updated
Jul 29, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible insider activity

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

IastateData DisclosureIowa State UniversityCanvas Learning Platform BreachedUniversityCanvasTOXShinyHuntersCanvas andTicketmaster and Google. The

Quick context

Questions about this signal

What happened in this signal?

Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages. The message advised users to "consult with a cyber advisory firm" and to "contact us privately at TOX to negotiate a settlement." This incident is part of a larger series of over 9,000 attacks affecting various educational institutions. The hackers, identified as the criminal extortion group ShinyHunters, had previously caused an outage on Canvas and are also linked to data thefts from Ticketmaster and Google. The compromised data includes names, email addresses, student ID numbers, and internal messages. Iowa State IT Security issued an email addressing the outage and advised students to seek alternative submission methods for coursework. The university's news service director, Angie Hunt, confirmed that Iowa State is one of many institutions affected by a nationwide Canvas platform outage. Instructure, the parent company of Canvas, has not provided a timeframe for resolving the issue. The group ShinyHunters claimed to have stolen over 3.65 terabytes of data, encompassing approximately 275 million records belonging to students, teachers, and staff, and threatened to release this data if their demands were not met. While the affected data may include full names, email addresses, student ID numbers, and messages, there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. The sensitivity of some Canvas messages, which can contain medical and mental health information, adds to the concern. Officials are advising students, parents, and staff to be cautious of unsolicited messages claiming to be from Canvas or the university that request personal information or prompt immediate action. They also recommend monitoring accounts for unusual activity.

When was this signal reported?

Shadow Tier lists Jul 26, 2026 as the signal date.

Which organization is connected to this signal?

Iastate is the organization connected to this public signal.

Explore Iastate
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence