Notice of Third Party Incident
On May 1, 2026, Ohio University was made aware of a cybersecurity incident affecting one of our third-party vendors Instructure; the company that operates Canvas, the University’s preferred learning management system. This incident was not directed at Ohio University directly, as we are just one of the victims as part of a larger data breach. Instructure serves thousands of institutions worldwide, and this is a vendor-level event that impacts multiple institutions. Canvas continues to operate normally.
What Happened
According to Instructure, a third-party service provider that operates the Canvas platform, the University’s preferred learning management system, Instructure detected unauthorized activity in Canvas on April 29, 2026 by a threat actor known for large-scale attacks across multiple sectors, including technology and education. Instructure informed the University that it revoked the unauthorized party’s access, started an investigation, and engaged outside forensic experts. On May 1, 2026, Instructure notified the University that it had experienced a cybersecurity incident and the University’s data was impacted.
On May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability. The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas. Instructure stated that it was able to stop and contain the second attack approximately 10 minutes after it began , and no additional data was accessed or exfiltrated in this second attack. As a result of the April 29 cybersecurity incident, the attacker was able to gain access to parts of the Instructure network and view and take certain data of the University’s individual Canvas users.
For the latest official information from Instructure, visit their Security Incident Update and FAQs webpage.
What Ohio University Is Doing
Our IT team is actively monitoring the incident and working directly with Instructure to determine the specifics around information accessed and the related impacts to the Ohio University community.
What You Should Do
- Watch for phishing emails. Do not click links in unsolicited emails claiming to be from Canvas, Instructure, or OHIO IT. Visit the Phishbowl to review phishing messages that are actively impacting the OHIO Community.
- Access Canvas directly. Always log in to Canvas using official links on www.ohio.edu typing https://canvas.ohio.edu directly into your browser.
- Report anything suspicious to the IT Help Desk at help.ohio.edu or 740-593-1222.
- Visit the Infrastructure's FAQ to learn and understand more about the incident.