Skip to main content

Security Alert: Canvas Security Incident

Date:
2026-05-05 18:04:00
Status:
Closed
Brief Description:
Resolved: Canvas is fully operational. Please see https://www.instructure.com/incident_update for further details about the incident from the vendor Instructure.
Current Status:
Canvas is fully operational. Please see https://www.instructure.com/incident_update for further details about the incident from the vendor Instructure. Cornell and the thousands of other educational institutions affected by the global Canvas security incident are continuing to work with Instructure to understand the incident's impacts. Instructure states that Canvas data was not publicly released and that a comprehensive review of the data involved is being conducted. The university will follow up directly with individuals in our community whose personal data or information may have been exposed.
Services Affected:
Learning Technologies
Subsites Affected:
Canvas
Full Description:
Update: Canvas, the university's learning management system, is now available. Cornell is continuing to assess the impact of the Canvas security incident. See also the Instructure Security Incident Update & FAQ.

According to information provided by the vendor Instructure, thousands of institutions worldwide were affected, including Cornell. Instructure's investigation indicates that some identifying data was exposed, such as names, email addresses, student ID numbers, and messages among users. Cornell does not have specific details yet. See also Instructure Status.

Canvas, the university's learning management system, was affected by a global security incident involving Instructure, the company that provides Canvas. We are actively monitoring updates from Instructure and assessing the impact on Cornell data. 
CIT TDX ID:
2238708