A security breach of the online learning platform Canvas temporarily compromised data from Needham Public Schools together with thousands of users nationally and worldwide.
The learning management system is widely used as an academic hub, allowing students and educators to access assignments, grades, course materials and content. Hacking Canvas allowed threat actors access to information like usernames and email addresses, course names, enrollment information and messages between users.
“This is what keeps me up at night,” said Needham’s interim chief technology officer Mark Messias. “We don’t take it lightly.”
Parent company and developer Instructure said they first noticed unauthorized activity April 29. After revoking the party’s access and launching an investigation, they identified additional activity May 7. Instructure took Canvas offline into maintenance mode to contain the activity and investigate further, causing a service outage for schools relying on the learning platform.
A hacking group named ShinyHunters initially claimed responsibility for the incident, but has since posted they are “not commenting and have no further comment to make regarding this global incident.”
The initial notification alerting NPS to the cyberattack offered little information.
“That was our biggest problem with them,” said Messias. “We reached out to our customer service reps and said, ‘Hey, we need more than this. We need to know that we’re actually affected. We need to notify parents, but we’re not notifying anybody if we don’t know this … And they were not quick to respond.”
NPS immediately disconnected Canvas from PowerSchool software to prevent further compromise, and requested a complete account of the incident from Instructure detailing which data may have been downloaded or modified.
A week later, they were notified of the second breach.
“That really shook our confidence in them at that point, right? Because their first message was, ‘It’s down for maintenance.’ And we knew it wasn’t maintenance, something was going on,” Messias noted. “We realized that we were having a problem with confidence in what they were telling us, and so were other colleagues out there, for sure.”
Messias said the schools are partway through a pilot program with Canvas, preparing for a September release for all students and staff. As a result, NPS’ daily operations were not severely impacted, though the threat actor did have access to names and email addresses already uploaded to the system.
“While we do not yet have written confirmation from Instructure, we are operating under the assumption that all students and staff were affected,” superintendent Dan Gutekanst informed the community in a May 8 email. “We have also been informed of the potential that teacher gradebook data connected to our PowerSchool student information system could have been modified,” he added. “At this time, this has not been confirmed.”
TEC Student Data Privacy Alliance has recommended discontinuing the use of Canvas, Messias noted.
Despite this recommendation, and a lack of “quick,” “direct” communication to-date, Messias said NPS will give the company time to respond before making decisions — referencing a similar incident with PowerSchool in the 2024-25 school year.
Though initially concerned with the timeline of PowerSchool’s responses and explanations, NPS found PowerSchool’s long-term response to be sound. “We need to give [Instructure] time to correct their mistake,” he said. “How they act in the next three or so weeks, what information they give us as [a] forensic report on this, will determine that relationship.”
A recent update on Instructure’s website apologized for poor communication. “Last week, we made a call to get the facts right before speaking publicly. That instinct isn’t wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates. You’ve been clear about that, and it’s fair feedback. We will change that moving forward.”
Instructure has since launched an Incident Update page, and said they will deliver a forensics report summary.
Now that law enforcement is notified, monitoring added across platforms, user access restricted and hackers’ point of entry closed (Free-For-Teacher services), Canvas is back online and available for use.
Instructure said they have reached an agreement with the threat actors, who have returned the data, provided digital confirmation (“shred logs”) of data destruction, and promised not to extort users.
“While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” the company said. “We continue to work with expert vendors to support our forensic analysis, further harden our environment, and conduct a comprehensive review of the data involved.”
Instructure encouraged concerned users to consider their specific organization as the first point of contact. “They’ll share information specific to your situation as we provide it. In the meantime, it is always a good practice to be cautious of unexpected emails or messages referencing this incident, avoid clicking suspicious links, and report anything unusual to your school or institution’s IT or security team.”
NPS updates will be provided through continued communication from the superintendent.
“We understand the concern that incidents like this create for families and staff, and we are committed to keeping you informed as we learn more,” Gutekanst said in his email May 8.

