Editor’s note: As of May 8 at 4 p.m. canvas is back up
Dude, where’s my webpage?
On the afternoon of May 7, students and faculty nationwide, including those at Oregon State University, found themselves suddenly locked out of Canvas completely.
According to OSU’s Chief Information Security Officer David McMorries in an email, Canvas reported a service outage on May 7 at 1:40 p.m.
McMorries noted that at the time of the email, Canvas had not identified the cause of the outage and had not yet provided an estimate for restoring service. Despite this, OSU will aim to continue operations as usual.
“OSU leaders are developing guidance for teaching faculty to minimize disruption to students and learning.” McMorries said.
In the email, McMorries also noted that Instructure, the company that provides Canvas services to OSU, informed the university on May 1 that they were responding to a data security incident.
Instructure did not identify the group responsible for the attack, according to McMorries; however, a group known as the ShinyHunters, an online-based extortion group, has claimed responsibility for the security breach at Instructure.
Students across the nation were affected by the breach. Such as California State University’s Sophia Carbonaro, a Cinema and Television Arts major, who upon trying to open Canvas, expressed her shock on the internet when met with the following message from the group.
“If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by 12 May 2026 before everything is leaked.”
Linked in the message was a list of around 8,800 schools and institutions impacted by the breach. Oregon State University was not included in the list, however it is unknown if the list is fully accurate and/or if any OSU student data has been stolen.
This attack follows a claim made by ShinyHunters in a ransom note posted on May 3rd to Ransomware.Live, a website that tracks and monitors ransomware groups. In this note, the group claims they had stolen data regarding 275 million users, including private Canvas messages from a data breach of Instructure.
On the evening of May 7, Instructure reported on its official website that Canvas is up and running for most users, however, OSU students are still unable to access Canvas.
As of May 8, trying to open OSU Canvas page re-directs users to a page detailing the outage.
The message on the page ends with, “To protect the OSU community, we are validating the security and stability of the platform before re-enabling access. We will share updates as they become available.”
For more information on the status of OSU’s Canvas page, students can look to the OSU IT status page. Students and professors are advised to communicate via email regarding assignments and other academic matters impacted by the Canvas outage.
The Barometer is committed to keeping readers appraised as the story develops.



















































































































