Canvas Data Breach FAQs
Status
Published: 05/07/2026 - 3:29 PM
On May 2, 2026, Central Methodist University learned of a data security incident experienced by Canvas, a third-party vendor whose platform we use as our learning management system. Once Canvas was aware of the incident, they began an investigation with the assistance of third-party specialists. Our internal systems at the University have not been affected, however Canvas confirmed that its investigation determined that an unauthorized user accessed certain information on its platform, including names, email addresses, student ID numbers, and messages between Canvas users. At this time, Canvas has not reported any impact to passwords, dates of birth, government identifiers, or financial information, nor do we send this information for any of our users to Canvas. Canvas has set up a webpage to provide updated information about the event as their investigation continues at: https://status.instructure.com/
Because this event involved Canvas’s platform, we do not have any additional details about the incident or the investigation at this time. We continue to monitor updates from Canvas and will share those updates as they become available. The security of your information is of the utmost importance to us. We appreciate your patience as we await further information from Canvas.
WHAT SHOULD I DO TODAY?
- Even though the information was limited to non-sensitive information, bad actors can still use this in phishing attempts. Be cautious with any emails pretending to be Canvas/Technology Services asking you to verify identity, update passwords, or keep an account active.
- Don't share Multi-Factor Authentication codes from SMS, or approve authenticator prompts, for logins that you did not initiate
- Don’t enter Multi-Factor Authentication codes from an unknown source
- Report suspicious emails using the Red Fish,'PhishNotify' icon located in your Outlook toolbar (May be hidden under the three-dots, 'more options' menu icon)