Skip to content

Media Statements

Privacy Commissioner’s Office Publishes Investigation Findings on the Data Breach Incident of the Online Learning Management Platform Canvas

Date: 20 August 2026

Privacy Commissioner’s Office Publishes Investigation Findings on
the Data Breach Incident of the Online Learning Management Platform Canvas

Upon completion of its investigations into the data breach incident of Canvas, an online learning management platform, the Office of the Privacy Commissioner for Personal Data (PCPD) published the investigation findings today.
 

Background
 
The investigations arose from data breach notifications submitted by seven educational institutions to the PCPD between 6 May and 11 May 2026, reporting that they might have been affected by a cyberattack involving the third-party online learning management platform, Canvas (Incident). The seven educational institutions included City University of Hong Kong (CityU), The Hong Kong Academy for Performing Arts (HKAPA), Hong Kong Institute of Construction (HKIC), The Hong Kong University of Science and Technology (HKUST), Hong Kong Art School (HKAS), The Hong Kong Polytechnic University (PolyU) and Hong Kong Education City Limited (HKEdCity).
 
Canvas is a web-based learning management platform operated by Instructure, Inc. (Instructure), which assists educational institutions, educators and students to access and manage online course materials, and supports skill development and learning exchange. According to the information published by Instructure[1], Instructure discovered that a hacking group, ShinyHunters, carried out unauthorised activities in Canvas through a “Free-For-Teacher” account (Account) and exfiltrated user data on 29 April 2026. Upon detecting the unauthorised activities, Instructure immediately blocked the unauthorised access and engaged a cybersecurity firm, CrowdStrike (Network Security Company), to initiate an independent investigation. Subsequently on 7 May 2026, the threat actor exploited another security vulnerability to re-access Canvas, and defaced the login pages of some educational institutions to post a ransom note.
 
According to Instructure, the threat actor submitted a support request containing malicious code through the Account and exploited a cross-site scripting (XSS) vulnerability in the platform to obtain an authorisation token and gain elevated access within Canvas to carry out unauthorised activities and exfiltrate personal data. In the wake of the Incident, Instructure had fixed the relevant security vulnerabilities, strengthened security measures, and discontinued the “Free-For-Teacher” service. Following the review carried out by the Network Security Company, Instructure resumed Canvas’s services on 9 May 2026. On 11 May 2026, Instructure announced that it had reached an agreement with the threat actor and retrieved the stolen data.
 
Relevant Requirements of the Personal Data (Privacy) Ordinance
 
According to Data Protection Principle (DPP) 4(1) of Schedule 1 to the Personal Data (Privacy) Ordinance (PDPO), all practicable steps shall be taken by a data user to ensure that any personal data held by the data user is protected against unauthorised or accidental access, processing, erasure, loss or use.
 
In addition, DPP 4(2) provides that if a data user engages a data processor, whether within or outside Hong Kong, to process personal data on the data user’s behalf, the data user must adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use of the data transferred to the data processor for processing.
 
Investigation Findings
 
Having considered the circumstances of the Incident and the information obtained during the investigations, the PCPD has the following observations regarding the Incident:

  1. Among the data breach notifications submitted by the seven educational institutions, only four educational institutions, namely CityU, HKAPA, HKIC and HKUST (Affected Institutions), were affected by the Incident. The Affected Institutions have deployed Canvas for academic purposes, with the earliest adoption in 2014. Up to the present, there is no information suggesting that the remaining educational institutions, namely HKAS, PolyU and HKEdCity, were affected by the Incident.
     
  2. According to the updated information provided by the Affected Institutions, the data confirmed to have been affected by the Incident includes:

    Names of the educational institutions Categories and numbers of affected data subjects Types of personal data involved
    CityU 146,969
    students and staff
    Names, email addresses, usernames, student IDs, and/or course enrolment information
    HKAPA 4,584
    students and staff
    Names, email addresses, user/student IDs, and/or course enrolment information
    HKIC 2,333
    students and staff
    Names, email addresses and user/login IDs
    HKUST (pending Instructure’s further verification) Messages sent by users in Canvas
  1. The Affected Institutions confirmed that their internal systems (i.e. systems other than Canvas) have not been affected by the Incident. They have also implemented security measures prior to the Incident to ensure that the personal data held by them is protected. These measures included:
    1. Pre-assessments: prior to deploying Canvas as their online learning management platform, the Affected Institutions carried out assessments and reviews of the security measures adopted by Canvas to safeguard personal data security, such as evaluating whether the relevant security measures complied with internationally recognised security standards;
    2. Contractual Means: the Affected Institutions have entered into contractual arrangements requiring the implementation of appropriate organisational and technical measures to ensure that the personal data transferred to Canvas is protected against unauthorised or accidental access, processing, erasure, loss or use. The contractual terms also set out requirements relating to incident response, data confidentiality and compliance obligations, etc.; and
    3. Continuous Monitoring: the Affected Institutions have already established monitoring mechanisms, including reviews of the third-party security assessment reports to ensure that the security measures implemented on Canvas meet the contractual requirements and internationally recognised security standards.
       
  2. Following the Incident, the Affected Institutions maintained ongoing communication with Instructure to obtain the latest updates of the Incident. They also implemented measures to enhance data security, such as reviewing Canvas accounts’ access rights and log records, enabling multi-factor authentication for Canvas accounts, and resetting login passwords for all Canvas accounts with administrative privileges, etc.
     
In sum, the data breach incident of the four educational institutions, namely, CityU, HKAPA, HKIC and HKUST, stemmed from vulnerabilities relating to a third-party platform, and the Incident did not affect the internal systems of the Affected Institutions. Investigations revealed that the Affected Institutions had conducted pre-assessments prior to deploying Canvas, adopted contractual means and established monitoring mechanisms to safeguard the personal data transferred to Canvas. In view of the above, the Privacy Commissioner for Personal Data (the Privacy Commissioner), Ms Ada CHUNG Lai-ling, considered that there is no evidence to suggest that the four educational institutions had failed to take all practicable steps to safeguard the personal data in their possession while using Canvas, and therefore there was no contravention of the PDPO. Notwithstanding the above, the PCPD has recommended the educational institutions involved in the Incident to reassess the risks of data breaches, strengthen monitoring of the security measures implemented by third-party platforms, review and minimise the amount of personal data stored on such platforms, enable multi-factor authentication for accounts and define clear access rights and data retention periods, etc., to ensure data security.
 
The Privacy Commissioner would like to take this opportunity to remind organisations which hold large volumes of personal data to adopt the following organisational and technical measures when engaging data processors (including third-party platforms) to process personal data (including the processing of personal data using artificial intelligence models) to protect the personal data transferred to data processors:
  • Conduct due diligence before engaging data processors: review the data processors’ backgrounds and evaluate the information security measures implemented by them (e.g. data encryption, access control mechanisms, preventive and detective measures, etc.) to ensure that only competent and reliable data processors are engaged;
  • Use of on-premises servers: where practicable, organisations should prioritise the use of on-premises servers under their direct control and management for processing and storing large amounts of personal data;
  • Regulate data processors through contractual means: enter into data processing contracts that stipulate the security measures to be adopted by the data processors, the consequences for violation of the contracts, and the data user’s rights to review how the data processors process and store personal data;
  • Assess the risks of data breaches and establish an ongoing monitoring mechanism: conduct periodic assessments on the security measures implemented by the data processors and regular reviews of access rights and the system logs of third-party platforms containing personal data so as to ensure that they have fulfilled their contractual obligations and safeguarded data security;
  • Develop incident reporting mechanisms: establish clear incident response plans and require data processors to provide immediate notification following an incident;
  • Transfer personal data on a “need-to-know” basis: conduct assessments to ensure that only the necessary personal data is transferred to data processors. Organisations should also establish data retention policies; and
  • Enable security features where appropriate: for example, enable multi-factor authentication provided by third-party platforms to further enhance account security.
     
The PCPD calls on potentially affected persons to be vigilant of possible theft of their personal data and take the following measures to protect personal data privacy:
  • Consider changing the passwords of online accounts and enable multi-factor authentication feature (if available);
  • Stay vigilant when they receive any suspicious calls, text messages or emails from unknown sources. Do not arbitrarily open attachments, links or disclose personal data readily;
  • Be vigilant against phishing or other possible scams;
  • Beware of any unusual logins of personal emails or accounts; and
  • Potentially affected persons may make enquiries with the relevant organisation or the PCPD (telephone: 2827 2827 or email: communications@pcpd.org.hk).
     
Any other organisations notified by Instructure that they have been affected by the Incident may contact Instructure or the PCPD (telephone: 2827 2827 or email: communications@pcpd.org.hk) for enquiries, and the PCPD will provide assistance, as appropriate, to help organisations strengthen their information security.