Update on the Instructure (Canvas) Cybersecurity Incident

This page will be updated as new information becomes available.


May 15, 2026 2:30 p.m. - Canvas update: safely restoring full functionality

The University of Alberta’s Information Services and Technology (IST) teams will begin the process of fully restoring Canvas functionality today, Friday May 15, 2026.

Restoration may take until Wednesday, May 20, 2026 to fully complete, particularly for extensions and third-party platforms. Throughout this process, the U of A is working diligently to ensure there have been additional security controls and monitoring enhancements to help prevent recurrence.

We appreciate the community’s patience as we work to restore Canvas to full functionality. IST and the Information, Privacy and Records Management Office (IPRMO) continue to work together to ensure the university’s response aligns with our Protection of Privacy Act (POPA) obligations.

Questions?

Technical Support

Contact IST eClass/Canvas Support via the Service Portal or eclass@ualberta.ca

Pedagogical Support

Contact ctllms@ualberta.ca

POPA/Privacy Support

Contact the Staff Service Centre at 780-492-8000 and press 1 or submit a request through 26-INV-01608 Inquiry Form


May 11, 2026 4:30 p.m. - Increased Risk of Phishing Attempts following Canvas Incident

Recent news reporting of the third-party data breach affecting Canvas and multiple post-secondary institutions may increase the likelihood of targeted phishing and impersonation attempts directed at  students, staff and faculty. High-profile incidents can be utilized by cybercriminals to send convincing, course-related messages designed to appear legitimate.

Because Canvas was restored in limited mode on Friday May 8, 2026 and some features remain unavailable, attackers may attempt to exploit confusion about the system status.

Please remain cautious when receiving unexpected communications related to coursework, grades, account access, payments or university systems. 

Key reminders

  • Do not click on suspicious links or download unexpected attachments.
  • Verify urgent or unusual requests through another communication method before responding. 
  • Never share your password or Multi-factor Authentication (MFA) code by email, phone or chat. IST will never ask for this information. 
  • Be cautious of messages with high-pressure tactics designed for immediate action. 
  • To flag a suspicious email, forward it to phishing@ualberta.ca 

Examples may include

  • Emails claiming you must provide your password, CCID, or personal information to avoid Canvas account suspension.
  • Emails appearing to be a Canvas-related issue.
  • Messages referencing real course names, assignments or instructors but sent from non-U of A email addresses.
  • Messages asking you to open a link or log in to “verify your identity,” “restore access” or “confirm your grades.”
  • Emails asking you to provide payment to restore functionality of your Canvas account.

If you receive a suspicious message, do not engage, click links, or provide personal or private information.

Resources


May 8, 2026 5 p.m. - Canvas restoration with reduced functionality

We are anticipating restored limited service on Canvas at 8 p.m. today. 

To support successful learning outcomes for students while minimizing disruption and limiting further risk, the university is prioritizing student success, and the continued safety and protection of privacy of the community while it works to fully restore Canvas. The information contained in Canvas is essential to learning outcomes for students and instructors, and the assessed risks of Canvas are limited at this time.  

This is an interim measure for the short-term. To safeguard users, the university will continue to take steps to ensure the security of Canvas before restoring full access and functionality to the platform. At this time, we do not know when Canvas will be fully restored.

Steps taken to support learning and safety at this point include: 

  • Some features in Canvas will remain off, including integrations with third-party platforms.
  • Messaging and chat should be avoided within Canvas and move to other platforms as directed by instructors.  
  • The university is providing guidance to instructors on strategies for assignment submission, alternate methods of communication with students, and quizzes/exams and secure extraction of data.

There are no changes to scheduled exams. Students with questions or concerns about impacts should contact their instructor. 

We understand the very real impacts that this situation may have on well-being and academic progress. The university will continue to make the safety and security of the community its highest priority, and support is available for you.

Updates will continue to be provided as new information becomes available.


May 8, 2026 — 8:15 a.m.

Yesterday afternoon, the university received reports from users seeing an unauthorized message when trying to access the Canvas platform. Since then, Canvas has been taken offline and we are continuing to work with the vendor to learn more. The issue is not confined to the University of Alberta and is part of the ongoing issue with Instructure, the company that provides Canvas to the U of A.

University of Alberta Canvas users should not attempt to access Canvas until further notice.

More information about how this will affect courses and exams, and other updates will continue to be provided through this page as new information becomes available.


May 7, 2026 — 1:30 p.m.

The University of Alberta has been notified that U of A data is impacted by the recent cybersecurity incident involving Instructure, the company that owns our learning management system (LMS) Canvas. The incident has impacted approximately 9,000 institutions globally. 

The university is awaiting further details from Instructure regarding the scope of the impact on U of A data, including the volume and types of information involved.

While we are working to confirm this, we do know that data such as passwords, dates of birth, government identifiers and financial information is not stored in the U of A’s Canvas and will not have been exposed. 

Instructure has indicated that the incident has now been contained. See more details of the incident.

No action is required by Canvas users at this time.

This incident has been referred internally to the U of A Privacy and Security teams. 

The university remains in direct contact with Instructure as their investigation progresses. Updates and more information will be provided on this page as it becomes available.