Ian Linkletter

@Linkletter
1,051 Followers
448 Following
327 Posts
Emerging Technology & Open Education Librarian standing for freedom of expression, fair dealing rights, and academic freedom.
Stand Against Proctorio's SLAPP!https://linkletter.org
Canadian Privacy Libraryhttps://privacylibrary.ca
Blueskyhttps://bsky.app/profile/linkletter.org

I had a great conversation with Dexter Thomas about protecting students, institutional accountability, and rethinking our reliance on the LMS.

https://youtu.be/Tu9QbSIFwQc?si=s06g5F_lTfGg744g

the canvas hack isn't over

YouTube
Someone on Bluesky corrected me that the "any lawful purpose" language has actually been in there since 2024. It's the AI language that's new.

What is Instructure doing with user data?

On April 17, 2026, this "Usage Data" section had language added saying Instructure can use this data for "any lawful purpose". It prohibits customers from using their data to train AI, while allowing themselves to do so.

https://web.archive.org/web/20260513021744/https://www.instructure.com/policies/mastertermsconditions

Ransom paid!

"Instructure reached an agreement with the unauthorized actor involved in this incident."

https://www.instructure.com/incident_update

Wow! Unable to confirm security, UBC has still not reopened access to Canvas, instead choosing to pivot to open source for continuity! WordPress, MediaWiki, and Moodle (!) are being offered as alternatives.

This is open educational technology at its best!

https://ltic.ubc.ca/alternative-course-hosting/

It has been my mission for the past week to warn the public about the pending harms of the Instructure/Canvas hack.

I told 404 Media it is “the biggest student data privacy disaster in history” and am grateful I was able to share my concerns and help students.

https://www.404media.co/the-biggest-student-data-privacy-disaster-in-history-canvas-hack-shows-the-danger-of-centralized-edtech/

'The Biggest Student Data Privacy Disaster in History': Canvas Hack Shows the Danger of Centralized EdTech

Messages could include "medical circumstances, accessibility accommodations, disputes, sexual assault allegations," and more.

404 Media
New Wikipedia page for the Canvas hack: https://en.wikipedia.org/wiki/2026_Canvas_security_incident
2026 Canvas security incident - Wikipedia

Everywhere in the world, students using Canvas saw this message:

"ShinyHunters has breached Instructure (again)... You have till the end of the day by 12 May 2026 before everything is leaked."

https://www.theverge.com/tech/926458/canvas-shinyhunters-breach

Canvas is down as ShinyHunters threatens to leak schools’ data

Instructure’s learning management platform Canvas is down, after recently confirming a data breach and a ransom message from the ShinyHunters hacking group.

The Verge

BREAKING: Instructure has been hacked AGAIN. Students are posting to Reddit after seeing this message within Canvas.

"ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some "security patches".`

More reports are being posted to Reddit every minute: https://old.reddit.com/search/?q=canvas&include_over_18=on&t=hour

I thought I would post screenshots of Instructure's status update regarding the Canvas LMS data breach. A notice has been added that there will be no more public updates to this page.

Despite the stated commitment to transparency, it is not clear how this could have happened.

https://status.instructure.com/