Brevard Public Schools, Florida Institute of Technology, and Eastern Florida State College have restricted access to the Canvas learning platform after a global ransomware attack impacted nearly 9,000 schools. The cybercriminal group ShinyHunters claims to have stolen 275 million records from Instructure, Canvas’s parent company, and threatened to publish the data on May 12 unless a ransom is paid.
A Brevard Public Schools spokesperson confirmed the district disabled Canvas access on May 7 as a precaution. 'There is no evidence that any Brevard systems or data have been compromised,' the statement said. The district is among institutions listed on ShinyHunters’ dark web leak. Florida Tech has directed users to reset passwords, while EFSC’s website shows a service outage notice without detailing the breach.
The attack targets Instructure, a Utah-based company that provides Canvas to schools nationwide. ShinyHunters alleges it breached the company’s systems, though Instructure has not publicly confirmed the incident. Brevard schools have communicated with families and staff about the disruption, but no data breaches have been detected locally.
The ransom deadline looms as May 12, with hackers threatening to release stolen data if demands are unmet. Officials in Brevard County have not commented on potential ransom payments. Meanwhile, Florida Tech and EFSC have not issued detailed statements beyond urging password resets and acknowledging service issues.
The breach could be one of the largest in U.S. education history, affecting students, teachers, and staff across the globe. Local institutions are now navigating the fallout as they await updates from Instructure on resolving the cybersecurity incident.