A ransomware attack against a SaaS provider your institution cannot directly control creates unavoidable operational exposure — final exam disruptions affect academic calendars, accreditation standing, and student satisfaction in ways that compound over weeks. If student or faculty data was exfiltrated, institutions face notification obligations under FERPA and applicable state breach laws, with regulatory and reputational consequences independent of Instructure's own liability. The SaaS dependency model means your security posture is bounded by your vendor's — and you have no direct remediation lever.
You Are Affected If
Your institution uses Instructure Canvas as a cloud-hosted (SaaS) LMS
Your environment has SSO or API integrations connecting Canvas to internal systems or identity providers
Users reuse Canvas credentials across other institutional or personal accounts
Your institution stores student records, grades, or PII in Canvas
You have not yet received a formal breach notification or incident summary from Instructure
Board Talking Points
A ransomware attack against our LMS vendor, Instructure Canvas, disrupted final exams nationwide and involved a data breach affecting student and faculty data we cannot fully scope without vendor disclosure.
Leadership should request a formal incident report from Instructure within 48 hours and engage legal counsel to assess FERPA notification obligations pending breach scope confirmation.
Without a vendor-provided scope assessment, we cannot rule out data exposure that triggers mandatory breach notification — delay increases regulatory and reputational risk.
FERPA — Canvas stores student educational records; a breach of Instructure's systems constitutes potential unauthorized disclosure of protected student data requiring institutional assessment of notification obligations
State Breach Notification Laws — PII (names, email addresses, institutional credentials) held in Canvas may trigger notification requirements under applicable state statutes depending on confirmed data types exfiltrated