On May 7, in the midst of final exams, the Canvas learning management system’s login page was plastered with a roughly $10 million ransom demand from the ShinyHunters cyber criminal group. So, as students submitted their finals and teachers prepared to post final grades, they suddenly found that the home to the grading data for 8,809 schools and universities across the country was under threat.
While students and teachers were panicking, education cybersecurity teams scrambled to respond. Michael Klein, the Senior Director for Preparedness and Response at the Institute for Security and Technology (IST), joined a call with leaders from one state as they wrestled with fallout from the incident. “[T]hey were making a live decision about whether to cut access [to Canvas],” recounted Klein, who felt the situation was surreal, “being there and thinking ‘Oh, my gosh, are we gonna cut this off for an entire state? Like, all in this one moment?'”
The “Break Glass Moment”
The path to the ransom note, and the panic it caused, began around a week earlier. According to disclosures, Instructure–the parent company of Canvas–initially detected unauthorized activity in the Canvas learning management system on April 29, after ShinyHunters gained access to the site through exploiting a cross-site-scripting vulnerability tied to the Free-For-Teacher product. The breach, likely the largest cybersecurity incident impacting the education sector to date, affected 8,809 universities, school districts, and other institutions. On May 1, Instructure publicly disclosed the incident, claiming the threat had been resolved.
On May 7, the threat actors posted the ransom note from inside of the Canvas system. “It was kind of a break-glass moment,” said Klein. “I knew everyone was about to freak out,” because the ransom note demonstrated that the threat actors were still in the system. This transformed the incident from a large but manageable data breach, where Instructure claimed to have evicted the threat actors, to a live incident that would have real impacts for universities and school districts. Although the ransom threat was only visible on the login screens of approximately 300 Canvas customers, screenshots of the note had gone viral on social media and were being reported in local news across the country. “I had a sense that there was going to be a real loss of faith from everybody at that moment.”
The threat actors were able to enter Canvas a second time via another cross-site-scripting vulnerability in the free-for-teachers product. As a result, Instructure temporarily took Canvas offline and universities and school districts severed their connections to the platform. The following day, Klein convened a call with leaders from 22 states to provide real-time situational awareness. On May 11, Instructure released an apology and claimed they had “reached an agreement” with the threat actors. That same day, Klein convened 24 states for a second meeting to share best practices and to gather perspectives on whether or not to reconnect to Canvas. Many school districts and universities struggled to decide whether they should trust that the threat had been successfully resolved. While Instructure dealt with the breach in data, Klein and his colleagues across the education sector dealt with the breach in trust. “There were so many meetings in so few days.”
A Tale of Two Breaches
While the Canvas incident was unique in its scale and specific chain of events, it was not Klein’s first rodeo. Less than two years before the Canvas incident, another educational software vendor had suffered a major data breach. The PowerSchool student information system incident impacted over 60 millions students and 9 million educators. However, two key things made the PowerSchool incident fundamentally different from the Canvas incident: PowerSchool only notified impacted institutions after the incident had been resolved with the threat actor, and the PowerSchool incident did not cause an operational disruption to the school districts using the system. At the time, Klein was working in the Department of Education as the Senior Advisor for Cybersecurity. PowerSchool became his template for crisis response. Immediately following the incident, he convened 41 states and Guam through the K-12 Government Coordinating Council he had helped stand up. In the time between the PowerSchool and Canvas incidents, those governmental structures were dismantled, and Klein took his expertise and experience handling the PowerSchool incident from the government to the non-profit world, where he launched IST’s K-12 Cyber Defense Coalition (K12 CDC).
In the Room Where it Happened
Per Klein, “[It] was really about…how do we coordinate what is about to become a very messy incident response situation across thousands of organizations, in a world where, unfortunately, the Department of Education and the federal government no longer have the capacities and authorities to actually lead here?”
Bringing together state leadership and affected parties can be “incredibly helpful as a policymaker. It’s also very helpful for an affected entity to feel like someone is listening to you and to feel like there’s direction,” Klein explained. “It can feel really chaotic…if there’s not a convener…bring[ing] folks together…and so I wanted to, if possible, create that.”
Hoping to provide direction, Klein stepped up to the plate, and convened two meetings with over 30 states represented in the aftermath of the Canvas incident. To run those meetings, Klein drew on the same “playbook” that he had followed in the PowerSchool incident, building upon existing relationships. No longer working in the Department of Education, Klein was “reaching out as…someone who knew a lot of the folks in the room, and understood the problem, but was …going on the trust of those relationships…as opposed to kind of a positional authority.”
To Trust or not to Trust? That is the Question…
The meetings focused on operational triage, vendor accountability, and challenges with the vendor’s communication. During the meetings, “[state] leaders noted that many schools remained disconnected because they did not trust that Instructure had full control of their environment.” Scoping the damage was difficult. ShinyHunters posted a list of victims, but no one knew how accurate it was, and the level of centralization varied widely between states. Some states could shut off Canvas statewide with a single decision, while others completely lacked visibility and relied on district by district outreach. Many states and educational institutions chose to disconnect from Canvas in order to circumvent the threat.
Reconnecting was the harder call: “The big question is, how safe is safe enough… [and] what kinds of assurances do you need as a state that’s making this decision on behalf of hundreds of thousands, or even millions of people?” That decision, Klein claims, was reliant on three major factors: how urgently Canvas was needed for students to graduate, whether other sensitive systems were connected to Canvas, and whether they had the capacity to do their own risk assessment— capacity that larger institutions had and smaller ones often did not. “The thing underlying all of those is this question of trust — what do you do to reestablish trust when trust is broken?”
Filling the Vacuum
Klein emphasized the importance of the now-disbanded coordinating structures both during and leading up to an incident. Having built “trust over time with a group of institutions and a group of people” before a crisis is essential in making things work in the event of an emergency. The Critical Infrastructure Partnership Advisory Council (CIPAC), a Department of Homeland Security framework that facilitated communication between federal agencies and private-sector critical infrastructure owners and operators, had provided both a “trust-building mechanism” and a way to “deploy it on a monthly basis” and thus “have these conversations in a way that become practiced.” However, it was suspended in early 2025, and no replacement existed during the Canvas outage.
At times, the lack of federal incident coordination capacity and authorities left Klein feeling like “one person holding together a sector… the vendors were reaching out to me to talk about what vendors need, and the states are reaching out to me, and I’m convening the states…”
But what can feel like an overwhelming task for one person actually represented the powerful collaboration of K-12 CDC members like the K12 Security Information eXchange (K12 SIX), as well as national coordination with state cyber and education leaders from the National Association of State Chief Information Officers (NASCIO) and the Council of Chief State School Officers (CCSSO).
Treating the Symptoms, Not the Disease
Looking ahead, Klein believes “the easiest [policy change] that doesn’t require Congress is CIPAC.” While CIPAC no longer exists within the Department of Homeland Security, a couple months after the Canvas incident, Anchor CI was launched by the Department of Homeland Security and CISA. While not the same as CIPAC, Anchor CI seems to be tackling similar goals. “I’m glad that they have something in place now.” Klein also suggested reestablishing the K12 Government Coordinating Council within the Department of Education in order to assist with coordination in the event of a crisis. Longer term, he wants a fully funded sector risk management agency: “It aligns with the priorities that almost any administration would think are a good thing.”
But better coordination only addresses the response to the issue, not its root cause. For both PowerSchool and Canvas, attackers continue to exploit similar commonly exploited vulnerabilities. “[Coordination] doesn’t address the core issue of…why do the vendors keep falling short on these very basic things that hurt lots and lots of people? That’s a deeper conversation that we need to have,” Klein reflected.
Invisibly Important
The coordination work that followed the Canvas breach never made headlines the way the ransom note did. No one wrote about the states that reconnected safely, or the work that went into rebuilding trust, one call at a time. Coordination work like that only becomes visible in its absence; in the chaos of not having it. In the eye of the storm, Klein and his partners in the K-12 CDC provided direction and a way through the noise, all while staying out of sight.
In the event of a cyber attack, the importance of guidance – informed by experience, mutual trust, and expertise – cannot be understated, especially as advances in artificial intelligence seem poised to increase the frequency of cyber attacks. And yet, official guidance on cybersecurity continues to be understated and underfunded. Until that changes, the sector will keep relying on invisible work to hold together what visible institutions no longer do.
