After hack, Maastricht University disconnects Canvas “as a precaution”: learning platform unusable

After hack, Maastricht University disconnects Canvas “as a precaution”: learning platform unusable

Hackers threaten to release personal data following an attack on Canvas

08-05-2026 · News

MAASTRICHT. Hackers, who revealed earlier this week to have stolen personal data following a cyberattack on the educational software Canvas, struck again on Thursday evening on various Canvas websites. This prompted Maastricht University to completely disconnect the educational application from all systems, “as a precaution,” according to a spokesperson.

Maastricht University’s Canvas environment, like some 9,000 other educational institutions worldwide, was affected by the hack. In an email to UM students and staff on Wednesday it was announced that “it cannot be ruled out” that data, such as email addresses, may have been leaked. A warning was therefore issued regarding phishing emails. However, after implementing a number of security measures, the message concludes that “it is safe to use Canvas.”

But a day later, the hackers posted a message on various Canvas websites. They claim to have cracked the program again. According to UM spokesperson Koen Augustijn, it is unclear whether this also happened in the Maastricht Canvas environment. In response, UM decided to disconnect all systems still connected to the application. As a result, Canvas is unusable. It is clear that this is causing problems for students and staff, but Augustijn does not know how significant the problems are. He also cannot yet answer the question of when Canvas will be back online.

Deadline

The cyberattack was claimed by ShinyHunters, a hacker group previously involved in the Odido breach. Initially, the American company Instructure, the company of Canvas, was given until Wednesday to pay a ransom, or else all data would be made public. But the deadline has now been pushed back by six days, ShinyHunters reports on its website.
According to the group, several institutions have made contact (though not UM). Universities and colleges have until 12 May to negotiate to keep their data private. According to the group, Instructure itself has not yet made contact.

Ransom

Following the hack on Odido, the government issued urgent advice not to pay hackers a ransom. It is quite possible that hackers will not keep their promises. “Paying ransom perpetuates the criminals’ business model,” wrote the Minister of Justice and Security, David van Weel, at the time.

In December 2019, UM fell victim to a major ransomware attack. To regain access to its data, the university decided to pay 200,000 euros in ransom in bitcoins. In March 2025, the university received the amount back in its bank account. The police and the Public Prosecution Service had tracked down part of the amount fairly quickly, in 2020, and managed to freeze a “wallet” containing 40,000 euros in cryptocurrency. When they finally succeeded in transferring the money to the Netherlands, its value had risen to half a million euros.

Wendy Degens/ HOP

Author: Redactie

Illustration: Simone Golob

Categories: news_top, News
Tags: hack, cyberattack, canvas

Add Response

Click here for our privacy statement.

Since January 2022, Observant only publishes comments of people whose name is known to the editors.