Skip to main content
notice

A major higher education cybersecurity breach reveals the urgency of cyber awareness

Staying alert and completing training are key to protecting Concordia from cyber threats
May 13, 2026
|

In early May 2026, a major cybersecurity incident involving Canvas, one of the world’s most widely used learning management systems (LMS), shocked the higher education sector in Canada and around the world. Hackers linked to the group ShinyHunters claimed responsibility for breaching Canvas’ systems, reportedly accessing data connected to nearly 9,000 institutions worldwide and affecting up to hundreds of millions of users.

Here in Canada, major institutions including University of Toronto, University of British Columbia, and University of Alberta were among the directly affected institutions. The breach triggered major outages and disruptions during final exams and risked having the data of Canvas users exposed.

What this means for Concordia

It’s important to emphasize that Concordia University was not impacted by this breach, as we do not use Canvas as our learning management system. However, this incident is a powerful reminder of the broader cybersecurity risks facing universities today. Learning platforms and other digital tools are deeply embedded in teaching, grading, research, communication, and student services. When those centralized systems are attacked, the impact can be extremely disruptive on campus but also for the individuals affected.

The Canvas breach also highlights the dangers associated with elevated or “admin” access. Accounts with administrative privileges are especially valuable targets for attackers because they provide broader access to systems and data. At Concordia, admin rights are granted only when absolutely necessary and are carefully managed. Still, individuals with elevated access must remain particularly vigilant. A single compromised admin account can significantly amplify the impact of an attack.

Concordia is committed to ensuring the security of the whole community's data and digital ecosystem amidst evolving cyber threats. Concordia continues to invest in technical safeguards, monitoring, and partnerships, while IITS cyber security teams work continuously to detect threats, apply patches, and limit exposure. From multi-factor authentication to the new email policy, IITS is working with the Concordia community to implement new cyber security initiatives to stay ahead of hackers.

Why cybersecurity training matters

One of the most effective defenses against cyberattacks is cybersecurity awareness training. These programs help to ensure that you can recognize real-world threats, understand how attacks unfold, and know what to do when something doesn’t look right.

Most large-scale breaches begin with small entry points, such as a convincing phishing email, an attachment, or a stolen login. Cyber security training equips you to spot red flags before they turn into major incidents that put academic work, research, and personal data at risk.

Concordia students have access to short, practical training capsules to learn how to spot phishing attempts, recognize impersonation tactics, protect your information, and use AI tools safely.

Faculty and staff are required to take one mandatory training and they have access to a whole series of cybersecurity trainings on Carrefour to stay informed, confident, and secure in their day-to-day work.

Other actions to take to protect yourself and the community

Cybersecurity is everyone’s responsibility

The Canvas incident underscores just how interconnected and vulnerable the higher education digital landscape has become. Protecting our community’s data, teaching, research, and reputation is up to all of us.
 

Learn more about IT Security and privacy at Concordia and what you can do to help keep our community safe.

 




Back to top

© Concordia University