Instructure Holdings, Inc. (Instructure), the parent company of the Canvas Learning Management System (Canvas), recently disclosed an ongoing cybersecurity incident affecting Canvas platforms used by K–12 schools and institutions of higher education worldwide. This incident involves unauthorized access to usernames, email addresses, course names, enrollment information, and messages. While some messages may incidentally include personally identifiable information, Instructure stated on their public web page that there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. A ransomware group identified as ShinyHunters claimed responsibility and repeatedly defaced Canvas login pages with ransom demands. Some institutions reported receiving ransom messages when attempting to access Canvas. For the latest verified information from Instructure, institutions should continue to monitor the Instructure Status Page at instructure.com/incident_update. Senior U.S. Department of Education (ED) leaders have been actively engaged with Instructure regarding this incident. ED is in contact with Instructure’s chief information security officer about technical details; the affected systems; the population of impacted institutions; and steps to protect students, teachers, school districts, K-12 schools, and institutions of higher education. ED’s office of Federal Student Aid (FSA) is coordinating with federal partners and continues to analyze incoming information as the investigation progresses. ED’s Student Privacy Policy Office has also requested information from Instructure to ensure compliance with the Family Educational Rights and Privacy Act or FERPA. Schools are reporting Canvas-related impacts to ED, consistent with existing incident-reporting requirements. ED continues to track every school that reports it received notice from Instructure or observes suspicious activity. Institutions of higher education should report incidents using established channels, including: - Email: FSASchoolCyberSafety@ed.gov If your institution receives a ransom message, threat communication, or evidence of unauthorized access through Canvas, please report immediately. Instructure publicly confirmed that bad actors compromised the Canvas platform through Free-For-Teacher accounts,