{
  "id": "2026-05-07-skagit-valley-college-canvas-security-incident-outage",
  "slug": "skagit-valley-college-canvas-security-incident-outage-2026-05-07",
  "institution": {
    "name": "Skagit Valley College",
    "shortName": "SVC",
    "state": "WA",
    "type": "community-college",
    "alertSystemName": "SVC Alert / Emergency Communications",
    "enrollment": 8000
  },
  "incident": {
    "date": "2026-05-07",
    "endDate": "2026-05-08",
    "type": "cybersecurity",
    "cleryCategory": "emergency-notification",
    "resolution": "resolved",
    "headline": "Canvas outage after third-party learning-platform security incident",
    "headlinePublic": "Canvas outage after third-party learning-platform security incident",
    "summary": "On May 7, 2026, [Skagit Valley College notified the community that Instructure reported a security incident affecting portions of Canvas](https://www.skagit.edu/security-services/emergency-communications.html), temporarily making Canvas unavailable. Follow-up notices on May 8 reported service restoration and later full restoration with vendor findings about Free-For-Teacher account vulnerabilities.",
    "outcome": "Canvas was restored the evening of May 7 (confirmed ~9:15 p.m.) with some residual user reports overnight; by May 8 11:05 a.m. SVC reported full restoration. No indication SVC systems were compromised.",
    "casualties": {
      "killed": 0,
      "injured": 0
    }
  },
  "alerts": [
    {
      "sequence": 1,
      "type": "initial",
      "channel": "email",
      "verbatimText": "Skagit Valley College has been notified by Instructure, the vendor that operates the Canvas learning management system, of a recent security incident affecting portions of its platform. Based on information currently available, certain SVC user information may have been involved in the incident.\n\nAt this time, there is no indication that Skagit Valley College systems, networks, or infrastructure were compromised. The incident occurred within the third-party vendor environment used to provide Canvas services to colleges and universities across the country. Canvas is currently unavailable as Instructure continues responding to the incident. We will continue to monitor and provide updates regarding platform availability and related information as additional details become available.\n\nAccording to information provided by Instructure, there is currently no evidence that passwords, Social Security numbers, dates of birth, financial information, or other sensitive government-issued identifiers were involved in this incident. The vendor's investigation remains ongoing, and additional information may become available as their review continues.\n\nAlthough the current risk appears limited, incidents of this nature may increase the likelihood of phishing attempts, ransomware-related messages, fraudulent emails, text messages, phone calls, or other scams that attempt to appear legitimate. Members of the college community may receive communications that reference Canvas, coursework, institutional business, or account activity in an attempt to create urgency or solicit personal information. We encourage all students, faculty, and staff to remain especially vigilant in the coming weeks.\n\nPlease use caution when:\n\nOpening unexpected emails or attachments\nClicking links requesting login credentials or personal information\nResponding to messages that create urgency or request sensitive information\nReceiving communications that appear to reference Canvas conversations, coursework, or institutional business unexpectedly\nReceiving suspicious messages related to ransomware, payment demands, account verification, or technology support requests\n\nSkagit Valley College will never request passwords, Social Security numbers, banking information, or multifactor authentication codes through unsolicited email, phone calls, or text messages.\n\nAs a precaution, members of the college community are encouraged to:\n\nMonitor their accounts for unusual activity\nUse strong and unique passwords\nReport suspicious emails or messages to the SVC Information Technology department\nAvoid clicking on unfamiliar links, even if the message appears to come from a known source\n\nIf you receive suspicious communications, believe you may have interacted with a fraudulent message, or have concerns related to this incident, please contact the SVC Information Technology support team at mv.help@skagit.edu for assistance.\n\nThe college is actively reviewing the information provided regarding this incident and will continue coordinating with appropriate parties as necessary to better understand the scope of the event and determine whether any additional actions are warranted.\n\nWe appreciate your patience and partnership as we continue to monitor this situation and provide updates as appropriate.",
      "isVerbatimConfirmed": true,
      "sourceUrl": "https://www.skagit.edu/security-services/emergency-communications.html",
      "sourceDescription": "SVC Emergency Communications — May 7, 2026 Canvas security incident",
      "characterCount": 3291,
      "annotations": [
        "Verbatim text transcribed from the official SVC or university page cited in sourceUrl."
      ],
      "timestampApprox": "2026-05-07 midday (exact clock time not stated on archive page)"
    },
    {
      "sequence": 2,
      "type": "update",
      "timestamp": "2026-05-08T08:30:00-07:00",
      "channel": "email",
      "verbatimText": "Canvas is currently accessible once again. Service was restored last evening around approximately 7:30 p.m., with confirmation from Canvas around 9:15 p.m. However, some users reported Canvas difficulties after this time. We are not currently seeing continued issues in Canvas.\n\nPlease see yesterday's message below from campus leadership regarding the overall security breach related to the outage. We encourage continued caution with any suspicious links, images, or attachments claiming to be related to Canvas.\n\nIf you encounter ongoing difficulties within Canvas, such as tools not functioning properly, please contact eLearning@skagit.edu.",
      "isVerbatimConfirmed": true,
      "sourceUrl": "https://www.skagit.edu/security-services/emergency-communications.html",
      "sourceDescription": "SVC Emergency Communications — May 8, 2026 8:30 a.m. service restored",
      "characterCount": 645,
      "annotations": [
        "Verbatim text transcribed from the official SVC or university page cited in sourceUrl."
      ]
    },
    {
      "sequence": 3,
      "type": "update",
      "timestamp": "2026-05-08T11:05:00-07:00",
      "channel": "email",
      "verbatimText": "Skagit Valley College would like to provide an update regarding the recent security incident involving Canvas, the learning management system operated by Instructure.\n\nCanvas services have now been restored and are fully available for use. According to information provided by Instructure, the vendor identified and contained the unauthorized activity and temporarily placed portions of the platform into maintenance mode as a precautionary measure while the issue was investigated.\n\nWhat Happened\n\nInstructure has informed the Washington State Board for Community and Technical Colleges (SBCTC) that the unauthorized activity involved changes made to pages viewed by some students and instructors while logged into Canvas.\n\nThe vendor reports that it worked with an independent forensic partner and, at this time, has found no evidence that the unauthorized actor:\n\nObtained institutional account credentials\nEstablished persistent access within the environment\nExfiltrated additional data related to SVC users\n\nAccording to Instructure, the incident originated through vulnerabilities associated with Canvas Free-For-Teacher accounts, which have since been temporarily disabled while additional security measures are implemented.\n\nImpact to Skagit Valley College\n\nAt this time, there continues to be no indication that SVC systems, networks, or infrastructure were compromised.\n\nInstructure has also stated there is currently no evidence that passwords, Social Security numbers, dates of birth, banking information, or other sensitive government-issued identifiers were involved in the incident.\n\nReminder to Remain Vigilant\n\nAlthough Canvas services have been restored, members of the college community are encouraged to remain vigilant regarding potential phishing attempts, fraudulent emails, or suspicious messages that may attempt to leverage awareness of this incident.\n\nPlease continue to use caution when:\n\nOpening unexpected communications\nClicking unfamiliar links\nResponding to requests for personal or institutional information\n\nImportant Reminders\n\nSVC will never request passwords, multifactor authentication codes, Social Security numbers, or banking information through unsolicited email, phone calls, or text messages.\nSuspicious messages or cybersecurity concerns should be reported to the Information Technology department at mv.help@skagit.edu.\nUsers are encouraged to continue monitoring accounts for unusual activity and maintain strong, unique passwords.\n\nThe college will continue coordinating with Instructure and monitoring any additional information related to this incident.\n\nWe appreciate your patience, understanding, and partnership as we worked through this disruption and restored services to the campus community.",
      "isVerbatimConfirmed": true,
      "sourceUrl": "https://www.skagit.edu/security-services/emergency-communications.html",
      "sourceDescription": "SVC Emergency Communications — May 8, 2026 11:05 a.m. fully restored",
      "characterCount": 2749,
      "annotations": [
        "Verbatim text transcribed from the official SVC or university page cited in sourceUrl."
      ]
    }
  ],
  "context": "On May 7, 2026, [Skagit Valley College notified the community that Instructure reported a security incident affecting portions of Canvas](https://www.skagit.edu/security-services/emergency-communications.html), temporarily making Canvas unavailable. Follow-up notices on May 8 reported service restoration and later full restoration with vendor findings about Free-For-Teacher account vulnerabilities.",
  "keyFindings": [
    "Full English text recovered from the official SVC Emergency Communications page.",
    "Spanish parallel versions exist on the same page and were not transcribed as separate alerts."
  ],
  "sources": [
    {
      "title": "Emergency Communications (Skagit Valley College Security Services)",
      "url": "https://www.skagit.edu/security-services/emergency-communications.html",
      "type": "official-archive"
    }
  ],
  "confidence": "high",
  "tags": [
    "skagit-valley-college",
    "cybersecurity",
    "canvas",
    "community-college"
  ],
  "dateAdded": "2026-07-27",
  "lastUpdated": "2026-07-27",
  "addedBy": "ingestion"
}
