Connect with us

Latest

School app Canvas breach hits during finals

Published

on

Finals week is stressful enough without your school’s main classroom app suddenly going dark.

That is what many students faced when Canvas, the school platform used by colleges, universities and K-12 schools, went down for several hours. The outage came after Instructure, the company behind Canvas, detected unauthorized activity tied to a cybersecurity incident on the platform.

For students and teachers, this was more than a tech glitch. Canvas is where many schools post assignments, messages, grades, class updates and exam instructions. So when access disappeared, it created confusion at the worst possible time.

Sign up for my FREE CyberGuy Report

WHY LAST YEAR’S BREACH IS THIS YEAR’S IDENTITY FRAUD

Instructure says it detected unauthorized activity in Canvas on April 29, 2026. The company said it immediately revoked the unauthorized party’s access, started an investigation and brought in outside forensic experts.

Then, on May 7, Instructure said it identified additional unauthorized activity tied to the same incident. The company said the unauthorized actor made changes to pages that appeared when some students and teachers were logged in through Canvas.

Out of caution, Instructure temporarily took Canvas offline into maintenance mode to contain the activity, investigate and apply additional safeguards.

Instructure said it later confirmed that the unauthorized actor exploited an issue related to its Free-For-Teacher accounts. The company said this was the same issue that led to the unauthorized access the prior week.

In a statement to CyberGuy, Instructure said, “Instructure discovered the unauthorized actor involved in our ongoing security incident made changes to the pages that appeared when some students and teachers were logged in. Out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate. We have confirmed that the unauthorized actor exploited an issue related to our Free-For-Teacher accounts. As a result, we have made the difficult decision to temporarily shut down our Free-For-Teacher accounts. This gives us the confidence to restore access to Canvas, which is now fully back online and available for use. We regret the inconvenience and concern this may have caused.”

That detail is important because it explains how the company says the attacker gained access. It also shows why Instructure took a more aggressive step after the May 7 activity.

The timing made the outage especially frustrating. Students across the country are preparing for finals or already taking them.

Several schools reported problems with Canvas access. Student newspapers at Harvard, the University of Pennsylvania, Duke, UCLA and the University of Nebraska were reportedly blocked from using Canvas and saw a message from the hacking group ShinyHunters.

Think about how that feels if you are a student. You may need to submit a paper, check exam details or message a professor. Then the system you rely on suddenly stops working.

That is the real-life problem with school tech. When one major platform goes down, the disruption spreads fast.

A hacking group called ShinyHunters claimed responsibility for the attack. The group reportedly threatened to leak school data unless it heard from affected schools by May 12, 2026.

The group also claimed it had data tied to nearly 9,000 schools and about 275 million people. Those numbers come from the hackers’ claims. Instructure has not publicly verified that full scale.

That is worth keeping in mind. Cybercriminals often use big numbers to create panic and pressure victims. However, the confirmed incident is serious enough for schools and families to pay attention.

Based on Instructure’s investigation so far, the data taken in the April 29 incident includes certain personal information of users at affected organizations. That includes names, email addresses, student ID numbers and messages among Canvas users. Instructure said it has found no evidence that passwords, dates of birth, government identifiers or financial information were involved.

The company also said that, based on its investigation to date, it has not found evidence that data was taken during the May 7 activity. Still, Instructure said the investigation is ongoing.

Even so, this kind of information can still create problems. A scammer could use a student’s school email and Canvas details to send a fake message that looks official.

For example, a student may get an email that says a final exam file failed to upload. Another message may claim the student needs to verify a Canvas account. A fake IT alert could ask for a login code. That is how a data breach can turn into a phishing attack. 

Yes. Instructure says Canvas is fully back online and available for use. However, Free-For-Teacher accounts remain temporarily shut down while the company works through the issue.

The company also says its outside forensic partner reviewed the known indicators and found no evidence that the threat actor currently has access to the platform.

Instructure says it has revoked privileged credentials and access tokens tied to affected systems. It also says it deployed additional platform protections, rotated certain internal keys, restricted token creation pathways and added monitoring across its platforms.

Many parents may not know how much school life now runs through platforms like Canvas. Students use Canvas to track deadlines, get teacher updates, submit work and read class messages. Teachers use it to manage assignments and communicate with students.

That makes Canvas a tempting target. If criminals can disrupt access or steal user information, they can create chaos quickly. The bigger lesson here is that school accounts deserve the same protection as bank accounts or email accounts. They hold personal details, private messages and information tied to a student’s daily life.

HACKERS THREATEN TO LEAK DATA FROM 275M USERS AFTER BREACHING MAJOR COLLEGE PLATFORM USED NATIONWIDE

Even if passwords and financial details were not part of the breach, students and teachers should still stay alert. Scammers can use names, school emails, student ID numbers and message details to make fake alerts look convincing.

Be careful with any message that claims to come from Canvas, Instructure or your school’s IT department. Scammers may use urgent language. They may say your account will be locked, your exam file is missing, or your final grade is at risk. That pressure is the trick. Go directly to your school’s official website or Canvas login page instead of clicking links in surprise emails.

Instructure said it found no evidence that passwords were involved. Even so, follow your school’s instructions. If your school tells you to reset your password, do it right away. Choose a strong password you do not use anywhere else. A password manager can help you create and store unique logins for each account. Check out the best expert-reviewed password managers of 2026 at CyberGuy.com.

If your school offers multifactor authentication, turn it on. MFA adds another step when someone tries to log in. That extra step can stop a scammer who has your password. An authenticator app or passkey is stronger than a text code. Still, any MFA is better than leaving your account wide open.

No real school IT worker should ask for your password or login code. If someone asks for that information, treat it as a red flag. End the conversation and contact your school through an official help desk number or website.

Since Canvas messages may have been involved, think about what you shared there. Did you send personal details? Did you mention another account? Did you share private information with a teacher or classmate? You do not need to panic. But you should stay alert for messages that reference details from your Canvas account.

A breach like this can lead to phishing emails with malicious links or attachments. Strong antivirus software can help block malware, warn you about dangerous websites and protect your devices if you accidentally click the wrong link. Keep it updated on your phone, tablet and computer. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

Student and teacher information can end up on people-search sites and data broker databases. A data removal service can help reduce how much personal information is floating around online. That can make it harder for scammers to connect your school email, home address, phone number and other personal details. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.

If your school confirms that your personal information was involved, identity theft protection can help you spot suspicious activity faster. These services can monitor your personal information, alert you to possible misuse and help you respond if someone tries to use your identity. See my tips and best picks on Best Identity Theft Protection at CyberGuy.com.

Younger students may not recognize a fake school message. Parents should keep the warning simple. Tell students not to click unexpected links, share codes or respond to scary messages without checking first. A quick conversation now can prevent a bigger mess later.

Instructure says it notified impacted organizations on May 5, 2026. If a school or institution was affected, Instructure says it will contact that organization’s primary contacts directly.

For students, parents and employees, Instructure says the school or institution should be the first point of contact. It also recommends being cautious of unexpected emails or messages about the incident, avoiding suspicious links and reporting anything unusual to the school’s IT or security team.

Schools should also warn students and staff about follow-up scams. A breach does not end when the platform comes back online. For students and teachers, the risk can continue through fake emails, fake login pages and scam messages.

ADT DATA BREACH EXPOSES CUSTOMER INFORMATION

The Canvas breach shows how much school now depends on a few digital platforms. When one of them goes down, students feel it right away. The good news is that Instructure says it has found no evidence that passwords, financial data, birthdays or government IDs were involved. The tougher reality is that names, school emails, student IDs and private messages still have value to scammers. So the best move is to stay calm and stay skeptical. Use official school links. Turn on stronger login protection where possible and treat urgent messages with caution.

Should schools and tech companies do more to protect student and teacher data before a breach puts their privacy at risk? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading

Culture

Cracker Barrel Fans Outraged Again After NEW Major Change

Published

on

Cracker Barrel Fans Outraged Again  After NEW Major Change

Cracker Barrel built its reputation on comfort food, Southern tradition, and a menu customers could count on for decades.

That’s exactly why loyal diners are still fuming as the restaurant chain continues removing many of the classic dishes that helped make it a household name.

For years, customers have pleaded with the Tennessee-based chain to restore fan favorites that quietly disappeared from the menu, including black-eyed peas, fried haddock, red-eye gravy, fried chicken livers, and perhaps the most mourned item of all—the Sunrise Sampler.

For many longtime patrons, the Sunrise Sampler wasn’t just another breakfast. It was the breakfast.

The hearty platter came loaded with eggs, grits, fried apples, hash brown casserole, sausage, bacon, country ham, and biscuits with gravy—giving diners a taste of nearly everything Cracker Barrel had to offer without having to piece together a meal item by item.

“I noticed a while back that Cracker Barrel removed the GOAT of all breakfasts, the Sunrise Sampler, from the menu,” Josh Cooper, owner of Cooper’s Next Level BBQ in Tallahassee, Florida, told Fox News Digital. “You used to get a little bit of everything without breaking the bank.”

The meal hasn’t completely disappeared—but recreating it now comes with a catch.

Customers must order every component separately, turning what was once an affordable breakfast favorite into a considerably more expensive order.

“Now, in order to get that same teaser touch from the Sunrise Sampler, you have to order it all à la carte, which costs around $25 for the same great meal,” he said. “Blasphemy!”

Fox News Digital reached out to Cracker Barrel for comment.

The growing frustration over disappearing menu items comes after the company already faced a wave of backlash for attempting to modernize its image.

Last year, Cracker Barrel sparked outrage among longtime customers after unveiling a redesigned logo and updated restaurant interiors that many believed stripped away the rustic charm that had long defined the brand.

The changes were part of a sweeping $700 million overhaul across more than 660 locations, including menu revisions and a cleaner, less cluttered dining room design.

The company ultimately reversed course following widespread criticism, but many loyal customers say the damage had already been done.

The leadership shakeup continued last week when Cracker Barrel announced that CEO Julie Masino will step down on Aug. 10.

Former Bloomin’ Brands CEO David Deno is slated to take over.

For many customers, however, the issue extends far beyond a logo or a fresh coat of paint.

They believe corporate leadership has steadily chipped away at the very traditions that made Cracker Barrel stand apart from countless other restaurant chains.

Cooper said companies often underestimate the emotional attachment customers have to longtime menu favorites.

People are “asking for comfort and nostalgia.”

“The reality is that nostalgia matters. And when you remove popular items without controlling the narrative or managing customers’ expectations, you are bound to have upset patrons,” he said.

“Whether it’s due to rising food costs, kitchen timing or any other reason, it’s important to communicate with the people who put you on the map in the first place. Communication matters.”

Rachel Love, a self-described Cracker Barrel enthusiast from Tennessee, said one discontinued favorite remains at the top of her wish list.

“I absolutely loved the black-eyed peas, and I’m so glad they’re getting some attention,” Love told Fox News Digital. “They were one of my favorite sides and always felt like such a classic part of the Cracker Barrel experience.”

Love also hopes the restaurant revives its baked apple dumpling, describing it as “the perfect comfort dessert” for a brand built on old-fashioned hospitality.

To her, the debate is about much more than a handful of discontinued recipes.

“People aren’t just asking for old menu items — they’re asking for the comfort and nostalgia that came with them,” she said.

“Sometimes bringing back one classic dish means more to loyal customers than introducing several new ones.”

That may be the lesson Cracker Barrel continues to learn the hard way.

Customers aren’t asking the chain to reinvent itself.

They’re asking it to remember what made it successful.

They want the front porch.

They want the country store.

They want the breakfasts, the classic sides, and the timeless comfort food that turned Cracker Barrel into an American institution.

For many loyal diners, nostalgia isn’t a weakness.

It’s the brand.

Continue Reading

Latest

Mamdani Kicked Out — He’s Livid After Latest Announcement

Published

on

Mamdani Kicked Out — He’s Livid After Latest Announcement

Backlash against New York City Mayor Zohran Mamdani continues to mount, with the Democratic Socialist facing another public rebuke after reportedly being denied the opportunity to speak at the funeral of a U.S. Army soldier killed during an Iranian missile attack.

According to multiple reports, Mamdani attended Friday’s funeral for Army Sgt. Angel Sarah Rampersad in Queens but remained silent throughout the service after the soldier’s family reportedly chose not to have him address mourners.

Rampersad was one of three American service members killed in Jordan during an Iranian attack on July 17.

The funeral was held at a church in Ozone Park, where elected officials, community leaders, family members and fellow mourners gathered to honor the 28-year-old soldier’s sacrifice.

According to the New York Post, Mamdani appeared to review prepared remarks on an iPad while other dignitaries spoke, but his name was never called.

A source familiar with the funeral told The Post the decision came directly from Rampersad’s family, which reportedly wanted to keep politics out of the ceremony.

The family chose not to have Mayor Zohran Mamdani speak in an effort to avoid what the source described as “political distractions.”

After the funeral concluded, the mayor’s office released the remarks Mamdani had planned to deliver.

“It is often said that our fallen ‘gave their tomorrows for our today,’” Mamdani planned to say.

“Sergeant Rampersad had tomorrows waiting for her: birthdays, ordinary mornings, evenings spent with her loved ones,” his remarks continued.

“But she gave every one of them up so that we could have ours — so that we could stand here today, safe and protected,” he was to say.

New York Gov. Kathy Hochul, however, did address those gathered and offered an emotional tribute to the fallen soldier.

“I feel after reading and admiring this woman from a distance, I feel like she could be one of my daughters,” Hochul said.

Other speakers included Ozone Park Residents Block Association President Sam Esposito, state Sen. Joseph Addabbo Jr., and Queens Borough President Donovan Richards.

According to the Department of War, Sgt. Angel Sarah Rampersad, 28, of Ozone Park, New York, was killed in action during an enemy attack at Muwaffaq Salti Air Base in Jordan.

U.S. Central Command said Rampersad and two fellow service members were killed while American and coalition forces defended against Iranian ballistic missile and drone attacks.

The other fallen Americans were identified as 1st Lt. Tyler James Feehan, 25, of Ewa Beach, Hawaii, and Pvt. Isabella Gonzales, 19, of Carrollton, Texas.

All three were deployed to Jordan in support of Operation Inherent Resolve, the international mission to combat ISIS in Iraq and Syria.

Rampersad served with the 1st Battalion, 57th Air Defense Artillery Regiment, 52d Air Defense Artillery Brigade, 10th Army Air and Missile Defense Command in Ansbach, Germany.

She worked as a 25U Signal Operations Support Specialist, according to the Department of War.

One person who attended the funeral told the newspaper the mayor appeared visibly upset after realizing he would not be invited to speak.

“He looked over at his staff, frustrated and seemed angry that he didn’t speak,” the source told the Post.

The attendee said Mamdani eventually understood that his name would not be called, glanced toward members of his staff, and put away the tablet that reportedly contained his prepared remarks.

Another source cited by the newspaper said the decision reflected the wishes of Rampersad’s family, describing them as politically conservative and supportive of President Donald Trump.

“The family is more conservative and wanted to limit any political distractions,” the source told the Post.

Neither Mamdani’s office nor members of the Rampersad family have publicly confirmed the account explaining why the mayor was not invited to speak.

Although he never addressed the congregation during the service, the mayor’s office later publicly released the remarks he had prepared, bringing attention to a moment that underscored the growing political controversy surrounding New York City’s new mayor.

Continue Reading

Latest

GOP Just Passed It 232-288 — Pelosi And AOC Lose It On House Floor

Published

on

GOP Just Passed It 232-288 — Pelosi And AOC Lose It On House Floor

The House of Representatives delivered a major victory this week for Americans with disabilities who want the opportunity to work instead of being trapped by a broken federal bureaucracy.

In a bipartisan vote, lawmakers approved legislation aimed at dismantling long-standing barriers within the Social Security Disability Insurance program that critics say have discouraged work and punished self-sufficiency for decades.

H.R. 8884, the **Removing Barriers to Work for Disabled Americans Act**, sponsored by Rep. Austin Scott, R-Ga., passed the House by a vote of 232-188 and now heads to the Senate, where it has been referred to the Committee on Finance.

The legislation restores an important tool that the Social Security Administration lost when its demonstration authority expired in 2022.

Under the bill, the SSA would once again be authorized to test practical reforms under the Social Security Disability Insurance program through Dec. 31, 2030, with demonstration projects continuing through the end of 2031.

Rather than permanently rewriting federal law, the agency would be able to pilot innovative approaches designed to help beneficiaries who are able and willing return to the workforce.

The legislation includes significant safeguards. Participation would be entirely voluntary, and no participant could receive less total income as a result of joining one of the demonstration projects.

Supporters say those protections make the bill a common-sense effort to modernize a system that has too often discouraged Americans from pursuing employment.

House Ways and Means Committee Chairman Jason Smith, R-Mo., argued the current system is failing many of the very people it was designed to help.

“With over 60 percent of Social Security Disability Insurance recipients expressing an interest in returning to the workforce but less than one percent leaving the program because of a successful return to work each year, the Social Security Administration’s complex rules and regulations are clearly failing to deliver for too many Americans,” Smith said.

“Giving the SSA the authority to test innovative ways to better help disabled Americans pursue gainful employment is pure common sense, and this legislation goes a step further to ensure participation in any new system is both voluntary and will not reduce a beneficiary’s total income,” Smith added.

Smith pointed to what he described as a massive disconnect between Americans who want to work and those who are actually able to do so under the current system.

For years, disability recipients have warned that attempting to return to work can trigger a maze of complicated regulations, overpayment disputes, benefit cliffs, and uncertainty that ultimately makes taking a job financially risky.

Rather than encouraging independence, critics say the current structure often rewards staying on the sidelines.

Supporters argue H.R. 8884 takes a fundamentally different approach.

Instead of expanding government programs or imposing sweeping permanent reforms without evidence, the legislation gives the Social Security Administration the flexibility to test targeted solutions, evaluate the results, and determine what actually helps Americans reenter the workforce before making lasting policy changes.

Backers say the measure reflects a core conservative principle: government assistance should serve as a bridge to opportunity—not a permanent barrier to self-reliance.

The bill recognizes that having a disability does not automatically mean someone is unable to work and that federal policy should encourage those who are capable of seeking employment rather than penalizing them for trying.

The legislation also broadens the agency’s authority to include additional populations, including blind Americans, expanding the reach of future demonstration projects.

The proposal advanced through the House with bipartisan support after clearing the Ways and Means Committee, where lawmakers from both parties acknowledged that the current disability system leaves too many Americans behind.

Still, Republicans led the charge, arguing that practical reforms backed by measurable results are preferable to expanding entitlement programs or making permanent changes without first proving they work.

The bill now moves to the Senate, where lawmakers will decide whether to send it to President Donald Trump’s desk.

Supporters are urging swift action, arguing that restoring the SSA’s demonstration authority represents a fiscally responsible, low-cost reform that could help thousands of Americans regain the dignity, purpose, and financial independence that comes with meaningful work.

If enacted, the Social Security Administration would once again have the authority to launch carefully monitored pilot programs designed to improve employment outcomes, while reporting requirements would provide transparency and accountability as Congress evaluates which reforms deserve permanent consideration.

Continue Reading

Trending

Copyright © 2026 Political Signal