MiraCosta College, Palomar College and California State University San Marcos were among San Diego County campuses responding to a widespread cybersecurity incident Thursday, May 7, tied to the Canvas learning management system, throwing a wrench into final exam and late semester schedules.
The event prompted warnings to students and faculty not to access the platform and to remain alert for phishing and ransomware-related scams. The incident also affected K-12 school districts that use the platform.
By Friday morning, access to the online learning management system had largely been restored. As of Friday afternoon, CSUSM and SDSU access was reportedly open, but community college access was still not fully restored.
The outage occurred after a ransom cyberattack by a group called ShinyHunters.
“ShinyHunters is a financially motivated data theft and extortion gang that formed in 2019 and first emerged publicly in January 2020,” according to Halcyon Ransomware Research Center. “ShinyHunters does not currently employ ransomware encryption as part of its campaigns. Instead, the gang operates under a ‘pay or leak’ extortion model where they exfiltrate data from cloud platforms, software environments, and third-party integrators, then demand ransom under threat of public release.”
In an announcement explaining the event, Instructure, the parent company of Canvas, reported that an attack was first detected April 29, which was then under investigation. By May 7, more unauthorized activity had been discovered, which led to the system’s shutdown.
“The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas. Out of caution, we temporarily took Canvas offline into maintenance mode to contain the activity, investigate, and apply additional safeguards,” Instructure stated. “We have since confirmed that the unauthorized actor carried out this activity by exploiting an issue related to our Free-For-Teacher accounts.”
Instructure has temporarily shut down its Free-For-Teachers accounts, which the company stated was a difficult decision because they “have been a core part of our platform, and we’re committed to resolving the issues with these accounts.”
The outage came as final exams were set to begin at California State University San Marcos and San Diego State University, raising concerns about disruptions to assignments, testing and communication between instructors and students.
At MiraCosta College, officials issued an alert Thursday afternoon stating that the cybersecurity event involving Instructure Canvas had “escalated,” directing faculty and students to fully exit the system and avoid attempting to log back in until further guidance was provided.
The college also warned users to remain alert for suspicious emails, phishing attempts and unusual account activity.
Palomar College issued similar guidance Thursday after reporting that Canvas was unavailable due to what officials described as a cybersecurity attack on Instructure.
In updates posted by the college’s Academic Technology Resources Centers, Palomar instructed users to fully exit Canvas and not attempt to log back in until official communications indicated it was safe to do so. The college said no other Palomar systems appeared to be affected at the time.
Officials also cautioned employees and students against clicking unfamiliar links or responding to suspicious messages related to account verification or password resets.
At California State University San Marcos, students and faculty were also affected as part of the broader California State University system response to the outage.


