How safe is our data?

ShinyHunters’s attack on Instructure revealed vulnerabilities in UBC’s data management system. And we might not see the effects until 20 to 30 years from now, according to one computer scientist.

It's May 8, 2026, and Dr. Elizabeth ‘Biz’ Nijdam sits in her ninth-floor office in Buchanan Tower. The assistant professor is surrounded by colourful books and board games she uses as materials for her courses in the department of Central, Eastern and Northern European studies. A recurrent online Faculty of Arts meeting is playing in the background, and is discussing AI and teaching.

About a week prior, in a Salt Lake City office park, edtech developer Instructure detected unauthorized activity in its signature product: Canvas. The company was quick to identify the threat and remove it from the platform, but on the same afternoon that Nijdam listened to her colleagues debate the opportunities and challenges of AI, a new breach was detected. In a few hours, a criminal network known as ShinyHunters would take responsibility for an attack that compromised the personal data of 275 million Canvas users from nearly 9,000 universities worldwide, bringing the platform down for several days. The group provided a May 12 deadline for institutions to negotiate a settlement before leaking the breached information.

Nijdam turned to her screen and noticed the Canvas page she was working on was unresponsive. “I tried a few more times, and I was like, well, Canvas is down,” she told The Ubyssey. The roundtable was about to conclude when Nijdam was told there was an "emerging situation” that required a pause in discussion — it was the Canvas breach.

Administrators and department heads rushed to repeatedly communicate the urgency of the matter. As UBC reviewed the security of the platform, Canvas remained unavailable until May 15, marking a major disruption as summer classes got underway.

It's been more than a month since access was restored, but while some instructors rushed to shift to alternative platforms, and students remained confused about how to access final grades and summer classes, others saw a larger story developing — a story that connects concerns of instructors across B.C. with tech giants south of the border and hacker groups originating in Europe.

A letter to the privacy commissioner

Amid the Canvas calamity, a Thompson Rivers University professor decided to take action. Brenna Clarke Gray, an expert in educational technologies, crafted an open letter to the Office of the Information and Privacy Commissioner. The letter was signed by dozens of British Columbian academics, including some from UBC.

The OIPC is an independent provincial authority that regulates privacy protection in both private and public organizations, among other things. It researches the privacy implications of new technologies and policy, and can conduct investigations and audits into public bodies' compliance with the Freedom of Information and Protection of Privacy Act.

The signatories to Gray's letter want the OIPC to use that power. "As concerned educators and citizens, we are writing to request a compliance audit of the data handling by Canvas as it relates to data from within the province of British Columbia and of the risk assessment process by institutions, including University of British Columbia and Simon Fraser University, that led to the decision to opt for a cloud-based solution while BC-based solutions are available and in use at other institutions," the letter states. The letter also comes at a time of nationwide anxiety fuelled by the Trump administration's threats to Canadian sovereignty and tech billionaires’ growing power to shape society.

The letter goes on to argue that the audit would help British Columbians understand if risk assessment processes are impacting universities’ pursuit of U.S.-based cloud platforms. Clarke Gray said in an email tied to the letter’s release that educators' concerns over the dependence of B.C. institutions on U.S.-based platforms is compounded by the prospect of deeper integration with AI tools. The signatories are also asking for a review of the risk assessment processes used in the selection of cloud-based educational platforms, more transparency on cybersecurity and privacy standards, and clarification on how B.C. privacy laws are protecting sensitive educational communications.

Out of over 50 educators that signed the letter, seven are UBC professors — including Ben Britton, who is also a senator representing the Faculty of Applied Science. Britton told The Ubyssey the letter is a way for a group of interested educators to share concerns with their delegates and ask for help in the process of getting a “better solution at the end of it."

Nijdam was unaware of the letter and thus hadn't signed it, but she still had thoughts on how the incident played out. “I think it does warrant further investigation. We do need to seriously understand the consequences of some of these actions in light of increasingly vulnerable digital spaces and bad actors.”

Nijdam also said protecting historically marginalized communities’ data supports students who have chosen Canada as a refuge from persecution in countries like the United States. “Information is power around the world and ensuring that our own students are protected from … bad actors … should be a priority for not just UBC, but Canadian institutions."

Clarke Grey's open letter to the OIPC Dr. Brenna Clarke Grey / Thompson Rivers University

Costly trade-offs

For Britton, Canvas delivers practicality. “My interest in teaching students is not about how I upload my files or how I email my students, all of those things I don't want to think about. I want a system that is seamless,” he said. “Canada doesn't have [a] Silicon Valley creating lots of these tools or the centralization of resources” that could serve as an alternative LMS.

But Britton says the risks of relying on such technology are clear. "There is risk that data is no longer held within things that UBC trusts," he said. He thinks UBC is incredibly fortunate the attack took place during the summer session when fewer classes were running — implying the attack could have had a more acute effect if it had taken place during exam season or other busy educational periods. With the size of UBC and the value of its data making the institution “such a shiny prize” for hackers, the university has a vested interest in protecting community members’ data, Britton said.

The questions we have to ask ourselves, Britton said, are “who can read that data, what were the expectations on that data when it was created and what … UBC’s duty of care is with regards to us using these large systems and deploying them at scale to support 55,000 students.”

Finally, Britton said that the Canvas breach exemplified universities’ reliance on a “monolith” LMS in which over 9,000 institutions share a risk regarding data management.

During the attack, Nijdam worried about faculty members who would have trouble navigating the shift to alternative LMS tools and how this might impact enrolment numbers. Similar to Britton, she does not think the Canvas attack sparked debate over shifting to Canadian tools — it merely fuelled an ongoing conversation. 

She said UBC has pivoted in recent years to prefer that Canadian data be stored on Canadian servers, but this has not been the case for Canvas. For instance, Nijdam said that the Social Sciences and Humanities Research Council — a federal agency that funds post-secondary research — has been encouraging instructors to use their funding on Canadian services.

Should we worry?

The Ubyssey contacted experts on cybersecurity and privacy law to assess the validity of instructors’ concerns. They expanded on issues of data residency, data in-transit and data sovereignty — three concepts that are key to understanding the ongoing debate over data management.

Nguyen Phong, a computer science professor who works on cybersecurity, said many of the concerns are valid. “It didn't come from nowhere, because cybersecurity incidents happen on a daily basis,” he said.

Phong said the Canvas breach is perhaps the largest case that targeted an “academic setting.”

He explained that the attack exposed vulnerabilities related to how data is being managed and that the leaked information could have included anything from student IDs and transcripts to sensitive conversations between instructors and students. “Sometimes students say ‘I have family problems or I have mental issues’ [over Canvas]. Those are things that shouldn't be out there in the public.”

UBC says “the information in Canvas is stored and backed up in secure data centres run by Amazon Web Services (AWS) in Quebec. It is not stored outside Canada at any time.” During the interview with Phong, he ran a quick diagnosis into the frontend of Canvas and said it was directing him to an IP address in Pennsylvania. “So that is the front end of the website. When you type canvas.ubc.ca you're being routed to a Philadelphia server.”

The Ubyssey ran tests similar to what Phong ran and got IP addresses in the United States — both were AWS servers. Phong clarified that according to this, the data is not stored in the U.S., but that he is certain it passed through Philadelphia.

The Ubyssey also interviewed a law professor working at the intersection of law and technology (who asked not to be named — and didn't specify why and didn't respond to our followup correspondence about it). According to them, data residency refers to where the information is being stored, while data sovereignty is related to the specific legal bodies that have exclusive jurisdiction over data even after it has transited to and from where it is stored.

Phong told The Ubyssey that despite the data being stored in Quebec when it is being accessed, it can transit through places like Philadelphia, making it especially vulnerable to cyberattacks in the process. “If the credential to get into that frontend is stolen, they can still get through that, and then from there, get into the server in Quebec.” That risk would not be mitigated if data were to transit only through Canada, but the legal jurisdiction over what happens if the data is compromised would remain with Canadian courts.

The law professor explained that data can be resident in Canada but beholden to a U.S. institution that has operations in Canada. As a result, the U.S. has some legal authority over it. Complete data sovereignty would mean maximizing data residency for the entire chain of transmission to guarantee that Canadian courts and regulators have exclusive or near-exclusive jurisdiction over it.

If the data is in-transit abroad, as Phong's test seemed to show, concerns over who has legal jurisdiction to pursue criminal actors who access the data illegally are valid, according to the legal expert. They told The Ubyssey that because Canada lacks the infrastructure to support widespread domestic data residency, there's no all-encompassing, significant legal obligation to do so. Canada doesn't have any homegrown alternatives to the tech giants in the U.S., and stricter data privacy laws might also constrain innovation.

Britton said his concerns are not restricted to data being more vulnerable in transit and Canada having no legal authority over it. He's also worried about the U.S. CLOUD Act, which allows American authorities to compel American companies to disclose what information they have about non-Americans, even when it's stored outside the U.S. The legal expert added that concerns about the CLOUD Act can be compounded by the weaker data privacy culture compared to that of Canada or the European Union.

They said the language of the CLOUD Act is especially concerning for some people. “It talks about [how], if you're a tech service provider, then you may have to disclose the benefits within your possession, custody or control. And theoretically, something could be in your control even if it's offshore, and so it has what you call extraterritorial reach.”

They explained the legal tests that determine a company's possession of data are not concerned with residency. “They ask, 'Do you have the capacity to manipulate, dispose, access' — those kinds of things. A modern technology company would certainly be found under the law to control data, even if it was offshore, if they could quickly access it, and if they had exclusive authority to access it … That's the risk, because the legal question is about who has operational control.”

The legal scholar finally added that some companies might appear Canadian but may only have a Canadian subsidiary and actually be operated by a U.S. company, which would make them subject to the CLOUD Act without some people knowing.

The legal scholar called the letter sent by Clarke Gray “very modest” in terms of its demands. They added that what the professors are asking for is “exactly the role that the privacy commissioner ought to be taking” and explained that because Canada does not have “muscular privacy regulators, commissioners play a role of naming and shaming” to raise public awareness and spark legislation. 

They said the outcome of the letter could be an investigation by the OIPC, followed by a report that could lead to legislation. “That's been the historic role of these privacy commissioners. It's been doing that work of … investigating and amplifying.”

“It talks about [how], if you're a tech service provider, then you may have to disclose the benefits within your possession, custody or control, and theoretically, something could be in your control, even if it's offshore, and so it has what you call extraterritorial reach.”

— A privacy law expert from a leading Canadian university on the U.S. CLOUD Act

The road ahead

Clarke Gray’s letter is not the only effort to increase data sovereignty at Canadian universities. Multiple interviewees brought up the prospect of moving to local servers or increasing data encryption and some instructors said they have already moved to alternative tools.

The days during the attack were filled with stress and chaos for some as administrative work increased to provide learning tool alternatives to Canvas in a short period of time. Others saw it as an opportunity to assess UBC’s dependency on Canvas.

Nijdam said figuring out how to support her students when the Canvas attack happened required extensive screen time and caused migraines for her. For Annie Prud’homme-Généreux, a sessional instructor in the faculty of science, the administrative burden of transitioning between systems right before the start of the summer term was not so pressing, thanks to collaboration between faculty. “It has been a lot more work, like a ton more work, but it's not been that stressful for me in the sense that we're all in this together,” she said. “We've been working together, helping each other out through this.” 

Working through the Canvas attack, Prud’homme-Généreux said “it's actually been a very positive experience.” Nijdam also praised collaboration, saying her faculty set up Piazza threads so instructors could “learn alongside emerging information and also share tips with fellow faculty members.”

Britton sees the breach as an opportunity to explore the decentralization of learning tools. “Some discussions are percolating [around] ‘Is this the best place to do it’, ‘Are there ways of backing up data tools’ …. The sort of things we haven't thought about that we should have thought about,” he said.

One of the potential solutions would be an LMS completely owned and operated by UBC or a Canadian entity — which Britton called “the gold standard,” but said is unlikely for various reasons. According to him, UBC’s size might give it greater bargaining power in making something happen, but it would take time. He also recognized that student familiarity, ease of access and budget constraints must all be taken into account. “Yes, we could. The real question is, do we want to, and what's the cost of that,” he said.

Before transitioning to Canvas last year, the University of Alberta used to have a locally hosted and operated LMS through an open-source software called Moodle, which they had to move away from because the support needed to keep up the system exceeded resources, there were limited features to support modern learning and the system experienced frequent outages. (For reference, U of A has just under 40,000 students, compared to UBC’s over 70,000, and a consolidated budget of around $2.1 billion for 2026/27, compared to UBC’s $4.2 billion.)

Phong agrees that for “a full-scale university" like ours, it would make sense to have the IT department run a dedicated system. It would not reduce the risk of cyerbattacks, but would increase the control the university has over data management, he said. “I think having the system run in B.C. and the data in B.C. is critical, because at the end of the day, an attack like this is beyond the control of UBC — but if you have everything run locally and managed by UBC, then we have full control,” said Phong.

Another way to protect sensitive information is to bolster encryption. UBC's Chief Information Officer recommends Tier 3 or 3+ encryption as best practice for IT infrastructure — which are file-level or transparent database engine encryption and application-level database encryption, respectively. File-level encryption allows individual folders to be encrypted independently — these two are UBC’s highest levels of encryption to mitigate unauthorized access risks.

Phong said we need more data encryption, and explained that even if data resides in a foreign jurisdiction and is accessed illegally, encryption ensures it is not accessible to bad actors if the key is held by UBC.

Decentralization and moving away from a Canvas-centric approach are other potential solutions. Prud’homme-Généreux said she was not going to move back to Canvas for the summer semester even after the platform was back up. “To me, that changes nothing, because as you know, the summer terms are so fast that at this point, I've established all the alternative systems. I'm just gonna stick with them for now,” she said.

She said her switch to Microsoft Teams gave her better results in terms of communication with students than Canvas used to do. She said she used to get a few emails after classes, but after setting up Teams for direct communication, students are reaching out more frequently and more informally. “It's facilitated communication between me and the students, and I'm planning to keep that tool,” she said.

Nijdam turned to UBC Blogs — a learning platform managed and locally hosted by UBCIT that runs on WordPress, an open-source publishing platform — to reimagine the execution of her class outside of Canvas. She said she also used Gradescope for assignments and Piazza for discussion — the two are tools UBC instructors already used before the attack.

Britton said he was not directly impacted since he is not teaching over the summer, but stated that listening to his colleagues on the best alternative tools moving forward will be important for him. He added that building redundancy between platforms to ensure seamless transition in case of a technical difficulty would be beneficial.

When questioned on the potential of opening UBC data to more “points of attack” by increasing the platforms used through decentralization, he said there's a balance between points of attack and operational capacity to continue business as usual. “[It’s] about not [putting] all of your eggs in one basket, to use that old analog, but effectively to spread a little bit of that risk, and for instance a little bit more decentralization.”

A never-ending story

It's been over a month since digital chaos erupted while Nijdam met online with her colleagues to discuss AI. Canvas is backup and running, and a sense of normalcy has returned as students settle into the summer term.

Instructure reached an agreement with ShinyHunters on May 11. The company never announced that a ransom was paid, but it is most likely the case. Instructure claimed they received confirmation of data destruction from ShinyHunters.

“In my network security [class], the very first thing that I teach my students is never pay … because you can never trust that it is the last version of the data that they have,” said Phong, as he explained there is a non-zero chance that the stolen data is still being held by the group or has been sold illegally and can surface any time.

Britton said he still harbours mixed feelings about Canvas's safety. However, “I don't know what the alternative looks like. Do I want to have a large email list with my students? Probably not, because that has other risks with regards to disclosure of information that we shouldn't be using. There was a nice disconnect that Canvas operated in,” he said.

The legal expert The Ubyssey contacted said the attack “was primarily about creating inconvenience” to extract a ransom, and stealing the data itself wasn’t the main goal of ShinyHunters. They also said that tougher legislation — like requiring data residency and legal frameworks to maximize data sovereignty — could come with other problems. “If we flip the switch tomorrow and said, ‘we will only allow companies to operate if the data is fully resident in Canada and under [the] … sovereign … and exclusive authority of Canadian courts, we would be undoing a lot of the modern economy, because we haven't yet built up that domestic capacity.”

Phong said the long-term effects of the attack might not be revealed yet. “Maybe not tomorrow, but years from now,” the data stolen, including transcripts or communication between students and instructors, could resurface and be used to harm students who go on to become public figures. Transcripts with low grades, he said, could hurt alumni in the future. People would have forgotten about the attack and would be unaware of where the data came from — but the reputational damage would be done.

“That would not come in a few months. That would come in 20 years, 30 years from now.”

Juan Pablo is a News Editor for The Ubyssey's 108th Editorial. You can reach Juan Pablo at jp.sastoque@ubyssey.ca or news@ubyssey.ca!