Canvas Cybersecurity Incident May 2026

The University of Edinburgh has been advised of an ongoing global cybersecurity incident affecting Instructure, the parent company of our learning platform Canvas used by our short course learners and staff.

Instructure’s investigation is ongoing and early indications are that users at the University of Edinburgh are among those affected.  

  • We currently have no confirmation of the data involved and Canvas continue to investigate this.
  • Payment data for University of Edinburgh is not affected as this is processed separately from the Canvas platform.

The University understands this news may be unsettling and is actively taking precautions to keep our applications secure.

As a precaution, the University recommends:

  • Being cautious of unexpected emails or messages, especially those asking for personal information or prompting urgent action
  • Not clicking unfamiliar links
  • Do not open unexpected attachments
  • Changing your password - To create a strong password, use a mix of at least 8 random characters, including letters, numbers, and symbols. Avoid using full words, names, and common sequences (e.g. 12345). You can use a random password generator to create a strong password.

All further updates on the incident will be posted on this webpage, please check back regularly for updates.