The University of Nebraska system says a nationwide hack of Canvas, a learning management system used at all four campuses, was hacked, right as the semester is coming to an end.
They said on Thursday afternoon, a threat actor interrupted access to Canvas users around the world and is preventing some users from accessing and authenticating to the service.
The service remained unavailable across the University of Nebraska on Thursday.
According to Instructure, unauthorized activity was detected on April 29th.
They said they immediately revoked the unauthorized party’s access, started an investigation, and engaged outside forensic experts.
Then on Thursday, additional unauthorized activity tied to the same incident was identified.
The threat actor made changes to pages that appeared when some students and teachers logged in through Canvas.
Out of caution, the company said they took Canvas offline temporarily to contain the activity, investigate, and apply additional safeguards.
Instructure says the unauthorized actor carried out this activity by exploiting an issue related to their Free-For-Teacher accounts, which have since been temporarily shut down.
On Friday morning, the University of Nebraska said while Instructure, the parent company of Canvas, has taken steps to restore access, the university will evaluate risks before restoring access across the campuses.











