A Canvas data breach exposed personal information belonging to more than 150,000 students and staff at four Hong Kong educational institutions, but the Privacy Commissioner found no breach of the city’s Personal Data (Privacy) Ordinance by those institutions.
The institutions confirmed as affected were City University of Hong Kong, the Hong Kong Academy for Performing Arts, the Hong Kong Institute of Construction and Hong Kong University of Science and Technology. Seven institutions had initially reported possible Canvas-related breaches, with Hong Kong Art School, Hong Kong Polytechnic University and Hong Kong Education City among those that were not confirmed as affected by the investigation.
CityU reported that 146,969 people were affected, while HKAPA reported about 4,584 and HKIC around 2,333. The figure for HKUST was still pending verification. The exposed information included names, email addresses, usernames and student IDs.
Instructure, the operator of Canvas, detected unauthorised activity on April 29, 2026, involving a “Free-For-Teacher” account and a hacking group identified in the reports as ShinyHunters. The RTHK report said the account was used to exploit a cross-site scripting vulnerability.
Star Headline separately reported that hackers later used another Canvas security vulnerability to re-enter the platform, alter multiple institutions’ login pages and post ransom messages. The supplied reports do not establish whether that vulnerability was the same as the one described by RTHK or a separate flaw.
Instructure blocked the unauthorised access after detecting it and commissioned cybersecurity firm CrowdStrike to conduct an independent investigation, according to Star Headline.
The Privacy Commissioner said the four institutions had carried out pre-assessments before deploying Canvas, adopted contractual safeguards and established monitoring mechanisms. It found no evidence that they had failed to take all practicable steps to protect personal data and concluded that they had not breached the privacy ordinance.
The commissioner urged organisations to conduct due diligence on data processors, regulate them through contracts and enable security measures such as multi-factor authentication. The investigation results were published on August 20, 2026; the final number affected at HKUST and some technical details of the incident remain unresolved.