Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Superintendent: Canvas security breach exposed user names and messages; district, state and vendor disabled access

Rockingham County Board of Education · May 12, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Rockingham County schools disclosed a Canvas security incident in which a group identified as 'Shiny Hunters' accessed teacher portal accounts and exposed usernames, emails, course names and messages; the district and NCDPI suspended access while working with vendor Instructure and communicating with families.

Superintendent provided the board with a timeline and steps taken after a security incident affecting the district's Canvas learning management system.

"On April 29, a group called Shiny Hunters accessed Canvas through their free teacher portal, and got the following information, usernames, email addresses, course names, student messages back and forth, etcetera, and enrollment information," the superintendent told the board. The district said no Social Security numbers or comparable highly sensitive data were included in the disclosure.

District staff said NCDPI notified the district May 5 and that NCDPI and Instructure (Canvas's vendor) disabled access on May 7 and were investigating. The superintendent said the district also turned off Canvas access, has been working with both Instructure and NCDPI, and will only restore service after staff are confident systems are secure. "We're going to do our due diligence here, at the district, make sure we think everything's safe," the superintendent said, adding an expectation Canvas would be available by 7:30 a.m. the following school day if checks were complete.

Board members asked whether the outage affected day-to-day operations for teachers and students. The superintendent said it caused some disruption—students had difficulty submitting assignments at the end of the year and the district was monitoring potential impacts on end-of-course and end-of-grade assessments—but did not anticipate long-term problems.

The district said it will share NCDPI and Instructure communications with families and staff and encouraged vigilance against phishing, reminding staff not to follow unusual email requests and to report suspicious messages to the district tech team. The superintendent referred board members to a status page maintained by NCDPI and Instructure for updates.

The report was part of a broader superintendent update that also noted academic grants under consideration and routine end-of-year scheduling constraints tied to state testing windows. The meeting recessed for a closed-session discussion after committee reports and the superintendent's remarks.