Full Report
A data breach involving University of California, Berkeley was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: UC Berkeley Learning Management System Data Breach
## Executive Summary
In May 2026, the University of California, Berkeley (UC Berkeley) experienced a significant data breach affecting approximately 600,000 records. The incident originated from a supply-chain compromise of Instructure’s Canvas platform, orchestrated by the threat actor "ShinyHunters." The breach resulted in the exposure of sensitive student and staff information, leading to the temporary suspension of the Canvas platform nationwide.
## Incident Details
- **Discovery Date:** May 7, 2026
- **Incident Date:** May 2026 (Ongoing at time of report)
- **Affected Organization:** University of California, Berkeley (specifically the "bCourses" platform)
- **Sector:** Education / Higher Ed
- **Geography:** Berkeley, California, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-May 7, 2026
- **Vector:** Supply-chain compromise
- **Details:** Attackers targeted Instructure’s Canvas platform, a third-party learning management system used by UC Berkeley under the local name "bCourses."
### Lateral Movement
- **Details:** The threat actor moved from the third-party Canvas infrastructure to access specific institutional data silos, allegedly affecting over 7,000 educational institutions globally.
### Data Exfiltration/Impact
- **Details:** ShinyHunters claimed to have exfiltrated 600,000 records from UC Berkeley. Stolen data includes names, email addresses, student IDs, and private messages. The group issued a ransom demand to prevent the public leaking of this data.
### Detection & Response
- **Discovery:** The incident was reported/detected on May 7, 2026, following claims by the ShinyHunters group.
- **Response:** The Canvas platform was taken offline nationwide to contain the breach and prevent further exfiltration. UC Berkeley launched an investigation into the scope of the "bCourses" impact.
## Attack Methodology
- **Initial Access:** Exploitation of a third-party vendor (Instructure/Canvas).
- **Persistence:** Not explicitly disclosed; likely maintained through compromised cloud or platform credentials.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Likely targeted through the broader Canvas platform breach.
- **Discovery:** ShinyHunters identified UC Berkeley as a high-value target within the compromised vendor data.
- **Lateral Movement:** Movement within the multi-tenant architecture of the Canvas platform.
- **Collection:** Automated gathering of student/staff records and private communications.
- **Exfiltration:** Transfer of 600,000 records to threat actor-controlled infrastructure.
- **Impact:** Financial extortion (ransomware) and operational disruption (system downtime).
## Impact Assessment
- **Financial:** Potential ransom costs; costs associated with investigation and remediation.
- **Data Breach:** Exposure of 600,000 records including PII (names, IDs) and private communications.
- **Operational:** "bCourses" / Canvas platform taken offline, disrupting academic activities.
- **Reputational:** Medium severity; risk of loss of trust from students and staff regarding private communications.
## Indicators of Compromise
- **Network indicators:** Activity related to ShinyHunters' known infrastructure (specific IPs defanged: `hXXps://berkeley[.]edu` affected via `Canvas` infrastructure).
- **File indicators:** Claims of stolen record databases (600,000 entries).
- **Behavioral indicators:** Unauthorized access to bCourses private messaging modules and student ID databases.
## Response Actions
- **Containment:** Canvas platform disabled nationwide.
- **Eradication:** Investigation into the third-party vulnerability and ShinyHunters' access points.
- **Recovery:** Restoration of learning management services and notification of affected individuals.
## Lessons Learned
- **Vendor Risk:** Third-party platforms (SaaS) represent a significant attack vector that can bypass perimeter defenses.
- **Data Centralization:** The aggregation of private messages and PII in a single platform creates a high-impact target for extortion.
- **Response Speed:** Rapid platform shutdown was necessary due to the scale of the nationwide breach (7,000+ institutions).
## Recommendations
- **Multi-Factor Authentication:** Enforce phishing-resistant MFA (Hardware keys or TOTP) for all CalNet accounts.
- **Vendor Assessment:** Implement continuous attack surface management to monitor third-party vendor risks.
- **Data Minimization:** Review the necessity of storing long-term private messages within learning management platforms.
- **User Education:** Alert students and staff to watch for targeted phishing attempts using their leaked Student IDs and names.