Anchor: Claire Galt Photographer: Andy Cunningham
•5/8/2026

SOUTHWEST FLORIDA, (WINK)—A cybercrime group known as “ShinyHunters” claims it hacked the learning platform Canvas — potentially exposing millions of private student records and messages connected to thousands of schools worldwide.
A Collier County Schools spokesperson sent WINK News a statement reading, "We have received confirmation from Instructure, the company that owns and operates Canvas, that the District was impacted. District staff have reviewed the information provided, and according to Instructure, no sensitive information was obtained. Student access to Canvas remains available."
Retired FBI agent Rich Kolko says students who use Canvas could now be at risk of scams and phishing attempts if their personal information was accessed.
For FGCU student Sienna Miller, the news was alarming.
“It has our personal information, when we register for classes, our card numbers, and how we pay,” Miller said.
Canvas is used by millions of students to check grades, turn in assignments, message professors, and access class information. Miller says she first learned about the reported breach the same way many students did.
“TikTok and Instagram,” Miller said.
Kolko says the concern is not just what hackers may have now, but how they could use the information in the future.
“The information’s never coming back,” Kolko said.
Kolko says scammers have historically targeted older Americans, but breaches like this could give hackers access to years of student data and personal conversations.
“They’re basically building up their, their storage, their cache of, potential victims down the road,” Kolko said.
He says hackers can now use artificial intelligence to sort through private messages and personal details to create scams that sound believable.
“They’ll get a note. Might be a month from now, a year from now, or two years from now. And it’s going to say, 'Hey, remember when you told me about your dog named Rex when you were at such and such a college?' That looks good. Somebody is going to click on it. Boom! You’re caught,” Kolko said.
“That does freak me out,” Miller said.
Kolko says schools should not pay ransoms because there is no guarantee that stolen information would ever actually be deleted.
He recommends that students change their passwords, use two-factor authentication, and be cautious about emails, texts, or messages that seem unusually personal.
Charlotte County Schools, Florida SouthWestern State College, and Florida Gulf Coast University also use Canvas. The School District of Lee County does not.
Canvas says it traced the unauthorized activity back to its “Free-for-Teacher” accounts and has temporarily shut those accounts down.
Infrastructure, the company behind Canvas, has updates about the hack here.