Hong Kong Privacy Watchdog Confirms Over 153,000 Individuals Affected in Global Canvas Cyberattack

Hong Kong’s privacy watchdog has confirmed that a significant cyberattack on the widely used online learning platform Canvas in May affected the personal data of over 153,000 students and staff across four educational institutions in the city. This figure represents a substantial increase from initial estimates and underscores the pervasive reach of the sophisticated cyber threat. The Office of the Privacy Commissioner for Personal Data (PCPD) released its comprehensive findings on Thursday, detailing the extent of the breaches and the institutions impacted.

The investigation, which began following initial reports from seven institutions, ultimately identified four as having suffered data exposure due to the incident. These include the City University of Hong Kong (CityU), the Hong Kong Academy for Performing Arts (HKAPA), the Hong Kong Institute of Construction (HKIC), and the Hong Kong University of Science and Technology (HKUST). The PCPD’s review indicated that three other institutions that had initially reported breaches – the Hong Kong Art School, Hong Kong Polytechnic University, and Hong Kong Education City Limited – did not appear to have been directly affected by this specific incident.

Over 153,000 students, staff affected in Canvas data breach, Hong Kong privacy watchdog says

This revised tally more than doubles the initial figure of 72,000 individuals that the PCPD reported in May, shortly after the global attack on Canvas, a learning management system operated by Instructure, a US-based company. The scale of the breach was international, with the hacker group ShinyHunter, which claimed responsibility for the attacks, reporting that nearly 9,000 institutions worldwide were compromised.

Unpacking the Scope of the Breach

The PCPD’s detailed investigation revealed that the City University of Hong Kong bore the brunt of the data compromise. Close to 147,000 students and staff from CityU had their personal information, including names, email addresses, usernames, student identification numbers, and course enrollment details, exposed. This alone constitutes a significant portion of the total affected individuals.

The Hong Kong Academy for Performing Arts (HKAPA) also experienced a substantial impact, with approximately 4,500 students and staff affected by the data breaches. Similarly, the Hong Kong Institute of Construction (HKIC) reported that around 2,300 of its students and staff had their personal information compromised. The number of individuals affected at the Hong Kong University of Science and Technology (HKUST) is still undergoing verification with Instructure, indicating that the final figures for this institution may still be subject to adjustment.

Over 153,000 students, staff affected in Canvas data breach, Hong Kong privacy watchdog says

Crucially, the PCPD’s investigation confirmed that the internal systems of the affected institutions, separate from the Canvas platform itself, remained secure and were not compromised. This distinction is vital, as it suggests the breach was localized to the data hosted and managed by the third-party learning platform.

Chronology of the Cyberattack and Investigation

The cyberattack on the Canvas platform, and consequently on the institutions utilizing it, is believed to have occurred in May 2026. The hacker group ShinyHunter publicly claimed responsibility for compromising a vast number of educational institutions globally. Following these reports, educational bodies in Hong Kong began to assess the potential impact on their own systems and data.

In the immediate aftermath of the initial reports in May 2026, the PCPD launched an investigation and provided an early estimate of affected individuals. As the investigations progressed, data was collated from the affected institutions and cross-referenced with information from the platform provider, Instructure. This ongoing process led to the revised and significantly higher number of over 153,000 affected individuals being confirmed by the PCPD in their August 2026 findings. The PCPD’s formal announcement on Thursday marked the culmination of this extensive inquiry into the data breaches.

Over 153,000 students, staff affected in Canvas data breach, Hong Kong privacy watchdog says

Findings and Conclusions of the PCPD Investigation

The PCPD’s investigation concluded that the data breaches stemmed from vulnerabilities associated with a third-party platform, specifically Canvas. The watchdog found no evidence to suggest that the four identified institutions had failed to implement reasonable and necessary steps to safeguard personal data prior to the incident. This implies that the primary cause of the breach lay within the security architecture or practices of the Canvas platform itself, rather than any dereliction of duty by the local educational bodies.

The PCPD noted that prior to the breaches, the affected institutions had already put in place security measures. These included conducting pre-assessments of the Canvas platform and establishing contractual agreements with Instructure, which typically outline data protection responsibilities. This indicates a proactive approach by the institutions to manage risks associated with third-party service providers.

Recommendations for Enhanced Data Security

Despite finding no evidence of negligence on the part of the affected institutions, the PCPD has issued a series of recommendations aimed at strengthening data security practices across the board. These recommendations are designed to mitigate future risks and improve the resilience of institutions against cyber threats, particularly when utilizing third-party platforms.

Over 153,000 students, staff affected in Canvas data breach, Hong Kong privacy watchdog says

The PCPD advised the affected institutions to:

  • Reassess Data Breach Risks: Conduct thorough reviews of their existing risk assessment frameworks to identify potential vulnerabilities and enhance their preparedness for future incidents.
  • Strengthen Third-Party Platform Monitoring: Implement more robust mechanisms for monitoring the security practices and compliance of third-party service providers, including Canvas.
  • Review and Minimize Stored Data: Evaluate the necessity of storing personal data on third-party platforms and consider minimizing the volume of sensitive information retained to reduce the potential impact of breaches.
  • Step Up Data Security Measures: Continuously review and enhance their own internal data security protocols and technical safeguards.

Beyond the directly affected institutions, the PCPD extended its recommendations to all organizations that handle substantial volumes of personal data. These broader recommendations include:

  • Conducting Due Diligence: Performing rigorous background checks and security assessments on any third-party data processors before engaging their services.
  • Utilizing On-Premises Servers: Where feasible and appropriate, consider the use of on-premises servers for storing sensitive data, offering greater direct control over security.
  • Developing Incident Reporting Mechanisms: Establishing clear and efficient protocols for reporting and responding to data security incidents.
  • Implementing Data Retention Policies: Defining and enforcing clear policies for the retention and deletion of personal data to minimize the amount of data at risk.
  • Enabling Security Features: Actively utilizing and enforcing security features offered by third-party platforms, such as multi-factor authentication, to add an extra layer of protection.

Broader Implications and the Growing Threat Landscape

The widespread impact of the Canvas cyberattack highlights a growing trend of sophisticated cyber threats targeting educational institutions globally. These institutions often hold vast amounts of sensitive personal data, making them attractive targets for malicious actors. The interconnected nature of modern digital infrastructure means that a vulnerability in one widely used platform can have cascading effects across numerous organizations.

Over 153,000 students, staff affected in Canvas data breach, Hong Kong privacy watchdog says

Hong Kong has experienced a notable increase in data security incidents in recent years. The PCPD recorded 246 data breach notifications in 2025, representing a 21 percent year-on-year increase. A significant portion of these incidents involved hacking, underscoring the evolving tactics of cybercriminals. The nature of the Canvas breach, attributed to vulnerabilities in a third-party platform, serves as a stark reminder for all organizations to exercise vigilance and implement comprehensive data protection strategies, particularly concerning their reliance on external service providers.

The findings from the PCPD investigation provide valuable insights into the challenges of data security in the digital age. They emphasize the shared responsibility between institutions and their technology partners in protecting personal information and underscore the critical need for continuous adaptation and enhancement of security measures in response to an ever-evolving threat landscape. The commitment to safeguarding personal data remains paramount, requiring ongoing diligence, robust protocols, and a proactive approach to cybersecurity.

Related Posts

Hongkong Post Faces Backlash Over Decision to End Permanent Civil Servant Contracts for New Hires

A pro-Beijing coalition of trade unions has voiced strong opposition to Hongkong Post’s recent decision to discontinue offering permanent civil servant contracts to new employees, a move anticipated to impact…

Tragic Dog Attack Claims Life of Woman at Hong Kong Animal Shelter

A 33-year-old woman has died following a brutal dog attack at a licensed animal shelter in Ta Kwu Ling on Thursday, a distressing incident that underscores a recent spate of…

You Missed

SenseTime Unveils SenseNova U1.5 Lite, Pushing Boundaries of Multimodal AI with Open-Source 8-Billion-Parameter Model

SenseTime Unveils SenseNova U1.5 Lite, Pushing Boundaries of Multimodal AI with Open-Source 8-Billion-Parameter Model

China’s Coal-Fired Power Generation Dips Below 50% for the First Time in a Landmark Shift for Energy Landscape

China’s Coal-Fired Power Generation Dips Below 50% for the First Time in a Landmark Shift for Energy Landscape

DaDong Duck Ready for New York Opening

DaDong Duck Ready for New York Opening

AmCham Taiwan Technology Committee Proposes Comprehensive Reforms to Strengthen National Digital Resilience and AI Governance

  • By Sagoh
  • August 21, 2026
  • 3 views
AmCham Taiwan Technology Committee Proposes Comprehensive Reforms to Strengthen National Digital Resilience and AI Governance

Hongkong Post Faces Backlash Over Decision to End Permanent Civil Servant Contracts for New Hires

  • By Nana
  • August 21, 2026
  • 3 views
Hongkong Post Faces Backlash Over Decision to End Permanent Civil Servant Contracts for New Hires

Donald Trump announces tariffs of up to 100% on imported drones

  • By Asro
  • August 21, 2026
  • 3 views
Donald Trump announces tariffs of up to 100% on imported drones