TechNewsReel
Live

Canvas Breach Hit 153,000 Hong Kong Students and Staff, Watchdog Finds

A privacy investigation reveals the scale of the leak was double the initial estimates provided by platform operator Instructure.

TechNewsReel Newsroom · August 20, 2026

More than 153,000 students and staff at four Hong Kong tertiary institutions had their personal data exposed in a breach of the Canvas learning management platform. An investigation by the Office of the Privacy Commissioner for Personal Data (PCPD) confirmed the leak originated from vulnerabilities within the third-party platform rather than the institutions' own internal systems.

According to the PCPD, at least 153,866 individuals in Hong Kong were affected. The vast majority of these users were from the City University of Hong Kong (CityU), which accounted for 96% of the total with 146,969 compromised accounts. Other affected institutions included the Hong Kong Academy for Performing Arts, with 4,584 people impacted, and the Hong Kong Institute of Construction, with 2,333 people affected. The leaked data comprised a wide array of identifiers, including names, email addresses, usernames, student IDs, login IDs, course enrolment information, and user messages.

The Vendor Gap

Canvas, operated by the company Instructure, is a centralized web-based system used globally by educational institutions to manage coursework and communication. This specific incident was part of a larger global breach that Instructure previously estimated in May affected 9,000 institutions worldwide. At that time, the company estimated that 72,571 people in Hong Kong had been impacted. However, the PCPD's final findings show the actual number of affected individuals in the region was more than double that initial figure. Instructure reported that it reached an agreement with the attacker on May 11 to ensure the return of all stolen data.

Institutional Liability

Despite the scale of the leak, the privacy watchdog cleared the affected universities and colleges of wrongdoing. Privacy Commissioner Ada Chung Lai-ling stated there was no evidence to suggest the four educational institutions failed to take all practicable steps to safeguard the personal data in their possession while using the platform. Consequently, the PCPD found no contravention of the Personal Data (Privacy) Ordinance by the institutions themselves.

Systemic Risks

This discrepancy between the vendor's initial report and the regulator's findings highlights a significant risk in the reliance on centralized third-party platforms for sensitive academic data. When a single vendor manages data for thousands of institutions, a single vulnerability can create a systemic failure. The incident underscores the necessity for educational bodies to implement rigorous monitoring and data minimization strategies to reduce the volume of sensitive information stored on external servers.

What's Next

While the institutions have been cleared of legal contravention, the event serves as a warning for other schools using similar learning management systems. Observers will be watching whether the PCPD or other regulatory bodies demand more transparent reporting standards from third-party vendors following the significant underreporting of the breach's scale in Hong Kong.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.