Hackers Breached Canvas, the SEP, and UNAM: What Really Happened (and What to Do Today)
In recent months, there have been not just one, but three distinct cyberattacks on educational platforms: one global, one in Mexican schools, and one at UNAM. Here’s a straightforward explanation, backed by credible sources, and a list of actions you can take today.
First, the good news: it’s not one single massive hack
If you saw headlines about "hacking universities," "school data leaks," or "UNAM breach" and thought it was all the same incident, relax: these are three separate cases, involving different attackers, at different times. That’s actually good news because it means there isn’t a single major vulnerability affecting the entire education system at once. Let’s go through each one, like I’m telling you over coffee.
Case 1: They hacked Canvas, the platform used by thousands of universities
Canvas is one of those platforms that hardly anyone notices until it fails: millions of students worldwide upload assignments, exams, grades, and notices there. It’s owned by a company called Instructure.
In late April 2026, a cybercriminal group known as ShinyHunters claimed to have stolen 3.65 terabytes of data from this platform: information of nearly 275 million people, across about 8,800 institutions in over 50 countries. To put it in perspective, it’s probably the biggest hack the education sector has experienced so far worldwide.
A week later, they attacked again, right during exam season, giving Instructure an ultimatum: pay or release everything, including private messages between students and teachers. Instructure reached an agreement with them a day before the deadline. Several specialized media (Xataka Mexico, Security Boulevard, The Hacker News) report that the company paid a ransom, though they never publicly confirmed it: they only said they received proof that the stolen data was destroyed.
And in Mexico? The cybersecurity firm SILIKN identified at least six Mexican universities on the leaked list: UAG, UDEM, Universidad Tecnológica Metropolitana, Universidad Anáhuac, ITAM, and Tecnológico de Tijuana (source). The Tec de Monterrey reported access issues during the attack, but that doesn’t necessarily mean their data was included in the leak.
Case 2: For months, they attacked the SEP’s school systems, and the response was denial
This is a completely different case, which didn’t even happen simultaneously: between April and October 2025, a group called Sociedad Privada 157 (SP157) targeted several systems of the Secretaría de Educación Pública one by one: the Mexico City scholarship system, the Servoescolar control system (used by about 1,600 schools), and systems in Quintana Roo, Zacatecas, Baja California, Tamaulipas, Chiapas, and Campeche.
What makes this case more serious is the type of data exposed, according to the timeline documented by Ciber Conciencia Digital and also reported by Infobae: CURP, addresses, photos, grades, passwords, and in several cases, medical history and blood type of primary school children. Over one million records were leaked just from Servoescolar, with hundreds of thousands more in various states over those months.
Each time, the SEP responded the same: that it was false. For example, when leaks were reported in Campeche and Puebla. As far as can be confirmed, there was no independent, public technical audit backing up those denials.
Case 3: UNAM did admit to a breach, but there’s an unresolved contradiction
On January 7, 2026, during the holidays, someone accessed five of UNAM’s over 150,000 computer systems by exploiting a security flaw the university had left exposed. The responsible group, identified as ByteToBreach, later put a complete university database up for sale on a cybercrime forum.
Here’s the interesting part: UNAM did acknowledge the breach, but denied that data of its over 370,000 students or 43,000 staff had been leaked. However, Milenio and independent technical analyses describe something different: full access to servers and exposure of enrollment numbers, emails, and encrypted passwords of more than 380,000 people. This contradiction, between what UNAM states and what specialized press reports, remains unresolved publicly.
And the organization that should be overseeing all this?
Here’s a fact few mention: during these three cases, Mexico did not have an independent data protection agency. The INAI was officially dissolved on March 19, 2025, and its data protection functions were transferred to a new Secretaría de la Función Pública. This agency did react: in January 2026, it confirmed 20 investigations into data breaches in public and private entities, the first time it acted on such a scale. But so far, it hasn’t publicly stated whether Canvas, the SEP, or UNAM are among those 20 cases. For affected families or students, this means it’s harder to know if their specific case is being addressed.
What you can do today, even if you’re not tech-savvy
You don’t need to be a cybersecurity expert to protect yourself. Here’s what’s enough:
Change your school password by going directly to your university’s or platform’s official site, never through a link received via email or WhatsApp.
Enable two-factor authentication if the platform offers it: it’s the extra lock that makes a stolen password useless.
Be wary of urgent messages asking to "update your data" or "verify your account" via a link. Serious schools will never ask for that through WhatsApp.
Never share a verification code, even if someone claims to be tech support. That code is literally the key to your account.
If you have children in public school, stay alert for messages or calls using scholarship or medical data as bait to ask for money or information: this type of fraud becomes possible after such leaks.
If you’re at UNAM, change your institutional password even if the official statement says there was no data leak: it’s a precaution that costs nothing, and specialized press suggests otherwise.
The underlying message
These three cases, though different, tell the same story: when a single platform holds the data of hundreds of thousands or millions of people, a single security mistake can expose an entire community. Neither official denial nor paying a ransom guarantees that the problem is truly resolved. The only thing within your control is not relying solely on the platform to do its part: change passwords, enable two-factor authentication, and be cautious of links. It’s a small effort compared to the risk involved.
Get the next note by email
The story, told while it happens. No spam: only when we publish, and you can leave with one click.
Sources
- 2026 Canvas data breach — Wikipedia
- Instructure quiso negar el mayor hackeo... — Xataka México
- Instructure Pays Ransom to Resolve Canvas Data Breach — Security Boulevard
- Instructure Reaches Ransom Agreement with ShinyHunters — The Hacker News
- ShinyHunters se adjudica ataque a Canvas; universidades mexicanas y el INE — Fortuna y Poder
- El sistema educativo mexicano, en el centro de una tormenta de ciberataques — Infobae
- Cronología de ataques atribuidos a Sociedad Privada 157 — Ciber Conciencia Digital
- SEP desmiente supuesto hackeo a su base de datos — Milenio
- UNAM admite 'hackeo' a cinco sistemas y niega filtración de datos — La Jornada
- Hackeo en la UNAM tuvo acceso total a servidores y datos sensibles — Milenio