Updates on Instructure (Canvas) Security Incident

14 . 08 . 2026

Further to the previous notice issued on 14 May 2026 regarding the cybersecurity incident reported by Instructure, operator of the Canvas Learning Management System (LMS), the Academy would like to provide an update on the latest findings following our detailed review of the vendor’s investigation data package.

Following Instructure’s delivery of institution-specific incident reports on 27 July 2026, the exact impact on our LMS users has been verified.

Assessment Findings & Confirmed Scope of Data
Based on the verified user reference reports received from Instructure, we can confirm the following details regarding the data involved in this incident:

  • The confirmed personal data elements involved are primarily user full names and email addresses
  • The incident was strictly restricted to the third-party Canvas LMS platform. No other systems were accessed or affected


Single Sign-On (SSO) Security Protection
We would like to reassure that your eHKAM account remains fully secure. The eHKAM LMS relies on centralized Single Sign-On (SSO) authentication. Under this architecture, your actual account passwords and credentials are hosted securely on SSO identity provider servers and are never stored within the Canvas LMS. Consequently, your eHKAM login credentials were not exposed and remain entirely safe.

Recommendations & Staying Vigilant Against Phishing
Although account passwords were not leaked, the exposure of names and email addresses increases the risk of targeted phishing attacks or social engineering scams. We advise all users to observe the following precautions:

  • Genuine Canvas system notifications are dispatched strictly from [email protected]
  • Do not click on unexpected links or download unverified email attachments
  • The 2-Step Verification is recommended to maximise security level of your eHKAM ID. Please visit to the Google Account Security page to setup your preference.


The Academy regards data privacy and cybersecurity with the utmost importance. We have notified the Office of the Privacy Commissioner for Personal Data (PCPD) and will continue to liaise closely with relevant authorities and the service provider to ensure all robust protection measures remain in place.

If you notice any suspicious activity, unexpected login prompts, or phishing emails, please report them immediately to [email protected].