Empty school classroom with rows of desks and chairs lit by natural light
Photo via Unsplash

Today in Surveillance:

  • Canvas ransom deadline is Monday. ShinyHunters gave 9,000 schools until May 12. The platform is partially back online, but some universities (including Cambridge) still have suspended access. The FBI says it's "aware." Al Jazeera, WaPo, CNN, and NBC are all covering it now.
  • ShinyHunters leaked 50GB of Cushman & Wakefield data. Ransom talks failed. The real estate giant's Salesforce records (500,000+ entries with PII) are now public. Two days before the Canvas deadline, that's a message.
  • NBC: AI is supercharging government surveillance. Senator Wyden asked leading AI companies whether they'd help the government surveil Americans. Only Anthropic and Google replied. OpenAI and xAI stayed silent.
  • State CISO confidence collapsed to 22%. The 2026 NASCIO-Deloitte survey found that less than a quarter of state cybersecurity chiefs feel confident they can protect public data. Budget cuts hit 16% of states. AI-enabled attacks are accelerating.
  • Congress returns Monday: 33 days to fix FISA 702. The 45-day extension expires June 12. The Government Surveillance Reform Act is sitting in committee. Reform advocates have a narrow window before the summer punt.

48 Hours: The Canvas Ransom Deadline Is Monday

ShinyHunters' final deadline for Instructure arrives Monday, May 12. The group told roughly 9,000 educational institutions directly (via Canvas's own messaging system) that "everything is leaked" if payment isn't made by end of day. At stake: 3.65 terabytes of data covering 275 million students, teachers, and staff. Names, emails, student IDs, and private messages [1].

As of Saturday, Canvas is back online for most users. Instructure's status page says no current incidents. But "most" isn't all. The University of Alberta confirmed it's running with "reduced functionality," and the University of Cambridge suspended access entirely. Several institutions haven't restored full service. The FBI acknowledged it's "aware of a service disruption" affecting educational institutions, though it didn't name Canvas specifically [2].

The story has gone fully mainstream. Al Jazeera, CNN, the Washington Post, NBC News, Time, and NPR all published coverage this week. The 2026 Canvas security incident now has its own Wikipedia page. Class action attorneys at ClassAction.org, Fisher Phillips, and others are actively investigating. The Daily Pennsylvanian reports 300,000+ Penn users affected. Harvard's Crimson, Cornell's Daily Sun, and student papers across the country are running coverage [3].

If your school uses Canvas: assume your name, email, and student ID are compromised. Watch for phishing emails that look like Canvas password resets. That's the attack vector security firms flagged this week. Monday will tell us whether ShinyHunters leaks, extends, or goes quiet.

Background: 275M Students, 3.65TB Stolen · May 12 Deadline and Finals Week · What Happens Monday

ShinyHunters Leaked 50GB of Cushman & Wakefield Data. Talks Failed.

Cushman & Wakefield, the $10 billion commercial real estate giant, confirmed a data breach after ShinyHunters posted 50 gigabytes of the company's Salesforce data online. The leak came after ransom negotiations collapsed. ShinyHunters had set a May 6 deadline and claimed C&W never made contact [4].

The dataset includes over 500,000 Salesforce records containing personally identifiable information and internal corporate data. The initial attack vector: vishing (voice phishing). An employee was socially engineered, giving attackers access to internal systems. A second ransomware group, Qilin, also listed Cushman & Wakefield on its leak site on May 4, though it's unclear if both groups accessed the same data [5].

The timing matters. ShinyHunters is demonstrating, two days before the Canvas deadline, that it follows through. The group has been on a tear in 2026: hitting ADT, Carnival Corporation, Canada Life, Medtronic, Panera, TransUnion, and dozens of others through its Okta SSO vishing campaign. Cushman & Wakefield is proof that when talks fail, data goes public.

Background: C&W Breach Details · ShinyHunters Campaign Tracker

Only Two AI Companies Answered When Congress Asked About Surveillance

NBC News reported this week that AI's growing ability to sift through bulk data and track Americans' locations has given new urgency to the FISA 702 debate on Capitol Hill. The concern: if Section 702 isn't reformed before AI capabilities mature further, warrantless collection of Americans' communications will be fed through increasingly powerful analysis tools, turning bulk collection into precision surveillance [6].

Senator Ron Wyden sent letters to America's leading AI companies asking a direct question: would you allow the government to use your technology to surveil Americans, including through bulk commercial data or intelligence data that might sweep up Americans' information? According to Wyden's office, only Anthropic and Google replied. OpenAI and xAI didn't respond [7].

Privacy advocates are framing this as the convergence they've warned about for years. The government already purchases massive quantities of location and behavioral data from commercial brokers, data that isn't subject to the constitutional protections required for directly collected surveillance. Layer AI analysis on top and you get what the ACLU of Massachusetts called "a digital police state," not through any single program, but through the accumulation of tools that individually seem unremarkable.

Background: AI Mass Surveillance Explainer · How LLMs Enable Mass Spying · Ad-Tech Surveillance Pipeline

State Cybersecurity Chiefs Are Losing Confidence, Fast

The 2026 NASCIO-Deloitte Cybersecurity Study landed this week with a grim headline: only 22% of state CISOs describe themselves as "extremely" or "very" confident that their state's data is protected from cyberthreats. In 2022, that number was 48%. In four years, confidence was cut in half [8].

It gets worse at the local level. The percentage of CISOs who said they're "not very confident" in local government and public higher education cybersecurity jumped from 35% to 63%. That's not a gap. That's a chasm. And it's the same local government and higher-ed infrastructure that ShinyHunters just breached through Canvas [9].

What's driving it: AI-enabled attacks are getting faster and more sophisticated. Foreign adversaries and cybercriminals are using AI tools to probe for weaknesses at scale. Budget cuts are hitting 16% of states, the first reported decreases in years. Only 22% saw budget increases of 6% or more, down from 40% in 2024. The people responsible for defending state systems are telling us, on the record, that they're falling behind.

Quick Hits

  • FISA 702: 33 days to the June 12 deadline. Congress returns Monday from recess. The 45-day extension is ticking. The Wyden-Lee Government Surveillance Reform Act (S. 4082) would require warrants for Section 702 queries, block government purchases of Americans' data from brokers, and mandate FISA Court transparency. It has bipartisan sponsors (Wyden, Lee, Warren, Lummis) and a 3% chance of passing, per GovTrack. The window is narrow. Full explainer · Reform Act breakdown.
  • Connecticut SB-4 heads to the governor. The state's Delete Act passed the House 141-6 on May 4. It creates a one-stop data broker deletion portal: request once, all registered brokers must delete your data within 45 days. Civil penalty: $200/day per violation. Effective October 1 if signed. Full coverage.
  • Meta NM trial enters week 2. Phase 2 continues in Santa Fe. New Mexico AG seeks $3.7 billion in mental health funding and court-mandated algorithm changes. Meta threatened to pull Instagram and Facebook from New Mexico if forced to comply. Judge Biedscheid still weighing how far a court can go in regulating platform design. Day one coverage.
  • Federal facial recognition expanding without legal framework. A Congressional Research Service report found CBP is expanding facial recognition to all non-citizen travelers at air, land, and sea ports. ICE has been granted access to new FR tools for deportation operations. Congress has no comprehensive law governing any of it. State FR legislation roundup.

What to Watch

  • Monday, May 12: Canvas ransom deadline. ShinyHunters either leaks 3.65TB of student data, extends the deadline, or goes quiet. The Cushman & Wakefield dump shows they're willing to follow through. School districts should be preparing parent notifications now.
  • Monday, May 12: Congress returns from recess. FISA 702 reform advocates have 33 days before the June 12 extension expires. The Government Surveillance Reform Act needs committee action before it can reach the floor.
  • Through May 22: Meta NM Phase 2 testimony. The most important tech platform trial in years. If Biedscheid orders algorithm changes, it sets precedent for every state AG watching.
  • May 18-20: IEEE Symposium on Security and Privacy (San Francisco). Watch for papers on ad-tech tracking, facial recognition accuracy, and AI-assisted surveillance.
  • June 12: FISA Section 702 extension expires. Either Congress reforms, extends again, or the program lapses. Reform advocates say this is the last realistic window before the midterm election cycle takes over.

Sources

  1. Al Jazeera: Hacked educational platform partially restored for millions of students
  2. CBS News: Canvas back online after cyberattack shuttered learning platform for schools across US
  3. Washington Post: Canvas hack exposes schools' vulnerability to cyberattacks
  4. CyberNews: ShinyHunters posts 50GB Cushman & Wakefield dataset after ransom talks fail
  5. The Register: Cushman & Wakefield confirms vishing cyberattack
  6. NBC News: AI is making it very easy for the government to spy on you. Some lawmakers are worried.
  7. The Conversation: US government ramps up mass surveillance with help of AI tech, data brokers
  8. Deloitte: State CISOs Report Lower Confidence Across the Public Sector Cyber Ecosystem
  9. StateTech: NASCIO 2026 Midyear: State CISOs Report Falling Confidence as AI Threats Accelerate