A Flag, Not a Firewall
The Canvas breach and the comforting fiction of Canadian data residency.
ShinyHunters, the criminal extortion group behind some of the largest data thefts of the past few years (Ticketmaster, AT&T, Santander, and last year’s sweeping Salesforce campaign that hit Google, Cisco, Qantas and others), has now claimed responsibility for breaching Instructure, the parent company of Canvas. The group says it accessed data from roughly 8,800 institutions, allegedly including names, email addresses, student ID numbers, and private messages between students and teachers. Instructure has confirmed a breach and that some user information was exposed, though the full scope remains under investigation. Looking through the leaked list, I counted at least 53 Canadian institutions: 28 universities and post-secondary, 15 K–12 school divisions and ministries, and 10 other organizations including health authorities, professional bodies, and a police service.
The breach also puts pressure on something we don’t talk about carefully enough in Canadian education: data residency, and what we actually expect it to do for us.
When Canadian school divisions, universities, and ministries push for data residency, the reasoning is usually some version of this: if our students’ data lives on Canadian soil, it stays under Canadian law, out of reach of foreign governments, subpoenas, and actors. There is real substance behind this. PIPEDA federally, FOIP and LAFOIP in Saskatchewan, and various legislative equivalents in other provinces all matter. The CLOUD Act and the question of US government access to data held by US companies are real concerns. Residency is a legitimate ask.
But residency is a jurisdictional protection, not a security one. It governs which laws apply to your data and which courts can compel its disclosure. It does not, on its own, prevent the data from being stolen.
So here are some things worth thinking about:
We should keep pushing for residency where it matters, especially for sensitive data under Canadian law and for situations where foreign government access is a foreseeable risk.
We should stop treating residency as a security control. Security comes from the vendor’s actual practices: how they patch, how they segment, how they monitor, how they respond.
Nearly all universities and divisions already ask vendors about security posture as part of procurement. The work now is to be more thoughtful about what those answers actually tell us and to weight them more heavily. The threat landscape is shifting fast. AI-enabled attackers are accelerating vulnerability discovery and automating exploitation, which means breaches at this scale are likely to become more frequent, not less. The question is no longer whether a vendor checks the right boxes on security. It is whether their defences hold up against a class of attacker that is getting faster, cheaper, and more capable every quarter.
We should be honest with our communities. Telling parents and students that their data is “safe because it’s stored in Canada” sets up an expectation that the next breach will violate. The honest version is that residency reduces certain legal risks while doing little against criminal ones.
None of this is an argument against residency. It is an argument for understanding what we are actually buying when we buy it, and for making sure the people doing the buying understand the difference. Faculty, academic administrators, technical staff, and others who sit on procurement committees are often the ones weighing these tradeoffs, and the framing they bring into the room shapes what gets asked and what gets accepted. Residency is one question. Vendor security preparedness is another. Treating them as the same question leaves real risk on the table.
There is also a bigger question hiding in this breach, and it is one we don’t ask often enough: whose infrastructure are we building our public education systems on? Canada has a long history of building ed tech of its own, going back to the earliest days of online learning. We have domestic vendors. We have open-source options that can be hosted domestically. We are not without alternatives. The reflex to default to the largest American platform is a procurement habit, not a necessity. Every time a US-headquartered vendor gets breached and our students’ data ends up on a leak site, it is worth asking whether the savings or convenience of the dominant option are still worth what we are giving up: not just data, but the chance to build and sustain Canadian capacity in a sector that matters enormously to our future.

