Hong Kong’s privacy watchdog has found that more than 153,000 students and staff from four educational institutions in the city were affected in a global cyberattack on online learning platform Canvas in May.

The Canvas logo. Photo: Canvas by Instructure.

The Office of the Privacy Commissioner for Personal Data (PCPD) published its findings on Thursday based on investigations into the data breaches, which were originally reported by seven institutions including universities, a vocational school, and a government-owned e-learning service provider.

The number of affected personnel was more than double the 72,000 first reported by PCPD in May after the global attack on Canvas, a web-based learning management platform operated by Instructure.

Close to 9,000 institutions worldwide were hit, according to the hacker group ShinyHunter, which was behind the breaches.

The PCPD’s investigations, however, found that only four institutions in the city were affected, namely the City University of Hong Kong (CityU), the Hong Kong Academy for Performing Arts (HKAPA), Hong Kong Institute of Construction (HKIC), and the Hong Kong University of Science and Technology (HKUST).

The other three institutions that reported breaches – Hong Kong Art School, Hong Kong Polytechnic University, and Hong Kong Education City Limited – did not appear to have been affected by the incident, the watchdog said.

Internal systems ‘not affected’

The university hardest hit was CityU, with close to 147,000 students and staff’s names, email addresses, usernames, student IDs, and course enrolment information leaked, according to the PCPD.

Around 4,500 students and staff at HKAPA and some 2,300 at HKIC also had their personal information stolen in the data breaches, PCPD said, adding that the number of affected personal at HKUST was still pending verification from Instructure.

Students at City University of Hong Kong. File photo: GovHK.

“The Affected Institutions confirmed that their internal systems (i.e. systems other than Canvas) have not been affected by the Incident,” PCPD said in a statement.

Prior to the breaches, the institution also implemented security measures to ensure the protection of personal data, such as pre-assessments of Canvas and setting up contractual terms with Instructure, the PCPD said.

The data breaches stemmed from “vulnerabilities relating to a third-party platform” and there was no evidence to suggest that the four institutions had failed to take the necessary steps to safeguard personal data, the PCPD concluded.

Security measures

The PCPD said it had nonetheless recommended that the affected institutions reassess data breach risks, strengthen the monitoring of third-party platforms, review and minimise the amount of personal data stored on such platforms, and step up data security measures.

The watchdog also suggested that organisations holding large volumes of personal data should adopt certain measures when engaging with third-party data processors, such as conducting due diligence background checks and using on-premises servers.

The Office of the Privacy Commissioner for Personal Data. File photo: Peter Lee/HKFP.

Organisations should also develop incident reporting mechanisms and data retention policies, and enable security features like multi-factor authentication provided by third-party platforms, the PCPD added.

Hong Kong has seen a growing number of data security incidents in recent years, with public institutions among those falling victim to hackers.

The PCPD recorded 246 data breach notifications in 2025 – a 21 per cent year-on-year increase, it said in February.