2026 Columbia University — Instructure/Canvas incident; 868,969 individuals notified (May)
Data compromised
Personal information per Columbia/Instructure notices; passwords/SSNs/financials not evidenced in initial statements
Technical writeup
Columbia University reported fallout from the global May 2026 Instructure Canvas cybersecurity incident (see instructure-canvas2026), notifying 868,969 students, applicants, and employees that personal information was involved. Security Affairs and Columbia communications stated Instructure indicated no evidence that passwords, dates of birth, Social Security numbers, or financial information were in the exposed dataset at notification time, while Columbia restored Canvas/CourseWorks access for valid UNI credentials. BreachHistory records this as a jurisdictional education impact row linked to unauthorized network access at the LMS vendor rather than Columbia-operated ransomware.
Root cause
Third-party Instructure Canvas incident; unauthorized access at vendor affecting Columbia tenant data