← Instructure

2026 Instructure Canvas - cyberattack involving user identifiers and messages; ShinyHunters claims 275M users

2026 275.0M records affected Share on X

Data compromised

Names, email addresses, student ID numbers, messages among users, and alleged Salesforce/user data per ShinyHunters claim

Technical writeup

Instructure disclosed a May 2026 cybersecurity incident affecting Canvas-related systems after disruption to tools relying on API keys. ShinyHunters claimed roughly 3.65 terabytes from on the order of 275 million users—including private messages between students and teachers—while Instructure said exposed data appeared to include names, email addresses, student ID numbers, and user messages, with no evidence at that stage that passwords, dates of birth, government identifiers, or financial information were involved. Reporting through late May 2026 described impacts at roughly 8,800+ educational institutions worldwide, renewed vendor-risk and third-party LMS alerts on May 30, and downstream outages at K-12 districts, universities, and government education ministries. The company revoked credentials, deployed patches, engaged forensic experts, and—per Inside Higher Ed and wire follow-ons—negotiated with extortionists while institutions documented ongoing access issues on status pages.

Root cause

Unauthorized access by a criminal threat actor affecting Canvas-related systems, credentials/tokens, and potentially Salesforce data; exact initial vector under investigation

References