2026 Instructure Canvas - cyberattack involving user identifiers and messages; ShinyHunters claims 275M users
Data compromised
Names, email addresses, student ID numbers, messages among users, and alleged Salesforce/user data per ShinyHunters claim
Technical writeup
Instructure disclosed a May 2026 cybersecurity incident affecting Canvas-related systems after disruption to tools relying on API keys. ShinyHunters claimed roughly 3.65 terabytes from on the order of 275 million users—including private messages between students and teachers—while Instructure said exposed data appeared to include names, email addresses, student ID numbers, and user messages, with no evidence at that stage that passwords, dates of birth, government identifiers, or financial information were involved. Reporting through late May 2026 described impacts at roughly 8,800+ educational institutions worldwide, renewed vendor-risk and third-party LMS alerts on May 30, and downstream outages at K-12 districts, universities, and government education ministries. The company revoked credentials, deployed patches, engaged forensic experts, and—per Inside Higher Ed and wire follow-ons—negotiated with extortionists while institutions documented ongoing access issues on status pages. Update September 27, 2026 catalog pass: BBC and The Hacker News coverage confirm Instructure reached an agreement with the unauthorized actor (ShinyHunters) under which data was returned with digital confirmation of destruction and customers would not be separately extorted; Inside Higher Ed previously reported a ransom payment. No new September 2026 Canvas compromise identified in this refresh — May 2026 incident remains the primary row.
Root cause
Unauthorized access by a criminal threat actor affecting Canvas-related systems, credentials/tokens, and potentially Salesforce data; exact initial vector under investigation
References
- https://status.instructure.com/incidents/9wm4knj2r64z
- https://status.instructure.com/
- https://www.gblock.app/articles/instructure-canvas-may-2026-breach-student-data
- https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/
- https://www.techrepublic.com/article/news-canvas-instructure-breach-275m-users/
- https://status.instructure.com/incidents/m88d7ymwpzpy
- https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/
- https://www.bleepingcomputer.com/news/security/canvas-login-portals-hacked-in-mass-shinyhunters-extortion-campaign/
- https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers
- https://en.wikipedia.org/wiki/2026_Canvas_data_breach
- https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week
- https://www.hipaajournal.com/may-2026-data-breach-round-up/
- https://www.pkware.com/blog/2026-data-breaches
- https://www.bbc.com/news/articles/cdepzg83x87o
- https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html