Unauthorized actors first accessed Canvas systems on April 25, 2026. Instructure detected the intrusion four days later, revoked access and brought in third party forensics support. On May 7, ShinyHunters defaced the Canvas login page with a ransom note, demanding payment by May 12 or threatening to leak stolen data. Instructure says the exploit was tied to its Free For Teacher accounts.
| Item | Detail |
|---|---|
| Operator affected | Instructure (Canvas LMS), Utah, United States |
| Threat actor | ShinyHunters |
| Timeline | April 25 to May 12, 2026 |
| Claimed scale | 3.65 terabytes from approximately 275 million users, across roughly 8,809 institutions |
| Data types involved | Names, email addresses, student ID numbers, user messages |
| Data not implicated | Passwords, birth dates, government IDs, financial information |
| US response | House Homeland Security Committee inquiry; class action filed in Southern District of California |
Table 1. Snapshot of the 2026 Instructure (Canvas) data breach. Source: Reuters, the Associated Press, Inside Higher Ed and the US House Committee on Homeland Security, May 2026.
Canvas is used by 41 percent of US higher education institutions and some K-12 districts. Reported impacts in the United States included the University of California system, Arizona State University, the University of Pennsylvania, Duke University, Sacramento State and Wake County Public Schools, with disruption falling during final exam periods at several institutions.
What this means for US institutions
A vendor breach at a single education technology provider disrupted systems at universities and school districts across the country at the same time, during finals week for many of them. This is a useful reminder that an institution’s own security controls cannot fully offset risk concentrated in a widely shared third party platform. Instructure stated it found no evidence that passwords, birth dates, government identifiers or financial information were involved, but names, email addresses, student ID numbers and private messages between students and staff were confirmed as accessed.
Risks, limitations and caveats
ShinyHunters’ claim of 275 million affected users and 8,809 institutions has not been independently verified, and the source material treats this as a claim by the attacker rather than a confirmed figure from Instructure. Reports that Instructure paid roughly 10 million US dollars to the attacker are described as unconfirmed. Instructure says the compromised data was destroyed under its agreement with the attacker, but the terms of that agreement have not been made public.
Recommended actions
US institutions using Canvas or similar third party education platforms should review what categories of student and staff data are stored with the vendor, confirm what notification obligations apply under state breach laws, and monitor for phishing attempts using the names, emails and ID numbers reportedly exposed. Security teams can map vendor risk reviews to NIST Cybersecurity Framework supply chain guidance, and should track the outcome of the House Homeland Security Committee’s inquiry, which asked Instructure to address the scope of data accessed and its coordination with CISA, the federal Cybersecurity and Infrastructure Security Agency.
Conclusion
The Canvas breach shows how a single compromised education technology vendor can disrupt operations and expose data across thousands of US institutions simultaneously. With a congressional inquiry and litigation still active as of this report, institutions should expect further detail on the scope of the breach and Instructure’s response in the coming weeks.

Leave a Reply