Breach report
Instructure confirms Canvas data theft and says it reached an agreement with the attacker

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The Canvas maker confirmed two intrusions exposing usernames, email addresses, enrolments and messages. ShinyHunters claimed the attack; Instructure says the data was returned under an agreement.
What happened
Instructure, the Utah company behind the Canvas learning platform, says it detected unauthorised activity in Canvas on 29 April 2026. On 7 May a second attack used a different vulnerability; Help Net Security reported that Canvas login pages at about 330 institutions were defaced with an extortion message that day. Instructure's incident page traces the root cause to a vulnerability in Free-for-Teacher accounts, the free version of Canvas, exploited by what it calls a known cybercriminal organisation.
On 11 May Instructure said it had reached an agreement with the attacker. It says the data was returned, it received "shred logs" as digital confirmation of destruction, and it was told no customers would be extorted. The ransom amount, if any, has not been disclosed.
Confirmed vs. claimed
Confirmed by Instructure: usernames, email addresses, course names, enrolment information and messages were exposed. Instructure says core learning data, submissions and credentials were not affected. It has not published counts of affected users or institutions.
Claimed by ShinyHunters (as reported by Help Net Security): 3.65 TB of data, about 275 million records, and 8,809 institutions. Instructure's page does not name the group. There is no independent way to verify that every copy of the data was destroyed.
Who is affected
Students, teachers and staff at institutions using Canvas. Instructure has been delivering affected-data files to institutions that designate a security contact, a process it paused on 14 July and resumed on 21 July. None of the sources we reviewed gives a breakdown by country.
What to do
- Ask your school or university whether its Canvas data was in scope.
- Expect phishing that quotes your course names or messages; verify through your institution's official channels.
- If you receive an extortion email mentioning Canvas, do not reply or pay; read our guide to ShinyHunters extortion emails.
- Institutions: designate a security contact with Instructure so you can receive your data file.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026