Last Update: 08/01/2026 at 2:00 PM EST

Education SaaS Breaches Expose User Data

Coverage from BleepingComputer, Morningstar, and others

Articles

117

Active Days

67

The Topic

Education SaaS Breaches Expose User Data topic image

Education technology providers and connected institutions are responding to breaches involving learning platforms, career services systems, and Salesforce environments. Reported exposures center on names, email addresses, student or staff identifiers, messages, contact records, and locally stored passwords, while several organizations said core academic, financial, or internal systems were not affected. The incidents underscore how compromise of third-party education platforms can create broad phishing, service disruption, and privacy risks across many schools and universities.

First Article: 05/02/26

Latest Article: 07/07/26

Summary

  • Instructure’s Canvas breach exposed or potentially exposed usernames, institutional email addresses, student IDs, course and enrollment data, and user messages.
  • Canvas access disruptions affected students, instructors, assignments, grading, and exams, while Instructure investigated an exploited Free-for-Teacher vulnerability.
  • Oxford University’s CareerConnect incident was isolated to third-party provider Group GTI and exposed names, email addresses, and encrypted locally set passwords.
  • Infinite Campus reported that a Salesforce environment breach exposed records linked to more than 137,000 school staff members, including contact details and support tickets.
  • Affected institutions generally reported no evidence that passwords, financial data, government identifiers, or core internal systems were compromised, though investigations remained incomplete.
  • Schools and vendors repeatedly warned users about phishing and social-engineering attempts using exposed education-sector contact information.

History

07/23/2026

The main update is a tighter, more specific framing of the education-breach pattern: the current version adds that locally stored passwords were exposed in the Oxford incident and that service disruption and phishing risks were more concrete across the incidents. It also sharpens the timeline and attribution around the Canvas and CareerConnect compromises.

07/21/2026

The story has broadened from a Canvas-centered breach pattern to a clearer multi-vendor set of education SaaS compromises, adding a Salesforce-based Infinite Campus incident and new details on disruption and remediation. The current version also strengthens the operational impact by showing login-page defacement, ransom demands, and password invalidation after the Oxford-related breach.

Featured

Timeline: 67 Days

May 2May 16May 30Jun 6Jun 20Jul 4

Additional Articles

⭐⭐⭐⭐⭐

TechRepublic / Ken Underhill06-16-2026
Infinite Campus said a threat actor breached its Salesforce environment and exposed personal data of more than 137,000 school staff members, enabling phishing risk.
JD Supra05-08-2026
Instructure reported a Canvas cybersecurity incident on April 30, 2026, after ShinyHunters claimed theft of millions of student and educator records and private messages, raising phishing and education-privacy compliance risks.
JD Supra05-11-2026
Instructure reported a May 2026 ShinyHunters cyberattack on Canvas that exploited Free-For-Teacher account weaknesses, exposing U.S. educational PII.
ComputerWeekly.com06-25-2026
Cyber Monitoring Centre reviewed a ShinyHunters breach of Infrastructure Holding Canvas LMS in the UK, citing limited financial impact but residual phishing and social engineering risk.
The Record / Jonathan Greig05-08-2026
Instructure reported a Canvas outage after a ShinyHunters cyberattack claim, following earlier theft of student identifiers and coordinated FBI and CISA notification.
NPR / Rachel Treisman05-08-2026
Instructure reported a Canvas data breach and related outage on Thursday after detecting unauthorized activity on April 29, disrupting final exams across many U.S. schools.
NPR05-09-2026
Instructure took Canvas offline on April 29 after unauthorized access linked to ShinyHunters disrupted education workflows at thousands of schools worldwide.
NPR05-09-2026
Canvas Comes Back Online After Data Breach Disrupts Schools
Instructure reported a Canvas breach after April 29 activity, temporarily disabling access for many U.S. schools and exposing student and staff identities and messages.
NPR05-09-2026
Instructure reported unauthorized Canvas activity detected April 29, after which universities restricted access and security teams advised password and MFA changes.
Claim Depot05-05-2026
Instructure disclosed a criminal threat-actor cybersecurity incident affecting Canvas starting late April 2026, exposing user identifying information and prompting service restoration through May 4.
Independent / Callie Fausey05-08-2026
Instructure shut down Canvas after ShinyHunters accessed student identity data and private messages at California schools, including Santa Barbara City College and UC Santa Barbara.
Newsday / Lorena Mongelli05-08-2026
Instructure said a Canvas education platform breach on April 29 exposed student identifiers and messages, affecting Hofstra University and multiple Long Island K-12 districts.
New York Post05-08-2026
Instructure disclosed a Canvas cyberattack detected on April 29 that disrupted finals and exposed student personally identifiable information, prompting recovery and regulatory scrutiny in the U.S. and beyond.
McLane Middleton / Jessica Oliveri05-08-2026
McLane Middleton notified independent schools in 2026 about an Instructure Canvas incident after a Free-For-Teacher tier vulnerability enabled alleged ShinyHunters data access.
EdTech: Focus on Higher Education / Amy McIntosh05-12-2026
Instructure reported a ShinyHunters breach of Canvas Free for Teacher beginning with unauthorized access on April 29 and leading to ransom payment on May 11.
SHS Courier05-15-2026
Instructure disclosed on May 7 a Canvas data breach following unauthorized access after logins at schools and colleges, exposing account and course information.
Marketbrief / Scott Elliott05-15-2026
Instructure disclosed a ShinyHunters hacking breach on Canvas that risked data from more than 200 million users, after free-tier accounts and support ticket access were exploited.
Dig In05-18-2026
In North America, ShinyHunters disrupted and breached Instructure Canvas during college finals, exposing student personal data and prompting undisclosed payments for return.
CyberArts06-03-2026
KVKK disclosed a Udemy breach after a vishing attack on an employee account exposed and exfiltrated personal contact data for about 12,000 people in 2026.
OU Daily05-07-2026
ShinyHunters extortion messages disrupted Instructure Canvas access for University of Oklahoma on Thursday, prompting OU and Norman Public Schools to notify families after third-party access to student data.
Higher Ed Dive05-08-2026
Instructure reported a May 7 Canvas outage after repeated unauthorized access, citing Free-For-Teacher account weaknesses and exposing student data in an April 29 incident.
EdTech Magazine / Adam Stone06-25-2026
In May, Instructure Canvas suffered a data breach affecting about 275 million users across roughly 9,000 education institutions, prompting universities to revise third-party vendor monitoring and breach response.
Rescana05-06-2026
Instructure disclosed a May 2026 ShinyHunters breach affecting Canvas users at up to 9,000 schools, exposing names, emails, student IDs, and private messages.
Safestate05-04-2026
Instructure confirmed a May 1, 2026 Canvas LMS breach affecting education users worldwide after a ShinyHunters extortion claim involving Salesforce-linked systems.
Insurance Business Mag / Jonalyn Cueto05-12-2026
Instructure said it reached an agreement with the unauthorized actor behind the Canvas data breach, potentially exposing up to 275 million students worldwide after incidents starting April 29.
TechSpot / Skye Jacobs05-10-2026
Instructure disclosed a Canvas cybersecurity incident in May 2020s that exposed student identifiers and messages and led to a US-wide maintenance outage during finals.
NBC San Diego05-07-2026
ShinyHunters disrupted Canvas access in San Diego and reportedly exposed student identifiers and private messages after suspicious Canvas API activity and ransom-related claims.
Dispatch05-08-2026
Instructure restored CarmenCanvas access for Ohio State students on May 8 after a April 29 and May 7 breach exposed student names, emails, and ID numbers.
The Next Web05-07-2026
ShinyHunters exploited a Instructure Canvas vulnerability in late April 2026, affecting 44 Dutch institutions and large higher-education networks with potential exposure of student communications.
Laist05-09-2026
Instructure said Canvas shut down after a breach detected on April 29, disrupting U.S. education access and exposing identity and message data.
Laist05-09-2026
Instructure said Canvas went offline after an April 29 data breach, exposing student identifiers and messages and prompting exam disruptions across U.S. schools.
ABC4 / Amelia Hobson05-13-2026
Instructure faced three class actions after a Canvas data breach disclosed April 29 and detected again May 7, with complaints citing inadequate security and notification failures impacting educators and minors.
Spectrum Bay News 905-08-2026
Instructure confirmed a Canvas cyberattack discovered May 1 in Florida, exposing student identifiers and messages and prompting temporary access disablement across multiple schools and universities.
Daily Hive05-08-2026
Instructure disclosed early-May Canvas breach impact on universities worldwide, with student names, emails, student IDs, and messages reported as affected data.
ABC7 Chicago05-07-2026
Instructure's Canvas system outage in the United States involved a ShinyHunters data breach threat, leading universities to postpone exams or disable logins and warn about phishing risk.
WTOP05-09-2026
Instructure said unauthorized activity in Canvas detected April 29 and additional activity on May 7 affected Prince William County Public Schools in Virginia, with exposure of some user personal information.
Berkshire Eagle05-10-2026
Pittsfield Public Schools reported potentially accessed Canvas student data after Instructure confirmed a criminal cybersecurity incident on May 1.
Inquirer / Robert Moran05-08-2026
After an Instructure-linked Canvas breach, Princeton, Rutgers, and other US universities reported access loss, phishing risks, and student identifier exposure.
Legal Insurrection / Leslie Eastman05-09-2026
ShinyHunters linked to an Instructure Canvas data breach exposing student and staff personal data; Canvas saw several hours of downtime on Thursday across the U.S. and abroad.
JD Supra06-08-2026
In Pennsylvania, Canvas cyberattack guidance emphasizes BPINA determination, individual notice, and federal Title IV notification timelines for schools and colleges.
Secure-ISS05-07-2026
Instructure disclosed a Canvas Data 2 and Canvas Beta incident affecting Australian and New Zealand institutions, with access to identities and user messages.
Reed Smith05-14-2026
ShinyHunters-linked hackers breached Instructure Canvas on April 30, 2026, claiming exfiltration affecting about 275 million users and exposing education-related identifiers and messages.
Vancord / Jason Pufahl05-15-2026
Instructure reported a 2026 Canvas security incident exposing usernames, emails, course and enrollment data, prompting FERPA and phishing response guidance for K-12 and higher education users worldwide.

⭐⭐⭐

KJZZ05-08-2026
Utah school districts and universities issued phishing and data-safety warnings after Instructure Canvas disclosed a cybersecurity incident.
KJZZ / Jonathan May05-11-2026
Instructure CEO Steve Daly reported a Canvas cyberattack and data breach in Salt Lake City, USA, with further incident updates planned within 48 hours.
The Record / Jonathan Greig05-04-2026
Infrastructure disclosed a Saturday confirmation of a ShinyHunters-driven breach affecting education user data, including names, emails, student IDs, and messages.
WRAL05-08-2026
Instructure disclosed a Canvas breach after ShinyHunters claimed stolen school-account data and threatened to leak it, prompting notifications across North Carolina districts.
Yahoo05-07-2026
In Oregon, Portland Public Schools and other districts notified families after Instructure Canvas faced a vendor breach with potential exposure of student data.
Yahoo05-22-2026
The Government of the Northwest Territories reported a Canvas platform breach in May that may have exposed names, email addresses, and training data for about 1,700 people in Canada.
Top Class Actions05-26-2026
Instructure disclosed a Canvas learning platform data breach in late April, confirmed cybercriminal involvement on May 1, and reported personal data exposure.
The Santa Barbara Independent / Callie Fausey05-15-2026
Instructure shut down and restored Canvas starting May 7 after a ShinyHunters breach exposed student and course data, while California colleges temporarily disabled access.
GovTech05-14-2026
Jane Doe filed a class action in Waco, Texas, against Instructure after ShinyHunters allegedly breached Canvas and forced final exam disruptions in May.
Boston.com05-08-2026
ShinyHunters claimed major student-data access as Instructure investigated a Canvas outage and breach affecting universities and K-12 schools.
The Advocate05-06-2026
Instructure disclosed an early-May Canvas breach affecting a California community college district, exposing student emails, ID numbers, and Canvas inbox messages while investigators assessed phishing risks.
The Badger Herald05-07-2026
University of Wisconsin advised students to avoid Canvas actions May 7 after Instructure investigated a May 1 cybersecurity incident affecting the Canvas platform.
Milton Area School District05-07-2026
Instructure notified a school district in an ongoing incident involving Canvas, reporting access to student names, emails, Canvas IDs, and messages, with no confirmed password, birthdate, or government ID exposure.
UCnet / Wendy Michelle Welsh05-06-2026
Instructure notified the University of California of a data breach in Instructure systems, affecting thousands of institutions nationwide and prompting coordinated monitoring and phishing warnings.
Los Alamos Daily Post / Rebecca Rutherford05-07-2026
Instructure disclosed a Canvas breach beginning around April 30, exposing student identifiers and messages, after ShinyHunters claimed responsibility on May 3.
Kentucky Kernel05-08-2026
Instructure confirmed a May 1 ransomware attack on Canvas, with ShinyHunters claiming exposure of 280 million student and faculty records across 8,000 schools.
TheU05-07-2026
University of Utah received May 2, 2026 notice of a nationwide Canvas incident involving Instructure, while university systems showed no breach evidence.
Beacon Journal05-07-2026
On May 7, Ohio State University reported a national Canvas outage tied to an Instructure vendor breach claimed by ShinyHunters with ransom threats.
abc7ny05-08-2026
Infrastructure reported a May 2 cybersecurity incident affecting Canvas for Columbia University, disrupting finals and potentially exposing student names, emails, phone numbers, and student IDs.
29 News / Gabby Womack05-07-2026
In May 2025, Charlottesville City Schools and the University of Virginia warned families after an Instructure Canvas breach exposed parent account contact details and increased targeted phishing risk.
The Daily Princetonian05-07-2026
Princeton University Canvas went down Thursday afternoon after ShinyHunters claimed an Instructure breach, with possible exposure of student identifiers and instructional disruption.
Fox 13 Memphis05-07-2026
The University of Memphis confirmed a Canvas-related cyberattack in which Instructure said student names, emails, and student IDs may have been exposed.
Trinitonian05-08-2026
Trinity Information Technology Services told universities on May 7 that Instructure shut down Canvas servers after a cyberattack tied to ShinyHunters threats and potential data leaks.
Cassia County School District05-09-2026
Cassia County School District reported Instructure Canvas security incidents during the prior week, after Instructure notified the FBI and CISA and remediated compromised credentials.
ReadTheReporter.com05-08-2026
On May 8, Hamilton Southeastern Schools in Indiana notified families of a Canvas data breach after Instructure reported unauthorized access to limited student and account information.
Nye County School District05-09-2026
Nye County School District said Instructure notified the district in 2025 of a Canvas cybersecurity incident affecting schools, prompting phishing-risk safeguards despite no internal-system compromise.
Armstrong School District05-08-2026
Armstrong School District reported Instructure Canvas notification of a cybersecurity breach, stating no student, staff, or family data was accessed.
Wisconsin Radio Network05-19-2026
Wisconsin Consumer Protection director Mike Domke said Canvas faced a data breach earlier this month and urged parents to freeze student credit.
AUTOMATON WEST06-04-2026
Visual Arts reported June 4 potential exposure of over 10,000 records after anemoi gold master credentials were stolen and an April 19 unauthorized upload occurred to an overseas site.
K-12 Dive05-05-2026
Instructure reported a contained Canvas cybersecurity attack on K-12 systems after exposure of student messages, names, emails, and student IDs.
Cardinal News05-19-2026
Roanoke City Public Schools paused Canvas after an Instructure breach in April and May, then restored access on May 13 after security reviews.
Hot for Security05-02-2026
Instructure confirmed a Canvas data breach on May 2 after ShinyHunters claimed data theft, exposing student identifiers and messages for potentially up to 275 million people worldwide.
WCCB Charlotte / Morgan Fogarty05-07-2026
Charlotte-Mecklenburg Schools reported a Canvas vendor data breach and possible personal information leakage, with claims of containment and no access to district internal systems.
Baylor Lariat05-07-2026
Baylor University delayed Friday finals after a ShinyHunters-linked Instructure breach caused a nationwide Canvas outage and extortion threat over student data.
Park Record05-07-2026
Park City School District reported that Instructure notified the district on May 5 of an April 25 Canvas breach exposing student and staff data in Utah.
CBS6 Albany05-11-2026
Pittsfield Public Schools notified families on Sunday about a Canvas incident potentially exposing student names, emails, ID numbers, and messages.
IndyStar / Katie Wiseman05-08-2026
Instructure said April 29 and May 7 Canvas breaches by ShinyHunters caused major access disruption for students while the company investigated and added safeguards.
Security Affairs / Pierluigi Paganini05-05-2026
Instructure investigated a Canvas cyber incident in the US after exposure of user identifiers and messages, while rotating keys and increasing monitoring.
KFOR / Spencer Humphrey05-08-2026
Shiny Hunters disrupted Canvas access for Oklahoma schools ahead of finals after claiming a Canvas parent-company breach.
KOIN / Aimee Plante05-06-2026
Portland Public Schools reported a Canvas learning management system breach in 2026 and is investigating possible student data exposure with Instructure coordination.
University of Nevada05-06-2026
Instructure notified NSHE in Nevada of a Canvas data breach in ongoing forensics, with potential exposure of student IDs, institutional emails, and private messages.
Indianapolis Star05-08-2026
Instructure placed Canvas into maintenance mode after a cybersecurity incident caused widespread login disruption and reported student data theft in the United States.
The Daily Progress05-06-2026
Charlottesville City Schools reported a Canvas data-breach impact on parent accounts in Charlottesville, Virginia, with multifactor authentication limiting exposure for student and staff accounts.
GW Hatchet05-09-2026
The George Washington University Law restricted Canvas access after an Instructure security incident caused a nationwide Canvas outage and potential data exposure concerns in 2026.
ABC4 / Amelia Hobson05-07-2026
ShinyHunters alleged an Instructure breach affecting Canvas, and Utah school districts including Granite and Davis reported incident updates on possible student data exposure.
Schubert Jonckheer & Kolbe / Nelida Almeida05-08-2026
Instructure detected Canvas unauthorized access in late April 2026, after ShinyHunters ransomware claims data exfiltration and login-page disruption affecting schools.
KUTV05-08-2026
Utah school districts issued phishing warnings after Instructure reported a Canvas cybersecurity incident potentially affecting student directory data, with investigations ongoing and password compromise reportedly not evidenced.
KUTV05-11-2026
In Salt Lake City, Instructure CEO Steve Daly disclosed that a Canvas cyberattack exposed usernames, email addresses, and enrollment information after unauthorized access.
KTVB05-14-2026
Boise State University notified students on May 13 about a Canvas cybersecurity breach, citing Instructure and ShinyHunters agreement and ongoing review.
WLOS05-13-2026
Henderson County Public Schools reported a Canvas-related data breach in May 2026, and Instructure confirmed no compromise of Social Security numbers, dates of birth, or financial information.
FOX 9 Minneapolis-St. Paul05-04-2026
In Minnesota, Wayzata Public Schools alerted families after Instructure reported a May 1, 2026 Canvas vendor-side breach with possible exposure of student and staff identifiers.
Newark Advocate05-08-2026
Instructure restored Canvas access for Ohio State University on May 8 after a ransomware-linked breach exposed student names, emails, and student ID numbers.
MTSU Sidelines05-07-2026
Instructure cyberattack triggered Canvas LMS unscheduled maintenance at MTSU during finals season, while ShinyHunters threatened breach data release.
WJXT News4JAX05-08-2026
Duval County Schools disabled Canvas after an Instructure ransomware breach attributed to Shiny Hunters, affecting 275 million people and raising identity theft concerns.
Sacramento Bee05-11-2026
Instructure disabled Canvas after April 29 unauthorized activity and ShinyHunters claims, reporting student ID and message exposure while notifying FBI and CISA.
WFMZ-TV 69 News05-12-2026
A Canvas data breach in the USA affected 275 million people and nearly 9,000 schools, after attackers claimed data erasure that experts said could not be verified.
Des Moines Register05-08-2026
Instructure reported a May 7 Canvas outage after a ShinyHunters-linked cyberattack, with alleged exposure of student names, emails, and student ID numbers.
6abc Philadelphia05-07-2026
Instructure's Canvas platform breach reported data exposure at universities including the University of Pennsylvania, with experts warning of phishing risks from exposed student identifiers.
KOMU 805-07-2026
University of Missouri reported a Canvas outage on Thursday, while a SHINYHUNTERS message warned of potential data leakage by May 12.
WIBW / Callie Holthaus05-08-2026
ShinyHunters claimed responsibility for a Canvas online learning platform breach in Topeka, Kansas, prompting restoration efforts and risks to student data.
WILX05-09-2026
Instructure disclosed a Canvas cyberattack affecting Michigan schools, reporting April 29 breach onset and student data exposure including emails and IDs.
ABC7 New York05-08-2026
Instructure Canvas and CourseWorks were disrupted by a cybersecurity incident in advance of final exams, raising potential student data exposure and phishing risks.
ABC7 Los Angeles05-07-2026
Instructure reported a cybersecurity incident affecting Canvas and related platforms in the United States during finals week, with Shiny Hunters reportedly claiming responsibility.
WEAU05-07-2026
Universities of Wisconsin issued breach-related guidance in Wisconsin after Instructure reported a May 1 Canvas learning management system breach by a criminal threat actor.
CBS News Texas05-09-2026
ShinyHunters claimed a Canvas cyberattack affecting thousands of school districts and universities, including North Texas sites, leading to breach alerts and account-protection guidance.
Northern News Now / Marisa Ornat05-07-2026
Instructure reported a May 1 cybersecurity incident affecting Canvas, disrupting University of Wisconsin campuses and involving exposure of student IDs, messages, and email addresses.
WHSV / Michael Russo05-08-2026
James Madison University received Canvas breach notification from Instructure in the spring 2026 semester during a short-lived outage tied to a ransomware claim.
JD Supra / Melissa Grand05-14-2026
Instructure disclosed a cybersecurity incident affecting Canvas LMS customers in 2026, prompting education institutions to address FERPA obligations, phishing risks, and incident response.
Techmedics06-01-2026
Instructure disclosed a 2026 Canvas breach after ShinyHunters claimed access to school data, prompting guidance on identity controls and faster vendor breach notification for education institutions.
Emery Reddy / Emery Reddy07-07-2026
Grandview School District in Washington State notified affected students, staff, and families in June 2026 after a 2024 unauthorized-file access period was confirmed.
Managed Solution / Kristin Davis06-02-2026
Instructure reported a May 7, 2026 Canvas breach that disrupted colleges nationwide during finals week and involved unauthorized access tied to Free-For-Teacher accounts.