Instructure Breach Exposes Canvas Data
Coverage from BleepingComputer, CNET, and others
Articles
8
Active Days
13
The Topic

Instructure’s Canvas learning management platform was compromised in incidents reported on April 29 and May 7, exposing or potentially exposing usernames, email addresses, student identifiers, course and enrollment information, and messages across schools and universities. The incidents disrupted Canvas access and some integrations, including PowerSchool connections, while Instructure and affected institutions investigated the scope. ShinyHunters claimed responsibility and reported a much larger number of affected records than has been independently verified, prompting congressional and cybersecurity scrutiny.
First Article: 05/04/26
Latest Article: 05/16/26
Summary
- Instructure reported Canvas compromises on April 29 and May 7, with the second incident contributing to service outages and maintenance mode.
- Potentially exposed information includes usernames, email addresses, student IDs, course and enrollment details, and Canvas messages.
- Schools reported operational effects including blocked Canvas access, disrupted finals-period coursework, and suspended PowerSchool integrations.
- ShinyHunters claimed access to more than 275 million or 280 million records across nearly 9,000 institutions, but those figures have not been independently verified.
- Instructure said data from the first incident was returned and destroyed and that it found no evidence of data theft in the May 7 incident; experts and officials continued to question whether deletion could be confirmed.
- The US House Homeland Security Committee and CISA reviewed Instructure’s response, security controls, and coordination.
History
The main update is added official scrutiny: the US House Homeland Security Committee and CISA reviewed Instructure’s response and coordination. The rest of the story is largely reaffirmed, with the same compromise timeline, exposed data types, and unverified ShinyHunters claims.
The story now has more concrete incident timing and a clearer technical picture of what was exposed and disrupted, while Instructure also added a stronger rebuttal to the largest theft claims. The alleged scope remains large, but independent verification is still lacking.
