Last Update: 08/01/2026 at 2:00 PM EST

Instructure Breach Exposes Canvas Data

Coverage from BleepingComputer, CNET, and others

Articles

8

Active Days

13

The Topic

Instructure Breach Exposes Canvas Data topic image

Instructure’s Canvas learning management platform was compromised in incidents reported on April 29 and May 7, exposing or potentially exposing usernames, email addresses, student identifiers, course and enrollment information, and messages across schools and universities. The incidents disrupted Canvas access and some integrations, including PowerSchool connections, while Instructure and affected institutions investigated the scope. ShinyHunters claimed responsibility and reported a much larger number of affected records than has been independently verified, prompting congressional and cybersecurity scrutiny.

First Article: 05/04/26

Latest Article: 05/16/26

Summary

  • Instructure reported Canvas compromises on April 29 and May 7, with the second incident contributing to service outages and maintenance mode.
  • Potentially exposed information includes usernames, email addresses, student IDs, course and enrollment details, and Canvas messages.
  • Schools reported operational effects including blocked Canvas access, disrupted finals-period coursework, and suspended PowerSchool integrations.
  • ShinyHunters claimed access to more than 275 million or 280 million records across nearly 9,000 institutions, but those figures have not been independently verified.
  • Instructure said data from the first incident was returned and destroyed and that it found no evidence of data theft in the May 7 incident; experts and officials continued to question whether deletion could be confirmed.
  • The US House Homeland Security Committee and CISA reviewed Instructure’s response, security controls, and coordination.

History

07/23/2026

The main update is added official scrutiny: the US House Homeland Security Committee and CISA reviewed Instructure’s response and coordination. The rest of the story is largely reaffirmed, with the same compromise timeline, exposed data types, and unverified ShinyHunters claims.

07/22/2026

The story now has more concrete incident timing and a clearer technical picture of what was exposed and disrupted, while Instructure also added a stronger rebuttal to the largest theft claims. The alleged scope remains large, but independent verification is still lacking.

Featured

Timeline: 13 Days

May 4May 6May 9May 11May 14May 16

Additional Articles

⭐⭐⭐⭐⭐

Berkshire Eagle05-16-2026
Pittsfield Public Schools reported disrupted secondary grade reporting in Massachusetts after Canvas was compromised on April 29 and May 7.

⭐⭐⭐

KOIN / Danny Peterson05-08-2026
Portland Public Schools updated parents after a reported student data breach led Instructure to halt nationwide Canvas services while assessing accessed information.
Hays Post / Cristina Janney05-13-2026
Instructure notified Kansas school district Hays USD 489 in a Canvas data-breach update on Friday, leading district staff to disconnect Canvas connections during the investigation.
Security Magazine05-04-2026
Instructure disclosed and investigated a May 1 cybersecurity incident believed contained by May 2, while ShinyHunters claimed school data theft possibly tied to Salesforce misconfiguration.
USA Today05-08-2026
Instructure said a May 7 security incident disabled Canvas for hours, disrupting U.S. schools while ShinyHunters claimed data access across thousands of institutions worldwide.