Last Update: 08/01/2026 at 2:00 PM EST

Canvas Breach Hits Schools Nationwide

Coverage from The New York Times, GovTech, and others

Articles

17

Active Days

53

The Topic

Canvas Breach Hits Schools Nationwide topic image

Instructure's Canvas learning platform was hit by a breach and extortion attempt tied to ShinyHunters, exposing student and staff data at schools and universities that use the service. The incident temporarily disrupted access during finals and end-of-term work, while schools and district officials assessed what information may have been exposed. It also renewed scrutiny of how much sensitive student data is concentrated in a small number of education technology platforms and how exposed identities can fuel phishing and other follow-on attacks.

First Article: 05/05/26

Latest Article: 06/26/26

Summary

  • Instructure said an unauthorized actor exploited an issue tied to Free-for-Teacher accounts on Canvas.
  • ShinyHunters claimed the intrusion and used payment-or-leak threats, with reports of deadline-based extortion messaging.
  • The breach affected a large number of schools and universities, with reports ranging from thousands of schools to broad student and staff reach.
  • Exposed data appears to include names, email addresses, student ID numbers, and platform messages; several reports say passwords and financial data were not involved.
  • Canvas was taken offline or placed into maintenance mode during a high-impact period, forcing schools to adjust exams, deadlines, and course communications.
  • Districts and universities across multiple states warned users about phishing risk and advised caution after the exposure of identity data.
  • The incident sharpened attention on education technology vendors as high-value targets because many institutions rely on shared platforms for core classroom functions.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 53 Days

May 5May 14May 26Jun 4Jun 16Jun 25

Additional Articles

⭐⭐⭐⭐⭐

ADN05-09-2026
Instructure faced a ransomware-driven Canvas breach in 2026 after Free-for-Teacher account exploitation, exposing student and staff data and disrupting access in U.S. K-12 districts.
NBC4i / Isabel Cleary06-26-2026
Columbus, Ohio technology director Sam Orth retired after a 2024 ransomware attack, with a breach report still not publicly scheduled.
Vermont Daily Chronicle / Timothy Page05-11-2026
Instructure disclosed a ShinyHunters-linked ransomware breach of Canvas starting in early May, with potential education data exposure affecting institutions including Vermont.
Wired / Lily Hay Newman05-08-2026
ShinyHunters targeted Instructure's Canvas with an extortion attempt starting May 1, leading Instructure to report exposed student identifiers and widespread U.S. school disruption.
Rocketnews05-05-2026
Instructure confirmed a ShinyHunters-linked breach on what date unknown, affecting student information at schools in Massachusetts and Tennessee with exposed names, emails, and messages.
ZDNET / Charlie Osborne05-08-2026
In Salt Lake City, Instructure investigated a May 7 ShinyHunters ransomware claim after alleged Canvas student-record exposure and temporary platform downtime for containment.

⭐⭐⭐

SCTimes05-08-2026
Instructure disabled Canvas during a ransomware-linked investigation after ShinyHunters claimed large-scale student and staff data access, while universities reported outages worldwide on May 7.
WOWK 13 News05-09-2026
ShinyHunters claimed an Instructure Canvas breach with extortionary messages, while Instructure said containment and remediation occurred and some U.S. schools saw access disruption.
Gates County Index05-10-2026
In North Carolina, Hertford and Gates County schools responded to an Instructure Canvas breach claim by a ransom group after Instructure reported unauthorized access starting April 25.
Fox 12 Oregon / Vince Ybarra05-08-2026
Instructure disclosed investigation and recovery efforts for a Canvas nationwide outage tied to a ransomware claim, following a May 1 exposure of student identifiers and messages.
Security Affairs / Pierluigi Paganini06-17-2026
Resecurity reports June 2026 education-sector cyber incidents involving ShinyHunters and FulcrumSec, including Infinite Campus staff data theft and Global Schools Foundation ransomware.
UPI05-08-2026
Instructure reported recovery after a Thursday ransomware attack on Canvas in the United States, as ShinyHunters claimed access to data from millions.
WBAY / Drew Best05-07-2026
In May 2025, Instructure investigated a claimed ransomware breach of Canvas that disrupted U.S. universities including Wisconsin and potentially exposed student identifiers and messages.
Class Action U06-04-2026
Termite claimed responsibility for a ransomware-linked data-breach affecting UEI College on May 29, 2026, as of May 30, 2026 reporting.