Skip to content

Instructure

Disclosed May 2, 20264 months agoUnverified

Instructure Canvas breach exposes students' messages at nearly 9,000 schools

Edtech firm Instructure confirmed attackers exploited a platform flaw in its Canvas LMS and took names, emails, student IDs and messages between users; ShinyHunters claimed data on about 275 million people at nearly 9,000 schools and later defaced login pages in a second breach. Instructure said it reached an agreement with the group to delete the data, and a House committee sought testimony.

What is known

People affectedNot stated in the sources we have
DisclosedMay 2, 2026
DiscoveredApr 29, 2026
AttackExtortion
Data exposedNames, Emails, Messages, Children's data, Education records
SectorEducation · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 2
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Instructure

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.