Briefing

Instructure’s Canvas faces 275‑million‑record data breach and defacement by ShinyHunters

security
by Lawrence Abrams ·

Investigate the Instructure incident, monitor Canvas Data 2 and Canvas Beta for API key issues, and keep clients informed of potential data exposure.

What to do now

Notify clients of the incident, monitor Canvas services for API key disruptions, and coordinate with Instructure for updates.

Summary

On 11 May 2026, Instructure, the cloud‑based education technology company that runs the Canvas learning management system (LMS), confirmed that a cross‑site scripting (XSS) flaw had been exploited by the cyber‑crime group ShinyHunters. The attackers hijacked authenticated admin sessions, defaced login portals with a ransom note, and exfiltrated more than 3.6 TB of uncompressed data. The stolen material included usernames, email addresses, course names, enrollment details and private messages for an estimated 275 million students, teachers and staff across 8,809 schools, universities and online platforms. The breach was first discovered on 29 April, when Instructure revoked the intruder’s privileges and engaged forensic experts. By 7 May the attackers had injected malicious JavaScript into the free “Free‑For‑Teacher” version of Canvas, and the defacement message demanded a settlement before 12 May or risk a public leak of the data.

The incident followed an earlier breach in the same month in which ShinyHunters claimed to have harvested data through Canvas’s export features—DAP queries, provisioning reports and user APIs—amassing hundreds of gigabytes of sensitive user information. While Instructure has not yet released a detailed response, several universities, including the University of Colorado Boulder and Rutgers, issued statements acknowledging the breach. Canvas was temporarily taken offline, and its status page now shows “scheduled maintenance” with an expected return. The outage disrupted final‑exam periods and forced educators to seek alternative platforms, while the ransom deadline pressured institutions to negotiate settlements with the attackers.

The breach underscores the vulnerability of LMS platforms to XSS attacks and the risks of built‑in data export tools. Instructors and administrators are urged to audit export settings, review API permissions and implement stricter credential management. The incident also raises concerns about GDPR enforcement and potential legal liabilities for data controllers, as schools must decide whether to comply with the extortion demands or risk a public data leak. Instructors, students and IT staff have flooded social media with complaints, highlighting the urgent need for rapid patching, incident response and stronger security governance in education technology.

Key changes

  • Instructure reported a cybersecurity incident and is investigating with external forensics.
  • Canvas Data 2 and Canvas Beta services are under maintenance, potentially affecting API key‑dependent tools.
  • The incident may be related to a prior September 2025 breach involving a Salesforce data leak.
  • ShinyHunters claimed responsibility for the September 2025 breach and listed Instructure on a data leak site.
  • No response has been received from Instructure to BleepingComputer inquiries.
  • The company has not confirmed whether the current maintenance is linked to the incident.

Affects

internal

Source angles · 6 perspectives

Bleeping Computer
Independent angle

Edu tech firm Instructure discloses cyber incident, probes impact

Open
Bleeping Computer
Independent angle

Instructure confirms data breach, ShinyHunters claims attack

Open
Bleeping Computer
Independent angle

Instructure hacker claims data theft from 8,800 schools, universities

Open
Bleeping Computer
Independent angle

Instructure confirms hackers used Canvas flaw to deface portals

Open
Hacker News (front page)
Independent angle

Canvas Outage After ShinyHunters Breach Threatens 275M Student Records

Open
Krebs on Security
Independent angle

Canvas Platform Suffers Data Extortion Attack by ShinyHunters, 275 Million Users Targeted

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting