Skip to main content
Mallory
Back to intelligence
education-sector-threatbreach-disclosure-notificationoperational-disruptionthird-party-vendor-breach

Instructure discloses cyber incident affecting Canvas services

Updated 13h agoFirst seen May 2, 2026141 sources

Instructure, the U.S. education technology company behind the Canvas learning platform, disclosed that it recently suffered a cybersecurity incident involving a criminal threat actor and has engaged outside forensic experts to investigate the scope and impact. The company said it is still determining what systems or data were affected and has not yet confirmed whether service disruptions beginning May 1—including maintenance affecting Canvas Data 2, Canvas Beta, and tools dependent on API keys—are directly tied to the incident.

The disclosure comes as education technology providers face sustained targeting because they hold large volumes of student and teacher information. Reporting around the incident notes that Instructure had already disclosed a separate Salesforce-related breach in September 2025 linked to social engineering, while external leak-site style listings have also associated the company with ShinyHunters claims that remain unverified. The latest incident also follows other major school technology breaches, including PowerSchool and Infinite Campus, underscoring continued pressure on the sector.

Share:
Instructure discloses cyber incident affecting Canvas services
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

51 events from the most recent confirmed update back to the earliest known activity.

51 EVENTS
May 23, 20263d ago

LBUSD, Cal State Long Beach, and LBCC tied to Canvas disruption

Reporting said the Instructure/Canvas cyberattack disrupted access for Long Beach Unified School District, California State University Long Beach, and Long Beach City College, adding three newly disclosed educational institutions to the list of affected organizations. The reference said users encountered ransom-style messages attributed to ShinyHunters and that the outage affected grading, coursework, and communications.

Ransomware Attack Disrupts Grading Platform Used by LBUSD Cal State and LBCC - CySecurity News - Latest Information Security and Hacking Incidents
May 15, 202611d ago

FBI issues PSA warning on ShinyHunters extortion tactics

The FBI issued a Public Service Announcement warning that cybercriminal claims tied to incidents such as the Canvas attack may be exaggerated or fabricated to pressure victims into paying. The bureau advised victims not to engage with extortionists, to verify suspicious communications through trusted channels, preserve evidence, and report incidents to IC3.

ShinyHunters Claims Credit for Cyber-Attack on Online Learning Management System
May 14, 202612d ago

Senate HELP Committee joins congressional scrutiny of Instructure

The Senate Committee on Health, Education, Labor, and Pensions sent a letter to Instructure CEO Steve Daly seeking answers about the repeated Canvas attacks, including whether a ransom was paid and whether the incidents were linked to the September 2025 Salesforce compromise. This expanded congressional scrutiny beyond the House Homeland Security Committee's earlier inquiry.

Congress Puts Heat on Instructure After Canvas Outage
May 13, 202613d ago

House lawmakers demand Instructure testify on Canvas breaches

U.S. House Homeland Security Committee lawmakers pressed Instructure to testify and answer questions about the two Canvas-related cyberattacks, including how the same vulnerability was allegedly exploited twice, what data was taken, how schools were notified, and whether the company coordinated adequately with CISA. The development marked an escalation from the committee's earlier inquiry into active congressional scrutiny of Instructure's incident response.

US lawmakers demand answers from Instructure after Canvas data breaches | TechCrunch
May 12, 202614d ago

Instructure says it paid extortion demand to prevent Canvas data leak

Instructure disclosed that it reached an agreement with the extortion group tied to the Canvas breach, paid to stop publication of the stolen data, received the data back, and obtained digital confirmation that it was destroyed. The company also said affected customers would not face separate extortion attempts under the agreement.

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

ShinyHunters resets Canvas leak deadline to May 12

In reporting published May 12, ShinyHunters said schools affected by the Instructure/Canvas breach had until May 12, 2026 to negotiate directly before stolen data would be leaked. This updated the gang's extortion posture after the earlier defacement campaign had already threatened publication on the same date.

Double Canvas intrusion confirmed as ShinyHunters resets leak deadline

Report details XSS flaws used to hijack Canvas admin sessions

Reporting said the attackers exploited multiple cross-site scripting vulnerabilities in Canvas user-generated content features to hijack authenticated administrator sessions and carry out privileged actions. The technical details provided new insight into how the Free-for-Teacher compromise and subsequent May 7 defacement were executed.

Instructure reaches 'agreement' with ShinyHunters to stop data leak
May 11, 202615d ago

ShinyHunters says its shinyhunte.rs domain was suspended

ShinyHunters claimed on May 11 that its clearnet domain, shinyhunte.rs, had been suspended and was no longer under the group's control, warning users not to trust it. The suspension prompted speculation about possible law enforcement action, although no official seizure was confirmed in the reference.

ShinyHunters claims domain suspension after Canvas LMS attacks | brief | SC Media

Australian cyber agencies coordinate Canvas breach response

Australia's National Office of Cyber Security and the Australian Signals Directorate said they were coordinating the response to the Instructure/Canvas incident and warned affected institutions not to pay ransom demands or engage with unsolicited extortion attempts. The move marked a formal Australian government response to the ShinyHunters-linked breach affecting schools and universities.

Deadline set by cybercriminal group looms as some institutions regain Canvas access - ABC News

FBI acknowledges Canvas breach as House committee opens inquiry

U.S. authorities publicly engaged with the Instructure/Canvas incident, with the FBI saying it was aware of the compromise and the House Homeland Security Committee opening an inquiry. The development marked a federal response to the breach and disruption affecting educational institutions.

Canvas breach spotlights cybercriminal appetite for student data - Nextgov/FCW

Birmingham, Oxford, Edinburgh, and Mississippi State report Canvas disruption

IT Pro reported that the Universities of Birmingham, Oxford, Edinburgh, and Mississippi State University were among institutions dealing with disruption from the Instructure/Canvas cyberattack during the exam period. This adds four newly disclosed institutions publicly tied to the broader incident across the UK and U.S.

Universities worldwide still struggling with fallout from Canvas cyber attack | IT Pro
May 8, 202618d ago

Proposed class action lawsuit emerges over Canvas data breach

The reference says the 2026 Canvas data breach prompted a proposed class action lawsuit in the United States. This marks a new legal escalation beyond the previously documented institutional responses, extortion activity, and congressional scrutiny.

2026 Canvas data breach - Wikipedia

UMass Lowell, MIT, Northeastern, Emerson, and Wellesley tied to Canvas outage

CBS Boston reported that the Instructure/Canvas cyberattack disrupted academic operations at additional Massachusetts institutions, including UMass Lowell, MIT, Northeastern University, Emerson College, and Wellesley Public Schools. The outage during finals forced some schools to postpone exams or deadlines, while UMass Dartmouth was also affected but had already been captured in earlier reporting.

Canvas goes down after hack, forcing some Massachusetts colleges to postpone final exams - CBS Boston

Dutch universities block Canvas after breach escalation

Dutch institutions including the University of Twente, Erasmus University Rotterdam, Fontys University of Applied Sciences, and Vrije Universiteit Amsterdam temporarily blocked Canvas in response to the ongoing Instructure/ShinyHunters incident, while Deltion later restored access after review. The schools said they were investigating potential impact, running crisis response measures, and warning users about phishing tied to the breach.

Universiteiten en hogescholen blokkeren studie-app Canvas na hack

Howard County schools posts Canvas breach updates

Howard County Public School System published updates about the May 2026 Instructure/Canvas security breach, indicating the district was publicly responding to the incident and communicating impact or guidance to its community. This adds HCPSS as another newly disclosed educational institution tied to the broader breach.

May 2026 Instructure/Canvas Security Breach Updates - HCPSS News

University of Memphis posts notice on Canvas security incident

The University of Memphis published a notice about the May 2026 Instructure/Canvas security incident, indicating it was publicly responding to the vendor breach and communicating potential impact or guidance to its community. This adds the University of Memphis as another newly disclosed institution tied to the broader incident.

Instructure Data Breach | May 2026

Instructure links May 7 attack to Free-For-Teacher vulnerability

Instructure said attackers breached its infrastructure a second time through an unspecified vulnerability in the Free-For-Teacher version of Canvas, leading to the May 7 defacement and disruption. The company said it temporarily took Canvas offline, shut down Free-For-Teacher accounts during containment, and had found no evidence of persistence, credential theft, or broader data theft from that disruption.

Canvas E-Learning Platform Breached by Cybercriminals

NUS, SIM, and ISCA named among Singapore institutions hit by Canvas breach

The Straits Times reported that the National University of Singapore, Singapore Institute of Management, and the Institute of Singapore Chartered Accountants were among organizations affected by the global Instructure/Canvas breach. Singapore's Cyber Security Agency said it was monitoring the incident and had contacted affected organizations to offer assistance and mitigation advice, while the institutions said core internal systems were largely unaffected and contingency measures were in place.

NUS named in global data breach list | The Straits Times

University of Illinois and UMass Dartmouth alter exams after Canvas disruption

The University of Illinois and the University of Massachusetts Dartmouth reported that the Canvas cyberattack disrupted coursework during finals, forcing postponements, rescheduling, or deadline extensions for exams and assignments. This adds two newly disclosed institutions with concrete academic impact from the broader Instructure incident.

Chaos erupts as cyberattack disrupts learning platform Canvas amid finals - Ars Technica

OCAD, Mohawk, Ontario Tech, and Ivey named in Canvas breach

CBC reported that several Ontario institutions were impacted by the Instructure/Canvas cyber incident, including OCAD University, Mohawk College, Ontario Tech University, and Western University's Ivey Business School. This adds four newly disclosed Canadian institutions publicly tied to the broader breach; the University of Toronto had already been identified in earlier reporting.

U of T, OCAD among Ontario universities impacted by Canvas cyber breach | CBC News

Idaho State, Toronto, and Chicago report Canvas disruption

BBC reported that Idaho State University, the University of Toronto, and the University of Chicago publicly confirmed operational disruption from the Instructure/Canvas cyber incident. The report said the outage affected coursework and examinations as institutions warned students about prolonged access issues or took precautionary steps such as logging out or disabling access.

International cyber attack disrupts swath of universities and schools

Queensland's QLearn reports disruption from Canvas cyber incident

ABC Australia reported that Queensland's QLearn platform, used across universities, TAFEs, and public schools, was disrupted as part of the broader Instructure/Canvas cyber incident. Officials and education providers said investigations were ongoing and warned users about phishing and scam risks tied to exposed contact information.

Tens of thousands of students and teachers unable to access QLearn following cybersecurity breach - ABC News

Instructure says Canvas mostly restored as schools report ongoing disruption

By late 2026-05-08, Instructure said Canvas had become available for most users following the widespread cyberattack, though some institutions continued reporting outages on Friday. The disruption affected schools internationally, including exam cancellations at Penn State University and service warnings from the University of Sydney.

International cyber attack disrupts swath of universities and schools

Sacramento State reports ongoing Canvas disruption from cyberattack

CBS Sacramento reported that Sacramento State was among the institutions affected by the nationwide Instructure/Canvas cyberattack, with disruption continuing into Friday morning during the run-up to finals and graduation. Users saw a ShinyHunters ransom message threatening to leak stolen data unless Instructure paid by May 12, adding Sacramento State as a newly disclosed impacted university.

Sacramento State caught in nationwide cyberattack targeting online learning platform - CBS Sacramento

Duke, UCLA, and Nebraska reported among Canvas-affected institutions

Reuters, citing student newspaper reporting, said Duke University, UCLA, and the University of Nebraska were among institutions reporting impact from the Instructure/Canvas breach and related disruption. This adds three newly disclosed universities to the list of schools publicly tied to the incident.

teiss - News - Education tool Canvas hacked, multiple US college newspapers report

University of Virginia posts notice on Canvas security incident

The University of Virginia published a notice about the May 2026 Instructure/Canvas cybersecurity incident, indicating it was publicly responding to the vendor breach and communicating potential impact or guidance to its community. This adds UVA as another newly disclosed institution tied to the incident.

Instructure Cybersecurity Incident - May 2026 | UVACanvas

Harvard, Columbia, and Georgetown warn students about Canvas breach

WIRED reported that Harvard, Columbia, and Georgetown warned students about the Instructure/Canvas security incident and its potential impact. This adds three newly disclosed institutions publicly responding to the breach, while Rutgers had already been identified in earlier reporting.

The Canvas Hack Is a New Kind of Ransomware Debacle | WIRED

UBC and SFU acknowledge Canvas breach impact

The University of British Columbia and Simon Fraser University said the Instructure/Canvas cyber breach could affect their communities, with SFU warning that exposed data may include names, email addresses, student ID numbers, and user messages. UBC said it learned of the incident late Tuesday and advised users to log out of Canvas, change passwords if they had logged in that afternoon, and remain alert for phishing.

UBC, SFU among thousands of universities affected by Canvas software cyber breach | CBC News
May 7, 202619d ago

TasTAFE says Canvas breach affected Tasmania and involved ransom demand

ABC Australia reported that Tasmania was among the jurisdictions affected by the Instructure/Canvas breach, with TasTAFE investigating exposure and stating that the hackers were demanding a ransom. The article also said Australian education providers and authorities were assessing impact while the stolen Canvas data had not yet been publicly released at the time of reporting.

Canvas data breach leaves education providers scrambling as student data compromised - ABC News

Pitt County Schools posts update on Canvas data breach

Pitt County Schools published an update regarding the Instructure/Canvas data breach, indicating the district was publicly responding to the incident and communicating potential impact or guidance to its community. This adds Pitt County Schools as another newly disclosed affected institution tied to the broader breach.

Important Update Regarding Canvas Data Breach | Post Details (DBPP)

University of Utah responds to Canvas data breach

The University of Utah published a notice saying its UIT team was responding to the Instructure/Canvas security incident and communicating guidance or impact information to its community. This adds the University of Utah as another publicly disclosed institution tied to the broader breach.

UIT responding to Canvas security incident - @theU

Universities report widespread Canvas outage amid cyber incident

On 2026-05-07, universities across the U.S. reported outages affecting the Canvas learning platform during the ongoing Instructure cyber incident. Institutions including Stanford, Columbia, Princeton, and Boston College said they were experiencing disruption or warned students to watch for suspicious messages.

Harvard, BC among schools reporting online cyber outage

Canvas defacement campaign expands to about 330 institutions

BleepingComputer reported that ShinyHunters' extortion-related defacement spread to roughly 330 colleges and universities, appearing on Canvas login pages and in the Canvas app with a ransom deadline of May 12, 2026. The report also said Instructure took Canvas offline in response, marking a significant escalation in scope and operational impact.

Canvas login portals hacked in mass ShinyHunters extortion campaign

ShinyHunters defaces Canvas login pages at three schools

TechCrunch observed defaced Canvas login pages at three schools displaying a message attributed to ShinyHunters, threatening to publish stolen data on May 12 unless Instructure negotiated a settlement. The defacement appeared linked to an injected HTML file, indicating a new extortion escalation beyond the previously disclosed data breach.

Hackers deface school login pages after claiming another Instructure hack | TechCrunch
May 6, 202620d ago

RMIT and UTS extend deadlines after Canvas disruption

The Guardian reported that Australia's RMIT University and the University of Technology Sydney were affected by the Instructure/Canvas incident and extended assignment deadlines in response. This adds two newly disclosed institutions with concrete academic impact from the broader breach and outage.

Canvas hack: is it ever a good idea to pay a ransom, and what happens to the data? | Cybercrime | The Guardian

University of California posts UC-wide notice on Canvas breach

UCnet published a notice about the nationwide security breach involving Canvas, indicating the University of California system was publicly responding to the Instructure incident and assessing or communicating potential impact to its community. This adds the University of California as another newly disclosed institution tied to the breach.

Nationwide security breach involving Canvas | UCnet

University of Pennsylvania says Canvas breach affected over 300,000 users

The Daily Pennsylvanian reported that the University of Pennsylvania said more than 300,000 Penn users were affected by the Instructure/Canvas hack claimed by ShinyHunters. This adds Penn as a newly disclosed impacted institution and provides a specific user-impact estimate tied to the broader breach.

Over 300,000 Penn users affected in Canvas hack, cybercrime group claims - The Daily Pennsylvanian

Baylor University says Instructure breach affects its community

Baylor University Information Technology Services published a notice stating that the Instructure data breach impacts U.S. universities, indicating Baylor was among the institutions affected or assessing impact from the Canvas incident. This adds Baylor as a newly disclosed institution publicly responding to the breach.

UPDATE: Instructure Has Taken Canvas Offline | Information Technology Services | Baylor University
May 5, 202621d ago

Texas Education Agency issues Canvas security incident guidance

The Texas Education Agency published a security advisory for Canvas users in response to the Instructure incident, providing guidance and public communication about the breach's potential impact. This adds TEA as another publicly disclosed education-sector entity responding to the Canvas incident.

Security Advisory: Canvas (Instructure) Security Incident - Guidance for Canvas Users

St. Petersburg College posts notice on Instructure cyber incident

St. Petersburg College published a notice about the Instructure cybersecurity incident, indicating the college was monitoring or responding to the Canvas-related breach and its potential impact on the institution. This adds St. Petersburg College as another publicly disclosed affected institution tied to the incident.

Instructure Cybersecurity Incident || St. Petersburg College

Colorado Boulder, Rutgers, and Tilburg acknowledge Canvas incident

Several universities, including the University of Colorado Boulder, Rutgers, and Tilburg University, issued statements acknowledging the broader Instructure/Canvas security incident or said they were still assessing whether their data was affected. This added newly disclosed institutions publicly responding to the breach's potential impact.

Instructure hacker claims data theft from 8,800 schools, universities

ShinyHunters shares sample Instructure data with TechCrunch

TechCrunch reported that ShinyHunters shared sample data allegedly stolen from Instructure, tied to two U.S. schools in Massachusetts and Tennessee, appearing to validate part of the gang’s breach claims. The broader victim-count claims remained unverified.

Hackers steal students' data during breach at education tech giant Instructure | TechCrunch
May 4, 202622d ago

UT Austin posts notice on Canvas vendor security incident

The University of Texas at Austin published a notice about the May 2026 Canvas vendor security incident, indicating it was publicly responding to the Instructure breach and assessing or communicating potential impact to its community. This adds UT Austin as another newly disclosed institution tied to the incident.

Canvas Vendor Security Incident - May 2026 | Enterprise Technology

UMass Amherst issues Canvas security incident monitoring update

UMass Amherst Information Technology published an update saying it was monitoring the Instructure/Canvas security incident and providing Canvas-related status information. This represents a newly disclosed institution publicly responding to the breach's potential impact.

Monitoring: Instructure Security Incident & Canvas Updates Mon., 5/4 : UMass Amherst Information Technology : UMass Amherst

Wayzata Public Schools warns parents about Canvas breach impact

Wayzata Public Schools sent warning letters to parents about the Canvas/Instructure data breach, indicating the incident affected data tied to the district. This represents a newly disclosed affected institution responding directly to the breach.

Canvas data breach: Wayzata Public Schools sends warning letter to parents | FOX 9 Minneapolis-St. Paul
May 3, 202623d ago

Instructure confirms data exposure and details remediation steps

Instructure said the 2026 cyber incident exposed certain user data, including names, email addresses, student ID numbers, and user messages at affected institutions, while reporting no evidence that passwords, dates of birth, government identifiers, or financial data were involved. The company said it engaged third-party cybersecurity experts and law enforcement, deployed patches, increased monitoring, rotated application keys, and required customers to re-authorize API access.

Instructure confirms data breach, ShinyHunters claims attack
May 1, 202625d ago

Instructure discloses new cyber incident and starts forensic probe

Instructure disclosed that it recently experienced a cybersecurity incident caused by a criminal threat actor. The company said it engaged outside forensic experts, began investigating the scope and impact, and would share more information as the investigation progresses.

Instructure says some Canvas services entered maintenance

Beginning May 1, Instructure customers were told that services including Canvas Data 2 and Canvas Beta were under maintenance, and that tools relying on API keys might experience issues. The company did not confirm whether this maintenance was connected to the cyber incident.

Apr 29, 202627d ago

Instructure says it discovered the breach on April 29

Instructure said the breach underlying the Canvas incident was discovered on April 29, 2026, before its public disclosure. The company later linked the May 7 defacement disruption to this earlier compromise.

Multiple universities forced to reschedule final exams after Canvas cyber incident | The Record from Recorded Future News
Oct 3, 20258mo ago

ShinyHunters leak-site listing names Instructure as a victim

A ransomware/leak-site style listing attributed an Instructure incident to ShinyHunters and claimed broad compromise metrics, including compromised employees and users. The listing said the attack was discovered on October 3, 2025, though the claims were not independently verified in the reference material.

Sep 21, 20258mo ago

Instructure discloses Salesforce-related security incident

Instructure published an update about a separate security incident affecting its Salesforce environment that was tied to social engineering. Later reporting said ShinyHunters claimed responsibility for this 2025 breach.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Instructure discloses cyber incident affecting Canvas services | Mallory