The Canvas Breach: How 275 Million Records Went Up for Ransom in Two Weeks
- Syed Adnaan

- Aug 13
- 2 min read
In late April 2026, students and teachers logging into Canvas — the learning management system used by roughly 41% of U.S. higher education institutions and around 30 million active users worldwide had no idea they were about to become part of the largest education-sector breach on record.
What happened
Canvas is operated by Instructure, a private edtech company whose software runs coursework, grading, and messaging for over 8,000 schools, universities, and ministries of education globally. On April 30, 2026, the extortion group ShinyHunters exploited a vulnerability in Instructure’s production systems to gain unauthorized access to Canvas.
Instructure detected the intrusion around April 29–30 and confirmed it publicly on May 1. By May 6, the company said the incident had been contained and that it had found no evidence passwords, birth dates, government IDs, or financial data had been touched.
That containment claim didn’t hold. On May 7, ShinyHunters returned through a second Canvas vulnerability, defaced course pages at major universities — including Harvard, the University of Pennsylvania, Duke, and Wisconsin — and replaced login pages with a ransom note. The timing was brutal: the outage landed during finals season for many schools.
The scale of the claim
ShinyHunters claimed to have exfiltrated 3.65 terabytes of data tied to roughly 275 million users across nearly 9,000 institutions, and by May 5 reporting indicated the group had pulled 231 million unique email addresses from Canvas. The group listed Instructure on its dark web leak site on May 3, warning it would leak the data unless the company paid by May 6.
What Instructure has actually confirmed is narrower: names, institutional email addresses, student ID numbers, and Canvas inbox messages. ShinyHunters’ broader claims of private student-teacher messages remain unverified.
How it ended
Instructure and ShinyHunters reportedly reached an agreement around May 11–12, 2026, that the company says prevented the stolen data from being published. No ransom amount has been disclosed by either party.
Notably, this was Instructure’s second confirmed compromise by ShinyHunters in about eight months — the group had previously breached the company’s Salesforce environment through a social engineering attack in September 2025.
Why it matters
This breach fits a pattern security teams have been watching all year: attackers are targeting the administrative and support layer of shared edtech and SaaS platforms rather than individual school networks. A single successful intrusion cascades across thousands of downstream victims — the same playbook ShinyHunters used in the 2024 Snowflake supply-chain campaign that hit roughly 165 organizations.
Key takeaways for institutions using shared platforms: - Vendor breaches are your breaches. Contractual data-protection clauses matter, but they don’t stop an outage during finals week. - “Contained” is a moving target. Instructure’s own containment claim was proven wrong within a week. - Claimed numbers and confirmed numbers diverge sharply in nearly every large 2026 breach — treat headline figures as upper bounds, not facts.
This post is part of our ongoing breach-tracking series. Sources: Instructure public disclosures, ShinyHunters leak-site statements, and independent reporting from TechCrunch, Reed Smith, and other outlets tracking the incident.
.png)
Comments