
Instructure’s Canvas learning management system suffered the largest educational data breach on record in May 2026. The hacking group ShinyHunters claimed to have stolen 3.65 terabytes of data from roughly 275 million users across 8,809 universities, schools, and educational ministries worldwide.
How the Canvas Breach Unfolded
Unauthorized actors first accessed Canvas systems on April 25, 2026. Four days later, Instructure detected the intrusion, revoked the unauthorized access, and brought in third-party cyber forensics experts. On May 1, Instructure disclosed the incident publicly. By May 2, the company confirmed that names, email addresses, student ID numbers, and user messages had been stolen for ransom.
ShinyHunters posted a ransom note claiming responsibility on May 3. Instructure initially said the situation was contained and that passwords, government IDs, and financial data were not involved. But on May 7, after Instructure attempted to implement security patches instead of negotiating, ShinyHunters struck again. They replaced the Canvas login page with a ransomware message, threatening to release data unless payment was made by May 12.
The second attack happened during the end of the academic year for many institutions, disrupting final exams at universities including Arizona State University, UC Berkeley, and Sacramento State.
Global Impact Across Dozens of Countries
The breach affected institutions in the United States, United Kingdom, Canada, Australia, New Zealand, Sweden, the Netherlands, Hong Kong, and Singapore. In the US alone, Canvas serves 41% of higher education institutions and some K-12 schools.
In Hong Kong, 42,000 students and staff at the Hong Kong Polytechnic University were impacted. In Australia, universities including Melbourne, RMIT, and Griffith offered assignment extensions while the Queensland Department of Education temporarily disabled Canvas access entirely. At least 44 educational institutions in the Netherlands were affected.
MIT, Oxford, and other top-tier universities were named among the victims. The University of California system instructed all locations to temporarily block or redirect Canvas access as a precaution.
Instructure Settles With Hackers, Lawsuit Follows
On May 11, Instructure apologized for its lack of transparency and announced it had reached an agreement with the unauthorized actor. The compromised data was reportedly destroyed, though the terms of the deal were not made public. Unconfirmed reports suggest Instructure paid 0 million in ransom.
A class action lawsuit was filed against Instructure on May 13 in the US District Court for the Southern District of California on behalf of a San Diego resident. The House Homeland Security Committee also launched an official investigation, requesting a closed-door briefing from CEO Steve Daly.
The root cause was traced to Instructure’s Free-For-Teacher accounts, which provided the initial entry point for the attackers.
Frequently Asked Questions
What data was stolen in the Canvas data breach?
Names, email addresses, student ID numbers, and messages among users were compromised. Instructure said passwords, birth dates, government IDs, and financial information were not involved.
How many people were affected by the Canvas breach?
ShinyHunters claimed 275 million users were affected across 8,809 educational institutions worldwide. The breach is considered the largest educational security incident on record.
Is Canvas safe to use now?
Instructure says Canvas is fully back online and safe to use. The breach was traced to Free-For-Teacher account vulnerabilities that have since been patched.
Who is ShinyHunters?
ShinyHunters is a criminal hacking group that has been linked to multiple high-profile data breaches. They were identified as the perpetrators of the Canvas attack and threatened to release stolen data unless Instructure paid a ransom.
