2026 Canvas data breach

In late April 2026, Canvas LMS, the learning management system operated by Instructure, suffered a massive data breach that is now considered the largest educational security incident on record. Unauthorized actors gained access on April 25, stealing names, email addresses, student ID numbers, and private messages, though Instructure stated that passwords and financial data were not compromised. After initially containing the breach and disclosing it on May 1, Instructure claimed on May 6 that the situation was resolved—but on May 7, the platform was hacked again by the criminal group ShinyHunters, who defaced the login page with a ransomware threat demanding payment by May 12. The breach impacted roughly 8,809 institutions and 275 million users globally, including 41% of U.S. higher education institutions, with ShinyHunters claiming to have stolen 3.65 terabytes of data. Following public backlash and Reddit-driven attention, Instructure apologized on May 11, stating it reached an agreement with the attackers to destroy the data (with unconfirmed rumors of a $10 million ransom), and a class action lawsuit was filed on May 13 in the Southern District of California. Despite Instructure's assurances that Canvas was safe and back online, its own status page continued to report access issues for some institutions as of May 12.