logo

Canvas Parent Instructure Confirms Data Breach After ShinyHunters Claims Attack

ID: fcf49f5e-c027-51a0-b080-92a21a3fb7ff

STIX ID: report--fcf49f5e-c027-51a0-b080-92a21a3fb7ff

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: AnuPriya

...
...

Instructure disclosed a cyberattack on Canvas services that began April 30, 2026, resulting in the exposure of user names, email addresses, student identification numbers, and messages exchanged on the platform; there is no current evidence of exposed passwords, dates of birth, government-issued IDs, or financial information. The company engaged external forensic experts, contained the incident by May 2, rotated and reissued application keys (forcing user reauthorization), revoked privileged credentials, deployed patches, and increased monitoring while some developer and data services experienced temporary outages; attribution remains unconfirmed though ShinyHunters has claimed activity consistent with the timing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.