logo

Instructure Breach Exposes Schools' Vendor Dependence

ID: 594bab44-6737-5c79-a52b-627beb0f9f37

STIX ID: report--594bab44-6737-5c79-a52b-627beb0f9f37

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Alexander Culafi

...
...

Instructure's Canvas LMS was breached and ShinyHunters claims to have exfiltrated ~3.65 TB of data affecting roughly 275 million users across about 9,000 institutions; exposed data reportedly includes names, emails, student IDs, and private messages. Instructure engaged forensics, revoked credentials, patched systems, and rotated keys while warning that stolen messages and identifiers enable phishing, extortion, and regulatory risks for schools covered by FERPA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.