Instructure Breach Becomes Largest Education-Sector Incident on Record

The breach of Canvas, used by 41% of North American higher education institutions, exposed the risks centralized education platforms pose during critical periods like final exams.

Illustration: Instructure Breach Becomes Largest Education-Sector Incident on Record
AI-generated illustration · Sylvaris

Attackers exploited teacher signup feature

Education technology company Instructure was breached twice in roughly two weeks by the extortion group ShinyHunters, in what became the largest education-sector breach on record. The group gained initial access in late April 2026 by exploiting the Free-For-Teacher program, a feature that let educators create Canvas accounts without institutional verification.

Instructure disclosed an incident on May 1 and said it had contained the issue by May 6. However, on May 7, ShinyHunters defaced Canvas login portals at roughly 330 institutions, including Harvard, Princeton, and the University of Pennsylvania, knocking the platform offline during final exam periods.

Ransom paid, data destruction claimed

On May 11, one day before the group's deadline, Instructure paid a ransom and said it received documentation confirming data destruction. The incident affected Canvas, a learning management system used by 41% of higher education institutions in North America.

Security analysts noted that paying the ransom does not protect the data retroactively. An estimated 275 million students and staff had their information copied by the criminal group, with the inclusion of private messages making the breach more serious than a simple credential leak.

Platform concentration risk

The sequence—containment announced on May 6, defacement on May 7—illustrated that an organization's belief that an incident is over does not mean it actually is. The broader pattern affects institutions that rely on centralized education technology platforms, where a single vendor breach can ripple across many campuses at once.

The incident was part of a wider ShinyHunters Salesforce campaign that also affected Carnival, CarGurus, Panera Bread, and 7-Eleven. Higher education remains a frequent target because institutions hold student data, financial records, research information, and identity credentials in vendor-managed systems.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.