Instructure Breach Becomes Largest Education-Sector Incident on Record
The breach of Canvas, used by 41% of North American higher education institutions, exposed the risks centralized education platforms pose during critical periods like final exams.
Attackers exploited teacher signup feature
Education technology company Instructure was breached twice in roughly two weeks by the extortion group ShinyHunters, in what became the largest education-sector breach on record. The group gained initial access in late April 2026 by exploiting the Free-For-Teacher program, a feature that let educators create Canvas accounts without institutional verification.
Instructure disclosed an incident on May 1 and said it had contained the issue by May 6. However, on May 7, ShinyHunters defaced Canvas login portals at roughly 330 institutions, including Harvard, Princeton, and the University of Pennsylvania, knocking the platform offline during final exam periods.
Ransom paid, data destruction claimed
On May 11, one day before the group's deadline, Instructure paid a ransom and said it received documentation confirming data destruction. The incident affected Canvas, a learning management system used by 41% of higher education institutions in North America.
Security analysts noted that paying the ransom does not protect the data retroactively. An estimated 275 million students and staff had their information copied by the criminal group, with the inclusion of private messages making the breach more serious than a simple credential leak.
Platform concentration risk
The sequence—containment announced on May 6, defacement on May 7—illustrated that an organization's belief that an incident is over does not mean it actually is. The broader pattern affects institutions that rely on centralized education technology platforms, where a single vendor breach can ripple across many campuses at once.
The incident was part of a wider ShinyHunters Salesforce campaign that also affected Carnival, CarGurus, Panera Bread, and 7-Eleven. Higher education remains a frequent target because institutions hold student data, financial records, research information, and identity credentials in vendor-managed systems.