Incident
Data Leak
Vulnerability
Canvas intrusion, data theft, and portal defacement
Updated 26.06.2026 11:00
Case score 70
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 70
- Main story score
- 65
- Related evidence lift
- +5 / 20
- Contributing updates
- 1
- Context updates
- 0
Top contributors
- Incident Primary intrusion and service-impact event with confirmed data theft, institutional reach, and recovery timeline. main
- Data Leak Confirms exposed data categories and documents response steps such as patches, key rotation, and monitoring. contributes
- Vulnerability Explains the **Canvas** web-application weakness and follow-on access path used for portal defacement and privileged actions. main
Case score 70
Members 3
Latest activity 26.06.2026 11:00
Active exploitation
Patch available
Members 3
First seen 04.05.2026 01:16
Last seen 26.06.2026 11:00
Updated 26.06.2026 11:00
Overview
Attackers compromised **Instructure's Canvas**, stole confidential course and user data, and later reused a **Canvas** application weakness to alter institutional login pages. The activity affected about **160 UK higher education institutions** and roughly **9,000 educational institutions worldwide**, while confirmed exposed data included user personal information and messages among users.
Response actions included temporary service disruption, shutdown of **Free-for-Teacher** accounts until issues were resolved, patches, key rotation, increased monitoring, and customer API re-authorization. **Canvas** was reported fully online by **May 9, 2026**, but the stolen data leaves a continuing phishing, smishing, and vishing risk, and some claimed exfiltration scale details remain unverified.
Attackers compromised **Instructure's Canvas** and stole confidential course and user data, affecting about **160 UK higher education institutions** and roughly **9,000 educational institutions worldwide**. Instructure detected unauthorized activity on **April 29, 2026**, and later tied further access on **May 7** to abuse of **Canvas** weaknesses in user-generated content handling that allowed malicious JavaScript injection, authenticated admin session access, and privileged actions. The May 7 access also altered login-page content seen by some students and teachers, with defacement appearing on approximately **330 institutional Canvas login pages**.
Available evidence connects the intrusion, the application weakness, and the data-theft fallout into one sequence: an initial breach was followed by repeat access through a **Canvas** weakness, portal defacement, and extortion messaging. Instructure confirmed exposure of names, email addresses, student ID numbers, and messages among users, while saying it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. A group calling itself **ShinyHunters** claimed responsibility and claimed theft of about **275 million** to **280 million** records and more than **3TB** of data, but those scale figures and the exact actor role are not independently established in the available material.
Response measures included taking **Canvas** offline temporarily, shutting down **Free-for-Teacher** accounts until issues were resolved, deploying patches, rotating application keys, increasing monitoring, and requiring customer re-authorization for new API keys. **Canvas** was reported fully online by **May 9, 2026**, and investigators said there was no evidence of lateral movement into other institutional systems. The remaining risk is secondary abuse of the stolen data for phishing, smishing, and vishing against students, educators, and staff, while the precise root cause chain and the full volume of exfiltrated data remain unclear.
Signals
10 derivedImpact signals
Exploitation
Exploitation
Active exploitation
Affected impact
Exposed data
Affected service
Victims/regions
Sector
education
Victim region
United Kingdom
Remediation
Remediation
Patch available
Status
Incident status
Disclosed
Threat context
Threat context
Shinyhunters
Data exposure
Data
Email Addresses
Leak status
Partially Leaked
Malware context
1 familiesMember happenings
3 related
Incident
Instructure's Canvas hit by data theft breach
Incident
Disclosed
Incident
Instructure's Canvas hit by data theft breach
Incident
Disclosed
Data Leak
Instructure user personal information breach
Data Type
Email Addresses
Data Status
Partially Leaked
Patch
Patch Available
Data Leak
Instructure user personal information breach
Data Type
Email Addresses
Data Status
Partially Leaked
Patch
Patch Available
Vulnerability
Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
Exploitation
Active Exploitation
Vulnerability
Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
Exploitation
Active Exploitation