Find notable cyber news and cases, enriched with sources, timelines, and signals.
Incident Data Leak Vulnerability

Canvas intrusion, data theft, and portal defacement

Updated 26.06.2026 11:00
Case score 70
Case score 70 Members 3 Latest activity 26.06.2026 11:00
Active exploitation Patch available
Members 3 First seen 04.05.2026 01:16 Last seen 26.06.2026 11:00 Updated 26.06.2026 11:00

Overview

Attackers compromised **Instructure's Canvas**, stole confidential course and user data, and later reused a **Canvas** application weakness to alter institutional login pages. The activity affected about **160 UK higher education institutions** and roughly **9,000 educational institutions worldwide**, while confirmed exposed data included user personal information and messages among users. Response actions included temporary service disruption, shutdown of **Free-for-Teacher** accounts until issues were resolved, patches, key rotation, increased monitoring, and customer API re-authorization. **Canvas** was reported fully online by **May 9, 2026**, but the stolen data leaves a continuing phishing, smishing, and vishing risk, and some claimed exfiltration scale details remain unverified.

Signals

10 derived
Impact signals
Exploitation
Exploitation Active exploitation
Affected impact
Exposed data Affected service
Victims/regions
Sector education Victim region United Kingdom
Remediation
Remediation Patch available
Status
Incident status Disclosed
Threat context
Threat context Shinyhunters
Data exposure
Data Email Addresses Leak status Partially Leaked

Malware context

1 families

Member happenings

3 related
Incident Instructure's Canvas hit by data theft breach
Updated 26.06.2026 11:00 Lead Contribution 65
Incident Disclosed

The **Canvas** incident at **Instructure** exposed confidential **course and user data** after **unauthorized activity** and a later access event, affecting about **160 UK higher education institutions** and roughly **9,000 institutions worldwide**. Instructure detected the activity on **April 29, 2026**, and the same threat actor gained additional access on **May 7, 2026** through a second Canvas vulnerability. Canvas was reported **fully online** by **May 9**, but the stolen data creates a continuing risk of **phishing, smishing, and vishing**.

Data Leak Instructure user personal information breach
Updated 04.05.2026 01:16 Scoring Support Contribution 1
Data Type Email Addresses Data Status Partially Leaked Patch Patch Available

Instructure confirmed a **data breach** that exposed **users' personal information**, putting students, teachers, and staff at risk across affected institutions. The exposed material includes **names**, **email addresses**, **student ID numbers**, and **messages among users**, while the company said it found no evidence that **passwords** or **financial information** were involved. A group calling itself **ShinyHunters** claimed responsibility and said the data was stolen through a **patched vulnerability**, but that claim remains unverified. Instructure said it deployed **patches**, increased monitoring, and rotated application keys as part of its response.

Vulnerability Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
Updated 11.05.2026 18:26 Scoring Support
Exploitation Active Exploitation

**Canvas Free-for-Teacher** was affected by **multiple XSS vulnerabilities** that let attackers obtain **authenticated admin sessions** and carry out **privileged actions**. The flaws were abused to **deface login portals** and post an **extortion message**, turning a web-app weakness into a visible service and trust failure. The issue mattered because the affected environment is used by educators, and the same flaw was reused after the initial breach.