Instructure's Canvas hit by data theft breach
Incident
Summary
Hide ▲
Show ▼
The Canvas incident at Instructure exposed confidential course and user data after unauthorized activity and a later access event, affecting about 160 UK higher education institutions and roughly 9,000 institutions worldwide. Instructure detected the activity on April 29, 2026, and the same threat actor gained additional access on May 7, 2026 through a second Canvas vulnerability. Canvas was reported fully online by May 9, but the stolen data creates a continuing risk of phishing, smishing, and vishing.
Cases
Related Happenings
Silent Ransom Group US law firm IT impersonation campaign
Campaign
H score36
First: 29.05.2026 16:00
Last: 29.05.2026 16:00
Sources 1
About this happening:
**Silent Ransom Group (SRG)**, also tracked as **UNC3753**, **Chatty Spider**, and **Luna Moth**, is running a **financially motivated data theft extortion campaign** against **do...
Silent Ransom Group US law firm IT impersonation campaign
CampaignAbout this happening: **Silent Ransom Group (SRG)**, also tracked as **UNC3753**, **Chatty Spider**, and **Luna Moth**, is running a **financially motivated data theft extortion campaign** against **do...
7-Eleven hit by network compromise
Incident
H score53
First: 19.05.2026 17:16
Last: 19.05.2026 17:16
Sources 1
About this happening:
**7-Eleven** is a **victim-focused breach incident** in which an **unauthorized third party** accessed systems used to store **franchisee documents** on **April 8, 2026**, trigger...
7-Eleven hit by network compromise
IncidentAbout this happening: **7-Eleven** is a **victim-focused breach incident** in which an **unauthorized third party** accessed systems used to store **franchisee documents** on **April 8, 2026**, trigger...
Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
Vulnerability
H score89
First: 11.05.2026 18:26
Last: 11.05.2026 18:26
Sources 1
About this happening:
**Canvas Free-for-Teacher** was affected by **multiple XSS vulnerabilities** that let attackers obtain **authenticated admin sessions** and carry out **privileged actions**. The f...
Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
VulnerabilityAbout this happening: **Canvas Free-for-Teacher** was affected by **multiple XSS vulnerabilities** that let attackers obtain **authenticated admin sessions** and carry out **privileged actions**. The f...
ShinyHunters school-by-school extortion campaign targeting Canvas institutions
Campaign
H score80
First: 11.05.2026 13:05
Last: 11.05.2026 13:05
Sources 1
About this happening:
ShinyHunters intensified a **school-by-school extortion campaign** against **Canvas-related institutions**, increasing pressure on schools and universities as the group threatened...
ShinyHunters school-by-school extortion campaign targeting Canvas institutions
CampaignAbout this happening: ShinyHunters intensified a **school-by-school extortion campaign** against **Canvas-related institutions**, increasing pressure on schools and universities as the group threatened...
Instructure user personal information breach
Data Leak
H score81
First: 04.05.2026 01:16
Last: 04.05.2026 01:16
Sources 1
How related:
The CMC said that approximately 160 UK higher education institutions were affected and threat actors exfiltrated confidential course and user data.
About this happening:
Instructure confirmed a **data breach** that exposed **users' personal information**, putting students, teachers, and staff at risk across affected institutions. The exposed mater...
Instructure user personal information breach
Data LeakHow related: The CMC said that approximately 160 UK higher education institutions were affected and threat actors exfiltrated confidential course and user data.
About this happening: Instructure confirmed a **data breach** that exposed **users' personal information**, putting students, teachers, and staff at risk across affected institutions. The exposed mater...
Timeline
-
26.06.2026 11:00 1 articles · 4h ago
Instructure detects unauthorized activity in Canvas
Initial DisclosureInstructure detected unauthorized activity in Canvas, marking the start of the incident response for the learning management system used by education customers.
Show sources
- CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach — www.infosecurity-magazine.com — 26.06.2026 11:00
-
26.06.2026 11:00 1 articles · 4h ago
Threat actor gains additional access and defaces Canvas login pages
Exploitation ObservedOn May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability and changed the pages shown to students and teachers, with a defacement message appearing on approximately 330 institutional Canvas login pages.
Show sources
- CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach — www.infosecurity-magazine.com — 26.06.2026 11:00
-
26.06.2026 11:00 1 articles · 4h ago
Canvas returns fully online and available for use
Victim Impact UpdateOn May 9, 2026, Instructure confirmed Canvas was fully online and available for use after the incident.
Show sources
- CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach — www.infosecurity-magazine.com — 26.06.2026 11:00
-
26.06.2026 11:00 2 articles · 4h ago
Cyber Monitoring Centre shares Canvas incident analysis and guidance
Technical Analysis UpdateThe UK’s Cyber Monitoring Centre shared its analysis of the Canvas cyber incident affecting Instructure’s learning management system, said about 160 UK higher education institutions and roughly 9,000 educational institutions worldwide were affected, and recommended clearer incident communication and maintained customer contacts for software providers.
Show sources
- CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach — www.infosecurity-magazine.com — 26.06.2026 11:00
- CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach — www.infosecurity-magazine.com — 26.06.2026 11:00