T1#security#privacy#outage#regulation

The Canvas Breach — When a Learning Management System Became the Education Sector's Single Point of Failure

Metadata

Date
Decade
2020s
Tier
T1
Sources
10
Connections
01
Tags
#security#privacy#outage#regulation

Just after midday on Thursday 7 May 2026, students and faculty across the United States went to log into Canvas and found a ransom note where the login page should have been. It was finals week.

The incident had begun a week earlier. Instructure detected unauthorised activity in Canvas on 29 April and disclosed it publicly on Friday 1 May. What happened on 7 May was the same threat actor's second intrusion.

Sorting the Numbers Before Anything Else

The hardest part of writing about this incident is not the technology. It is that the figures in circulation differ by two orders of magnitude and, worse, count different things. So:

What Instructure confirmed. In its updates in the days after disclosure, the company said the information involved consisted of "certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users," and that it had "found no evidence that passwords, dates of birth, government identifiers, or financial information were involved." Later statements phrase the fields as usernames, email addresses, course names, enrollment information and messages — the wording the US Department of Education reproduced in its own alert. Instructure has never published a count of affected individuals or institutions.

What the attacker claimed. ShinyHunters' leak-site listing read: "Nearly 9,000 schools worldwide affected. 275 million individuals data ranging from students, teachers, and other staff containing PII." Elsewhere the same group was reported as claiming 280 million records tied to 8,809 schools, universities and education platforms, and, in another telling, more than 240 million records; sample data it supplied spanned close to 15,000 institutions. The attacker's own numbers do not agree with one another. It claimed over 3.6TB of uncompressed data.

Numbers that count something else entirely. The figure of 330 is BleepingComputer's count of Canvas login portals defaced on 7 May — not a count of breached institutions. Instructure's "more than 30 million users" and "more than 8,000 institutions" describe its customer base, not its victims. Both are routinely repeated as though they measured the breach.

Ranked by confidence: the categories of data are established, because the company stated them. The number of people is not established by anyone.

The Way In: Free-For-Teacher

The entry point was Free-For-Teacher (FFT), the no-cost Canvas tier that let an individual educator create an account without institutional verification — by definition outside any enterprise-managed identity system. In his 8 May letter, CEO Steve Daly wrote that the company had "identified a vulnerability regarding support tickets in our Free for Teacher environment that was exploited." Instructure later confirmed that the actor used an FFT account in both intrusions.

BleepingComputer reported, from its own sourcing rather than from the company, that the attacker exploited multiple cross-site scripting flaws: malicious JavaScript injected through user-generated content features, yielding authenticated admin sessions and then privileged actions. Instructure has not published that level of technical detail itself.

The US Department of Education's Federal Student Aid office treated the incident squarely as a demonstration of the risk carried by accounts without multi-factor authentication, and told institutions to remove or disable non-managed "teacher-created" or "free" accounts wherever institution-bound identity controls could be used instead.

Containment, and Then 7 May

The sequence is the part that drew the scrutiny.

  • Friday 1 May — Instructure discloses the incident on its status page.
  • Saturday 2 May — the company publishes the categories of data taken. Chief Information Security Officer Steve Proud is reported to have declared the incident contained that day.
  • Wednesday 6 May — affected organisations are notified directly. The update states: "At this stage, we believe the incident has been contained." The attacker's original payment deadline also fell on 6 May, and was pushed to 12 May.
  • Thursday 7 May — Canvas login pages are replaced with an extortion message: "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'." It gives schools until the end of 12 May to negotiate individually. The defacements were visible for roughly thirty minutes; Instructure pulled the whole platform into maintenance mode.
  • Friday 8 May — the CEO publishes an apology and Free-For-Teacher is suspended.
  • Saturday 9 May — Canvas is fully back online.
  • Monday 11 May — Instructure announces an agreement with the attacker.

On the second intrusion Instructure says the monitoring it had put in place after the first attack caught it, that it was detected and disabled about ten minutes after it began, and that no additional data was accessed or exfiltrated. The damage on 7 May was to availability and to credibility, not to the data inventory. That distinction did not help much: the company had told its customers five days earlier that the matter was contained, and the attacker chose to disprove that on every login screen it could reach.

The 11 May "Agreement"

One clarification first, because the vocabulary in the coverage is loose: nothing was encrypted. ShinyHunters runs data-theft extortion, not file-locking ransomware — the leverage is publication, not recovery. The US Department of Education's alert nonetheless calls it "a ransomware group", which is how the category has drifted in official usage.

Instructure's own wording is precise and worth reading as written. The data was returned to it. It received digital confirmation of data destruction — shred logs. It had been informed that no Instructure customers would be extorted as a result of the incident, publicly or otherwise, and that the agreement covered all impacted customers, so no institution needed to approach the actor itself.

The company did not use the word "payment." ShinyHunters removed the Instructure entry from its leak site, which is what normally follows a ransom being paid. Figures for an amount circulated in reporting without confirmation from any party. Krebs on Security described the update plainly as Instructure having paid its extortionists in exchange for a promise to destroy the data. As the FBI has said repeatedly, paying guarantees neither that stolen data will not be sold on nor that the victim will not be extorted again.

Congress and the Regulators

Also on 11 May, Andrew R. Garbarino, chairman of the US House Committee on Homeland Security, wrote to Daly demanding a briefing by 21 May. "Within the span of one week, the cybercriminal group known as ShinyHunters breached Instructure twice," the letter said, describing an actor that "struck again on May 7, defacing Canvas login pages nationwide and posting ransom demands directly on students' screens." Garbarino argued that "the recurrence of an intrusion within days of an initial breach disclosure, and Instructure's apparent failure to fully remediate the underlying vulnerabilities during that window, raise serious questions about the company's incident response capabilities."

The Department of Education issued a technology security alert on 12 May, updated on 29 May, telling institutions to enforce MFA everywhere and to review authentication and integration logs for unusual access "especially between April 25, 2026, and May 8, 2026" — a window wider than the one Instructure's own account describes. Its Student Privacy Policy Office separately asked Instructure for information on FERPA compliance.

The Free Tier as Trust Boundary

The CrowdStrike outage of 2024 showed that one vendor's update could stop the world. Canvas is the same lesson from the other side: a platform does not have to stop working to fail catastrophically. Everything kept running on 2 May, and the damage was already done.

What makes this one instructive is how ordinary the entry point was. Not a nation-state, not a novel exploit chain — a product decision to let anybody create a free account without proving who they were, in the same platform that thousands of institutions had made their system of record for coursework, grades and private messages between students and teachers. The convenience of an unverified tier turned out to be the trust boundary for everyone else on the platform.

Instructure announced on 8 June that Free-For-Teacher was permanently discontinued, with a replacement product for former FFT users planned for the autumn. Institution-specific breakdowns of the exfiltrated data only began reaching customers in mid-July, delivered through a secure file-transfer service — a process the company itself paused for a week when that third-party platform came under a security threat of its own. Forensic review of the message data was still incomplete in August. For the schools involved, this incident did not end on 11 May.

Sources

  1. Tertiary2026 Canvas security incident — Wikipedia

    Accessed 2026-08-12

Last updated:

Share