Skip to content

Instructure Canvas breach disrupts schools worldwide

Summary

Instructure, Inc. logo

Instructure confirmed two related Canvas intrusions through Free-for-Teacher accounts, exposing user, enrollment, course and message data and prompting a platform-wide outage on May 7, 2026. Main Canvas service returned, while Free-for-Teacher was discontinued after restricted content-retrieval windows, the last officially scheduled for July 28–29. Instructure confirmed paying the ransom, while institution-specific data delivery, message review and optional user notifications continued.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Vulnerability exploitation

    Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.

  • Website defacement

    Unauthorized modification or replacement of website content.

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data exposure

    Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Cloud service disruption

    Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

DysruptionHub’s published report documented that Instructure took Canvas offline for institutions worldwide on May 7, 2026, during a cybersecurity incident that disrupted exams, coursework, grading, and access to course materials. Instructure’s official incident hub confirms two related intrusions in which an unauthorized actor used Free-for-Teacher accounts, exploited privilege-escalation paths, and accessed Canvas data.

DysruptionHub assesses with high confidence that the event was a successful data-theft and extortion intrusion with broad downstream operational consequences. Instructure identifies ShinyHunters as the actor in its customer FAQ, which now explicitly acknowledges that the company paid the ransom. The public record does not establish file encryption, so the incident is confirmed data extortion rather than confirmed encrypting ransomware.

Operational significance

Canvas is a core learning-management platform for K-12 schools, colleges, and universities. The May 7 maintenance shutdown made Canvas, Canvas Beta, and Canvas Test unavailable during final exams and end-of-term grading. Institutions delayed exams, changed assignment and grading procedures, and prepared to continue academic work without the platform.

The disruption outlasted the general Canvas outage for Free-for-Teacher users. Instructure permanently discontinued that product and offered restricted windows for educators to retrieve course content. Its final official window ran July 28–29, creating sustained downstream effects for educators and students who depended on Free-for-Teacher for courses, grades, assignments, and instructional materials. Instructure also said enhanced post-incident security controls could temporarily delay some customer-support responses.

Disclosure posture

Instructure’s disclosures evolved from security notices and status updates to a detailed incident hub. The company says a malicious support ticket exploited a cross-site-scripting vulnerability when opened by a customer-service representative, allowing the actor to obtain an authorization token and elevated access. It says the May 7 re-entry used a second unpatched XSS flaw and an OAuth flow; monitoring detected and disabled that activity in about 10 minutes, and no additional data was taken during the second intrusion.

The company says the involved data fields included usernames, email addresses, course names, enrollment information, and messages, while core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved. Instructure is delivering institution-specific data packets weekly. Unstructured message data remains under forensic review, with delivery targeted for late September, and customers may opt into Kroll-supported user notifications that can include identity monitoring.

Instructure says it paid the ransom to reduce the risk of data distribution, received assurances and digital evidence that copies were deleted, and was told customers would not be extorted further. Those statements document the company’s response and the actor’s assurances; they do not independently prove that no other copy exists. The ransom amount and full agreement terms remain undisclosed.

Confidence and uncertainty

Confidence is high that unauthorized access, data exfiltration, page defacement, material service disruption, and a ransom payment occurred because Instructure confirmed the attack path, affected data fields, remediation, payment, and outage. Confidence is high that ShinyHunters was responsible because Instructure identifies the group and describes both recent Canvas incidents as its activity.

No public evidence establishes file encryption. The ransomware-confidence field includes related data extortion, so the confirmed payment supports a confirmed value there without implying an encrypting ransomware payload. The complete population of affected institutions and individuals, exact record counts, and jurisdiction-specific notification scope remain unresolved.

Current status

Main Canvas service returned and Instructure says the known attack paths were remediated. Free-for-Teacher remained unavailable except for restricted retrieval windows, with the final official window ending July 29. Because that incident-related access limitation was documented within six days of August 4, DysruptionHub assesses the operational incident as active under its status lifecycle. The continuing forensic review and notification process are downstream breach-response work and do not independently extend the operational-impact clock.

Analytic gaps

The reviewed sources do not establish the complete initial-access sequence before the support ticket was opened, all exploited vulnerabilities, total dwell time, exact exfiltration volume, ransom amount, full agreement terms, or independent proof that every copied data set was deleted. They also do not provide a definitive count of affected schools, users, messages, courses, enrollment records, or legal notifications, or fully reconcile the first and second intrusion timelines.

Threat actor and claim

Listed as: Instructure / CanvasSource: otherPublished: Discovered:

Claim details

Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.

Organizations involved

Impacted location

Sources

Canvas outage disrupts schools nationwide after breach notices

Instructure took Canvas offline for institutions worldwide during a cybersecurity incident, disrupting exams, coursework, grading, and access to course materials. Schools reported extortion messages appearing on Canvas pages and a ShinyHunters deadline threatening release of school data.

Security Incident Update & FAQs

Instructure confirmed related April 29 and May 7 intrusions through Free-for-Teacher accounts. It said a malicious support ticket exploited XSS to obtain an authorization token and elevated access; a second XSS path enabled page changes before monitoring stopped the activity in about 10 minutes. The company said Canvas returned to service, Free-for-Teacher was discontinued, and institution-specific data delivery and message review continued.

For Customers — Security Incident Update & FAQs

Instructure’s customer FAQ identifies ShinyHunters, explicitly acknowledges that the company paid the ransom, and says it received assurances and digital evidence that copied data was deleted. It describes the support-ticket XSS and token-based access path, says ransom content appeared on roughly 300 institutional pages, and outlines ongoing institution-specific data delivery, message review and optional Kroll notifications.

For Faculty — Security Incident Update & FAQs

Instructure said the involved data fields included usernames, email addresses, course names, enrollment information, and messages. It said core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved.

Free-for-Teacher Platform Restoration

Instructure apologized for weeks of Free-for-Teacher disruption and offered a limited access window for educators to download course content. It described additional safeguards, system segregation, removed token-generation capabilities, and restricted functionality.

See something that needs correction?

Signed-in members can report an error, update, or missing source.