Skip to content

Instructure Canvas breach disrupts schools worldwide

Summary

Instructure, Inc. logo

Instructure confirmed two related Canvas intrusions through Free-for-Teacher accounts, exposing user, enrollment, course and message data and prompting a platform-wide outage on May 7, 2026. Main Canvas service returned, while Free-for-Teacher was discontinued after restricted retrieval windows ending July 29; as of August 10, customer-specific data delivery continued, message review remained pending and Kroll-supported user notifications were being organized.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Vulnerability exploitation

    Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.

  • Website defacement

    Unauthorized modification or replacement of website content.

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data exposure

    Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Cloud service disruption

    Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

DysruptionHub’s published report documented that Instructure took Canvas offline for institutions worldwide May 7, 2026, during a security incident that disrupted exams, coursework, grading and access to course materials. Instructure’s official incident hub confirms two related intrusions in which an unauthorized actor used Free-for-Teacher accounts, exploited privilege-escalation paths and accessed Canvas data.

DysruptionHub assesses with high confidence that the event was a successful data-theft and extortion intrusion with broad downstream operational consequences. Instructure identifies ShinyHunters as the actor in its customer FAQ, which explicitly acknowledges that the company paid the ransom. The public record does not establish file encryption, so the incident is confirmed data extortion rather than confirmed encrypting ransomware.

Operational significance

Canvas is a core learning-management platform for K-12 schools, colleges and universities. The May 7 maintenance shutdown made Canvas, Canvas Beta and Canvas Test unavailable during final exams and end-of-term grading. Institutions delayed exams, changed assignment and grading procedures and prepared to continue academic work without the platform.

The disruption outlasted the general Canvas outage for Free-for-Teacher users. Instructure permanently discontinued that product and offered restricted windows for educators to retrieve course content. Its final official window ran July 28-29, creating sustained downstream effects for educators and students who depended on Free-for-Teacher for courses, grades, assignments and instructional materials.

Disclosure posture

Instructure’s disclosures evolved from security notices and status updates to a detailed incident hub. The company says a malicious support ticket exploited a cross-site scripting vulnerability when opened by a customer-service representative, allowing the actor to obtain an authorization token and elevated access. It says the May 7 re-entry used a second unpatched XSS flaw and an OAuth flow; monitoring detected and disabled that activity in about 10 minutes, and no additional data was taken during the second intrusion.

The company says the involved data fields included usernames, email addresses, course names, enrollment information and messages, while core learning data such as course content, submissions, credentials, grades and disciplinary records had not been identified as involved. As of Aug. 10, Instructure said customer-specific data packets were still being delivered weekly. Unstructured DAP message data remained under forensic review, and customers could opt into Kroll-supported user notifications that may include 24 months of identity monitoring.

Instructure says it paid the ransom to reduce the risk of data distribution, received assurances and digital evidence that copies were deleted and was told customers would not be extorted further. Those statements document the company’s response and the actor’s assurances; they do not independently prove that no other copy exists. The ransom amount and full agreement terms remain undisclosed.

Current status

The incident remains active. Main Canvas service returned, Instructure says the known access paths were remediated and its status page showed Canvas services operating normally Aug. 10. Free-for-Teacher remained permanently discontinued, with the final incident-related access window ending July 29. That date remains the latest documented operational impact.

The continuing forensic review, customer data delivery and notification process are downstream breach-response work. They do not establish that Canvas service remained disrupted after July 29 or provide a later operational-impact date.

Confidence and uncertainty

Confidence is high that unauthorized access, data exfiltration, page defacement, material service disruption and a ransom payment occurred because Instructure confirmed the attack path, affected data fields, remediation, payment and outage. Confidence is high that ShinyHunters was responsible because Instructure identifies the group and describes both related Canvas incidents as its activity.

No public evidence establishes file encryption. The ransomware-confidence field includes related data extortion, so the confirmed payment supports a confirmed value without implying an encrypting ransomware payload. The complete population of affected institutions and individuals, exact record counts and jurisdiction-specific notification scope remain unresolved.

Analytic gaps

The reviewed sources do not establish the complete initial-access sequence before the support ticket was opened, all exploited vulnerabilities, total dwell time, exact exfiltration volume, ransom amount, full agreement terms or independent proof that every copied data set was deleted. They also do not provide a definitive count of affected schools, users, messages, courses, enrollment records or legal notifications, or fully reconcile the first and second intrusion timelines.

Threat actor and claim

Listed as: Instructure / CanvasSource: otherPublished: Discovered:

Claim details

Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.

Organizations involved

Impacted location

Sources

Canvas outage disrupts schools nationwide after breach notices

Instructure took Canvas offline for institutions worldwide during a cybersecurity incident, disrupting exams, coursework, grading, and access to course materials. Schools reported extortion messages appearing on Canvas pages and a ShinyHunters deadline threatening release of school data.

Free-for-Teacher Platform Restoration

Instructure apologized for weeks of Free-for-Teacher disruption and offered a limited access window for educators to download course content. It described additional safeguards, system segregation, removed token-generation capabilities, and restricted functionality.

Security Incident Update & FAQs

Instructure confirmed related April 29 and May 7 intrusions through Free-for-Teacher accounts and said known access paths were remediated. Main Canvas remained online, Free-for-Teacher was permanently discontinued, customer-specific data delivery continued and DAP message review remained pending.

For Faculty — Security Incident Update & FAQs

Instructure said the involved data fields included usernames, email addresses, course names, enrollment information, and messages. It said core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved.

For Customers — Security Incident Update & FAQs

Instructure’s customer FAQ identifies ShinyHunters, confirms payment of the ransom and describes the support-ticket XSS and token-based access path. As reviewed Aug. 10, data packets were still being sent weekly, DAP message review remained pending, and Kroll-supported notifications could include 24 months of identity monitoring.

See something that needs correction?

Signed-in members can report an error, update, or missing source.