Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

Canvas LMS breach: ShinyHunters claims records from thousands of schools

A late-April 2026 intrusion and outage hit the learning platform used by millions of students; the extortion crew claimed a massive haul, and schools spent the week assessing exposure.

Malik Johnson, · May 8, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
University students checking laptops during a campus outage

Canvas, the learning management system operated by Instructure and used by K-12 schools and universities worldwide, suffered a data breach and outage in late April 2026. The extortion crew ShinyHunters claimed responsibility, asserting it stole data covering millions of records across thousands of schools; reporting by Dark Reading and others noted the crew claimed a second intrusion against Instructure within an eight-month span. Instructure acknowledged an ongoing cybersecurity incident affecting Canvas; the full scope — what data was actually taken versus claimed — remained under investigation in the days after.

What happened?

Per Wikipedia's running article on the 2026 Canvas data breach and security-firm advisories, the incident began in late April 2026 with both data theft and service disruption, and some university login pages were reportedly defaced in connection with the second claimed attack. ShinyHunters — the same crew behind the January 2026 Match Group extortion claim — set a ransom deadline of May 12, 2026, according to ComplexDiscovery's tracking, moving the incident from disclosure to demand. The U.S. Department of Education issued a Technology Security Alert (GENERAL-26-27) on May 12 addressing the ongoing incident involving Canvas. As of this report, figures like the claimed record counts remain threat-actor claims, not verified findings.

What data could be involved?

For a learning management system, the concerning categories are student and staff names, email addresses, enrollment records, grades and coursework, and — most sensitive for U.S. schools — records that may fall under FERPA protections. Legal commentators immediately flagged FERPA and GDPR implications. Institutional data like rosters and organizational structures is also intelligence for follow-up phishing: an email that knows your course schedule and professor's name is dramatically more convincing.

What should students, parents, and staff do now?

  1. Change your Canvas password, and change it anywhere it was reused — credential reuse is the main way education-platform spills become email and bank takeovers.
  2. Expect targeted phishing. Emails "from your university" about the breach, fake password-reset pages, and urgency-themed lures referencing real course names are the standard follow-up. Navigate to Canvas through your institution's portal, never email links.
  3. Turn on MFA for your school and personal email accounts.
  4. Watch financial-adjacent accounts — bursar and payment-portal credentials stolen alongside Canvas logins are a direct fraud path.
  5. For families: talk to younger students about the phishing wave rather than assuming school email filters will catch it.

Institutions using Canvas should follow the Department of Education's alert, review their SSO integration logs for anomalous activity in the April-May window, and prepare for FERPA notification obligations if student records are confirmed exposed. We will continue following this incident as verified findings replace the crew's claims.

Frequently Asked Questions

When did the Canvas breach happen?
The intrusion and outage hit Instructure's Canvas LMS in late April 2026, with ShinyHunters claiming responsibility and setting a May 12 ransom deadline. The U.S. Department of Education issued a security alert on May 12, 2026.
How many records were stolen from Canvas?
The massive figures circulating are threat-actor claims, not verified findings — treat them as unconfirmed until Instructure or regulators publish investigation results. The claimed scope spans thousands of schools.
What should students do after the Canvas breach?
Change your Canvas password and any reuse of it, enable MFA on school and personal email, and expect convincing phishing that references real courses and names — reach Canvas only through your institution's portal.