// Alert

Instructure threat report

ShinyHunters breached Instructure's Canvas LMS in late April 2026 through stored cross-site scripting vulnerabilities in the Free-For-Teacher program, exposing approximately 3.65 terabytes of data including names, email addresses, and student IDs from 8,809 institutions. The threat actor later recompromised Canvas through a different attack vector, defacing login pages at roughly 330 institutions. Instructure paid ransom on May 11, 2026, and discontinued Free-For-Teacher, but the underlying trust-boundary design flaw highlighted systemic risks in vendor-extended identity systems.

// Get alerts for Instructure