// CanvasCRITICAL
In late April 2026, ShinyHunters breached Instructure's Canvas Learning Management System through stored cross-site scripting vulnerabilities in the Free-For-Teacher program tier. The attackers exfiltrated 3.65 terabytes of data affecting 8,809 institutions worldwide, defaced login pages at hundreds of schools, and disrupted student access during finals week. Instructure paid a ransom and discontinued the vulnerable freemium tier; a recompromise attempt occurred within 24 hours after the initial disclosure, revealing that the underlying trust boundary flaw persisted.
- The Canvas breach exposed higher Ed’s third-party identity blind(opens in a new tab)
- The Canvas breach exposed higher Ed’s third-party identity blind(opens in a new tab)
- When The Classroom Goes Dark: Lessons From The Canvas Breach For(opens in a new tab)
// Get alerts for Canvas