// Alert

Instructure threat report

ShinyHunters breached Instructure's Canvas LMS in May 2026 via a stored XSS vulnerability in the support ticket system, exfiltrating approximately 275 million records across nearly 9,000 schools. The threat group obtained unauthorized access using a Free-for-Teacher account and leveraged the compromised authorization token to escalate privileges and exfiltrate 3.65 terabytes of data including names, email addresses, student IDs, and private messages. After Instructure attempted patching rather than negotiating, attackers displayed ransom messages during peak academic periods; the company reportedly settled on May 11, 2026. This marks the largest education data breach on record and Instructure's second confirmed compromise by ShinyHunters within eight months.

// Get alerts for Instructure