Canvas Developer Apologizes for Data Breach as Class-Action Lawsuits Mount
Instructure, the parent company of the educational platform Canvas, has issued an apology following a significant security breach that disrupted final exams at numerous universities. The attack, attributed to the hacking group ShinyHunters, exploited a vulnerability in the Free-for-Teacher support ticket system, potentially exposing data on tens of millions of students across nearly 9,000 schools. Exposed information includes usernames, email addresses, course details, and private messages. In response, Instructure temporarily suspended the Free-for-Teacher service and launched a dedicated incident update page. Despite assurances that the platform is now secure, the company faces at least 18 class-action lawsuits in the United States. Plaintiffs allege severe privacy violations, citing the exposure of sensitive educational records containing confidential communications regarding mental health, disabilities, and other personal matters. ShinyHunters initially claimed to have stolen data on 275 million individuals to extort a ransom. CEO Steve Daly acknowledged communication failures during the crisis and promised further forensic reports. This incident highlights ongoing cybersecurity risks in the education technology sector and the legal repercussions of failing to protect student data.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection