Instructure Canvas Hack Update: Breach Linked to Teacher Accounts Disrupts Finals
The hacking collective ShinyHunters targeted Instructure's Canvas learning management system twice in recent weeks, causing significant disruptions during school finals. The initial breach on April 30 compromised data from 275 million users across nearly 9,000 schools, including usernames, email addresses, and private messages, though no passwords were stolen. A week later, the group launched a second attack by defacing school-specific login pages and threatening to release the stolen data unless a settlement was negotiated. Instructure identified the vulnerability in its Free-For-Teacher account environment and temporarily disabled this feature to conduct a security review. While the second incident did not result in further data theft, it caused widespread downtime, preventing students and educators from accessing assignments and exams. The timing proved particularly detrimental as many institutions were conducting end-of-year assessments. Public concern surged, with Google searches for Canvas-related issues spiking by approximately 1,000 percent. Several universities, including Seton Hall and Baylor University, acknowledged the disruption, with some postponing final exams to accommodate the technical failures. Instructure emphasized that securing the platform took precedence over immediate accessibility.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection