TL;DR: Instructure has not published a list of the schools whose Canvas data was taken. Its incident page names no institutions and says institution-specific details go to affected organizations privately, through secure ShareFile links. The long university rosters circulating online trace back to a list ShinyHunters published themselves, and appearing on that list is not evidence a school was breached. A small number of institutions have been individually confirmed or notified in independent reporting, and they are listed below with the exact status each source gave them. For every other school, the institution itself is the only authoritative source, and asking it directly is the step that produces a real answer.
The Short Answer: No Verified List Exists
ShinyHunters claimed the Canvas intrusion on May 3, 2026 [4], and the question that followed for millions of families was narrower than the headlines: was my school in it. There is still no public answer, because no party with authoritative knowledge has published one.
Instructure’s incident update page, which the page itself records as last updated on July 21, 2026, names no institutions at all. The company states that it will provide institution-specific data to affected organizations through secure ShareFile links, and it does not publicly identify which institutions were compromised [1]. That routing choice is the whole reason no list exists in public. Instructure treats the identity of each affected institution as something it hands to that institution, not to the internet.
Something did fill the gap, though, and it is worth being precise about what it is. The widely reposted roster of affected universities is a document ShinyHunters released. Campus papers that fetched it said so directly, and their own universities said so too. The rest of this guide separates the handful of individually reported confirmations from that attacker-supplied roster, then covers how to check a specific school. The wider campaign, including the Salesforce and Carnival intrusions by the same group, is tracked in the ShinyHunters 2026 breach tracker.
What Is Actually Confirmed, Institution by Institution
The table below includes only institutions that a source reported on individually: a district notifying its own families, a university system passing along a vendor notice, a campus newspaper verifying a sample of the stolen data. The status column carries the framing the source used, not a summary of it. Several rows are not confirmations of a breach, and they are here precisely because they are being quoted elsewhere as though they were.
| Institution | Status as the source frames it | What the reporting says |
|---|---|---|
| University of Pennsylvania | Confirmed in the leak, verified independently | The Daily Pennsylvanian “was able to confirm the group obtained Penn user data after a ShinyHunters member shared a sample of the stolen information, which included Canvas user accounts and internal messages between University students and faculty” [4]. The figure of 306,000 Penn users is ShinyHunters’ own claim, reported but not independently counted. |
| University of California system (all 10 campuses) | Notified by the vendor | “Instructure, the maker of the University’s learning management system Canvas, has notified the University of California of a data breach involving Instructure’s systems” [3]. |
| Wake County Public Schools, North Carolina | Notified, told parents | The district “notified parents Wednesday about the data breach” [2]. |
| Durham Public Schools, North Carolina | Notified, impact confirmed to a news outlet | Durham Public Schools, Chapel Hill-Carrboro City Schools and Cumberland County Schools “confirmed to ABC11 they were notified that the data breach impacted their students” [2]. |
| Chapel Hill-Carrboro City Schools, North Carolina | Notified, impact confirmed to a news outlet | Named in the same confirmation to ABC11 [2]. |
| Cumberland County Schools, North Carolina | Notified, impact confirmed to a news outlet | Named in the same confirmation to ABC11 [2]. |
| Duke University | Aware of the situation, impact not stated | Duke “also utilizes Canvas, and said university staff also have been made aware of the situation” [2]. That is not a statement that Duke data was taken. |
| North Carolina State University | Contacted, impact not confirmed at publication | Reported as contacted but not confirming any impact as of the article’s publication on May 8, 2026 [2]. |
| UNC-Chapel Hill | Contacted, impact not confirmed at publication | Reported in the same terms as NC State [2]. |
| Sacramento State | Platform outage seen on campus, nothing confirmed about its own data | “At Sacramento State, students logging into Canvas on Thursday were reportedly redirected to a page displaying a message from a hacking group calling itself ‘ShinyHunters’” [7]. No source reviewed here confirms Sacramento State data was in the leak. |
| Harvard University | Named on the attacker’s list, investigating, breach not confirmed | “The University was named in a document released by ShinyHunters listing allegedly affected schools” [5]. IT spokesperson Tim Bailey said Harvard was “aware that the Canvas platform is currently unavailable due to a cyber incident” and was “actively investigating”. He did not confirm the breach claim. |
| University of Chicago | Named on the attacker’s list, its IT department found no evidence | UChicago “is one of about 8,800 schools, school districts, and other institutions included on a list of ‘affected schools’ whose data ShinyHunters claimed to have breached” [6]. UChicago IT stated there was “no direct evidence at this time of unauthorized activity affecting UChicago Canvas accounts”. |
| UNC statewide, North Carolina Central University, Fayetteville State University | Canvas customers only, not reported as notified | Instructure “says all North Carolina public schools use Canvas, and some universities and colleges use it as well, including Duke, UNC, North Carolina Central and Fayetteville State” [2]. Being a customer is not the same as being notified. |
That set is small, and it clusters in North Carolina, California and Pennsylvania. The clustering reflects where local and campus reporters chased the story, not where the incident landed. A school missing from the table has not been cleared of anything. It has simply not been individually reported on.
Why the School Lists Circulating Online Are Not Reliable
The roster of universities being passed around originated with the attackers. The Chicago Maroon described the University of Chicago as one of roughly 8,800 institutions on a list of “affected schools” that ShinyHunters claimed to have breached [6]. The Harvard Crimson used the same construction: Harvard “was named in a document released by ShinyHunters listing allegedly affected schools” [5]. Both papers drew the line their own universities drew. A name on the attacker’s document is a claim by the attacker.
The two universities most often held up as proof of the breach’s reach are the two clearest examples of the problem. Harvard’s IT spokesperson confirmed only that Canvas was unavailable and that the university was investigating [5]. The University of Chicago’s IT department went further and said it had found no direct evidence of unauthorized activity affecting UChicago Canvas accounts [6]. Neither university has confirmed that its own data was taken, and stating otherwise contradicts what they have said on the record.
The headline numbers come from the same place. Inside Higher Ed reported that the group “claimed to have compromised the personal identifying information of 275 million people across 9,000 institutions”, framing it as a claim throughout [8]. A different figure has circulated in parallel: a Reed Smith client alert cites TechCrunch reporting “231 million unique email addresses from Canvas” [9]. One counts email addresses, one counts people, and Instructure’s own incident page gives no total at all [1].
Scale is also worth putting next to Instructure’s ordinary customer base. The same Reed Smith alert quotes the company describing Canvas as serving “over 41% of colleges and universities in North America, more than 8,000 institutions worldwide, and over 30 million active users” [9]. The attacker’s list of about 8,800 institutions is roughly the size of that entire customer base. Whatever else that list is, it is not a filtered set of verified victims.
From there the laundering is mechanical. The roster gets reposted by aggregator blogs, law-firm client alerts and at least one newsletter post that advertises a school list in its title, usually as a long undifferentiated column of well-known institutions with no sourcing attached to any individual name. After two or three hops the origin disappears and the list starts to read like reporting. Any list of affected schools that does not say where each name came from should be assumed to be that document.
One more distinction matters, because it caught a lot of campuses. On May 7, 2026 Canvas login pages were defaced nationwide with a ShinyHunters ransom message, an event confirmed independently at Harvard and the University of Chicago [5][6] and seen by students at Sacramento State [7]. That message appeared to Canvas users generally. Seeing it says nothing about whether a particular school’s records were exfiltrated.
What Instructure Says Was Taken
Instructure’s incident update page describes the compromised data as “usernames, email addresses, course names, enrollment information and messages”, and states that “Core learning data (course content, submissions, credentials) was not compromised” [1]. That is the company’s own characterization of the categories, and it applies across the incident rather than to any named school.
On the resolution, Instructure told Krebs on Security: “The data was returned to us. We received digital confirmation of data destruction” [10]. Krebs notes that press reporting characterizes the arrangement as a ransom payment, that Instructure has not used that word, and that no amount has been disclosed [10]. Figures circulating for the size of that payment have no confirmed source behind them. The settlement and the shred-log claim are covered in detail in the report on the Instructure settlement.
How to Check Your Own School or District
1. Ask the institution directly, in writing. Because Instructure sends institution-specific data to each affected organization through private ShareFile links rather than publishing it [1], the institution is the only party that can answer. For a school district, that is the technology or IT director and the superintendent’s office. For a university, it is campus IT, the registrar, or the privacy officer. Two questions do the work: did the institution receive a breach notification from Instructure, and was it identified as affected. Ask for the answer in writing, and ask what categories of student data the institution stores in Canvas.
2. Search your state attorney general’s breach database for Instructure, not Canvas. Filings normally carry the vendor’s corporate name rather than the product name. California publishes a browsable list of breach notifications filed with the state Department of Justice [12]. Washington publishes a public data breach notifications directory [13]. Maine, Texas, Vermont and Massachusetts also maintain breach registries or require notification to the attorney general once a resident threshold is crossed.
3. Do not read an empty search result as an all-clear. As of mid-August 2026, no Instructure or Canvas entry appears on the most recent page of the California list, which covers entries dated July 17 to August 14, 2026, or on the current page of the Washington directory. Neither database was searched back through May and June 2026, which is the window a notification clock starting from an April discovery would fall into. Separately, a May 8, 2026 client alert from the firm Schubert Jonckheer & Kolbe stated that “Instructure has not yet reported either data breach to state attorney general offices, which may have violated federal or state laws” [11]. That is one firm’s characterization on one date more than three months old, and whether filings have been made since is not settled by the registries above.
4. Know what a real notification looks like. The confirmed cases show two shapes. In the first, the vendor notifies the institution and the institution passes it to its own community, as the University of California did through its employee news channel [3] and Wake County Public Schools did through a notice to parents [2]. In the second, an independent outlet verifies a sample of the stolen data itself, as the Daily Pennsylvanian did [4]. A screenshot of the ransom page, a school name on the leaked roster, and an aggregator post are none of those things.
5. Treat a name on a list as a reason to ask, not as an answer. If a school appears on one of the circulating rosters, the useful response is step one, addressed to that school, referencing the Instructure incident by name and date. Harvard and the University of Chicago both appear on that roster, and both said something quite different from what the roster implies [5][6].
What Is Still Unknown
Which institutions were actually affected. Instructure has published no list and routes that information privately [1]. Public knowledge is limited to institutions that reported on themselves or were reported on individually, which is the table above and very little else.
The true scale. The 275 million figure and the count of roughly 9,000 institutions are the attackers’ claims as reported [8], and a materially different email-address count has circulated alongside them [9]. Instructure’s own page confirms categories of data, not totals [1].
Where the regulatory filings stand. The one dated public assertion about state attorney general notifications is from May 8, 2026 [11], and the two registries checked here show nothing under Instructure on their current pages [12][13]. Both facts are time-sensitive and worth re-checking.
For a parent or a student, the honest position is uncomfortable and short. Nobody outside the institution can say whether a particular school’s records were in the set. Absence from public reporting is not clearance, and presence on a criminal’s roster is not proof. The notification from the school or district is the document that settles it, and the request that produces that document is the thing worth sending this week.
Sources
- Instructure: Incident Update page (last updated on the page as July 21, 2026)
- ABC11: Canvas data breach, NC schools and universities on the lookout for potential effects (May 8, 2026)
- UCnet: “Nationwide security incident involving Canvas” (May 11, 2026)
- The Daily Pennsylvanian: ShinyHunters claims responsibility for breaching Instructure, including Penn user data (May 6, 2026)
- The Harvard Crimson: Canvas down after alleged data breach (updated May 8, 2026)
- The Chicago Maroon: “Canvas Down After Student Data Allegedly Breached” (May 7, 2026)
- CBS News Sacramento: Sacramento State affected by nationwide cyberattack on online learning platform (May 8, 2026)
- Inside Higher Ed: “Hackers Target Canvas, Again” (May 7, 2026)
- Reed Smith: Canvas/Instructure cyberattack, key developments and action items for higher education institutions (May 14, 2026)
- Krebs on Security: “Canvas Breach Disrupts Schools, Colleges Nationwide” (May 2026)
- Schubert Jonckheer & Kolbe: Canvas data breach client alert (May 8, 2026)
- California Attorney General: Data breach notification list
- Washington State Attorney General: Data breach notifications directory
- State of Surveillance: ShinyHunters 2026 Breach Tracker (running campaign coverage)
- State of Surveillance: Instructure Canvas Breach Hits 275 Million Students (initial disclosure coverage)
- State of Surveillance: Canvas Ransom Deadline and How School Districts Responded
- State of Surveillance: Instructure Paid, Settlement and Shred Logs
- State of Surveillance: Infinite Campus Breach Hits 11 Million Students