TL;DR: On April 30, 2026, Instructure noticed something was wrong when API key tools started breaking. By May 1, the company confirmed a cyberattack. By May 3, ShinyHunters had posted Instructure to its Tor extortion site, claiming 3.65 terabytes of data covering 275 million students, teachers, and staff at roughly 9,000 schools and universities. Instructure confirmed names, email addresses, student ID numbers, and private user messages were taken. ShinyHunters also says it breached Instructure's Salesforce instance, the same playbook they've run on Crunchyroll, Bumble, Wynn, Kemper, and a dozen others. This is Instructure's second breach in under a year. If your kid uses Canvas, parent notifications haven't started yet. They will.
What Got Stolen
Per Instructure's own May 2 update, the attackers walked off with [1][2]:
- Names
- Email addresses
- Student ID numbers
- Private messages between Canvas users (parents, teachers, students)
What Instructure says was not taken: passwords, dates of birth, government IDs, financial information.
That distinction matters less than it sounds. A name plus an email plus a student ID plus your private message history with a teacher is a phishing kit. ShinyHunters specializes in turning data like this into the next round of attacks.
The Timeline
- April 30, 2026: Instructure detects a cyberattack after API-key-dependent tools start breaking [2]
- May 1, 2026: Company confirms cybercriminals are behind the disruption, retains forensic experts [2]
- May 2, 2026: Attack contained, application keys reissued, Instructure publicly identifies which user data categories were exposed [2]
- May 3, 2026: Canvas Data 2 platform restored. Same day, ShinyHunters lists Instructure on its Tor leak site with the 3.65TB / 275M / 9,000-school claim [1][2]
Three days from "tools acting weird" to "extortion listing." That's the new normal in the Salesforce supply-chain era.
Who Is Instructure?
Instructure is the Salt Lake City company behind Canvas, the dominant learning management system in American K-12 and higher ed. Canvas is where assignments get turned in, grades get posted, parent-teacher conversations happen, and student work gets stored. If your school district moved off Blackboard or Moodle in the last decade, there's a strong chance it moved to Canvas.
The company also operates Canvas Data 2, the analytics platform that institutions use to slice up student performance data. That product was offline during the response window.
Scale of the install base ShinyHunters claims to have hit [3]:
- 275 million users: students, teachers, staff
- ~9,000 institutions in North America, Europe, Asia-Pacific
- 3.65 terabytes of stolen data
- Billions of private messages, per the threat actor's own posting
Instructure has not confirmed those numbers. It also has not denied them.
Same Salesforce Playbook, New Victim
ShinyHunters' post says the quiet part out loud: "Your Salesforce instance was also breached and a lot more other data is involved" [1].
This is the campaign that has hit Bumble, Crunchyroll, Wynn Resorts, Kemper, McGraw Hill, Carnival, ADT, and at least 400 other Salesforce customers since late 2025. The pattern:
- Vish a Salesforce admin into approving a malicious OAuth app
- Pull data through legitimate API integrations (Salesloft, Drift, custom tools)
- Wait a few weeks. Add target to Tor extortion site. Demand payment.
The FBI flagged this campaign in September 2025. Salesforce's own Aura framework was implicated. Schools weren't on anyone's list of likely victims a year ago. They are now.
Second Breach in Under a Year
This isn't Instructure's first incident in this window. The company disclosed an earlier breach in 2025, the kind of detail that should matter to procurement officers at the 9,000 schools that signed contracts on the assumption Canvas was a hardened platform [3].
Two breaches in 12 months at the LMS holding records on more than a quarter-billion students is not a coincidence. It's a pattern. Instructure stores extremely high-value data and runs a sprawling SaaS integration surface (Salesforce, third-party apps, single sign-on). Both of those things are catnip to ShinyHunters.
What Instructure Did Right
Some things to credit. The company [2]:
- Detected the intrusion within days, not months
- Revoked privileged credentials and rotated access tokens
- Forced API re-authorization across the platform
- Disclosed the data categories within four days
- Stayed in public communication during the response
Compare that to the median breach disclosure timeline of 277 days per IBM's annual report. Instructure moved fast.
What Instructure Hasn't Done
- Confirmed how many users were affected
- Confirmed how many schools were involved
- Confirmed or denied ShinyHunters' Salesforce-compromise claim
- Started parent notifications (school districts will have to do that)
- Explained how this happened so soon after the previous breach
Until the first sample data drops or an enterprising security researcher gets a peek at the leak, the 275M / 9,000 / 3.65TB numbers are ShinyHunters' word. ShinyHunters doesn't usually inflate. They've been right more often than wrong.
What Parents Should Do Now
- Watch for the breach notice. Districts using Canvas will (eventually) send notifications under state breach laws and FERPA. If you don't get one within 60 days and your kid's district uses Canvas, ask why.
- Freeze your child's credit. Free at all three bureaus. Children's identities are the gold standard for long-running fraud: kids don't check their credit reports. Do this whether or not the school sends a notice.
- Brace for phishing. "Update your Canvas account" emails are coming. Real Instructure notifications will route through your school district, not a generic
canvas-support@address. When in doubt, log into Canvas directly via your school portal. Never click an email link. - Check FERPA notification rights. The Family Educational Rights and Privacy Act gives parents the right to know what student records exist and how they're handled. The Department of Education's Student Privacy Policy Office accepts complaints if your district stays quiet.
- Older students with linked financial aid. If your high schooler or college student has linked SSN-bearing FAFSA data through any Canvas integration, monitor under FCRA. Free weekly credit reports at AnnualCreditReport.com.
- Ask your district the questions. Was your data in the affected scope? Has Instructure confirmed it to the district? What's the district's data-minimization policy with Canvas going forward? "We're waiting for guidance" is not an acceptable answer six weeks in.
What Schools Should Do Now
- Get a written, dated statement from Instructure confirming whether your institution's data was in the exfiltration scope
- Audit the Salesforce-Canvas integration if you have one, and rotate every OAuth token tied to it
- Review your data-sharing addendum with Instructure: what categories are they actually authorized to store?
- Pre-draft parent notifications now. Don't wait for legal to tell you to start typing
- Reassess whether Canvas is the right platform after a second breach in a year. The procurement conversation is overdue
The Bigger Picture
Public schools have spent the last decade outsourcing their data infrastructure to SaaS vendors that they don't really audit. Districts pick a vendor based on UX and price, sign a contract that limits the vendor's liability to whatever they paid that year, and trust that someone, somewhere, is keeping the security tight.
Then ShinyHunters phishes one Salesforce admin and 275 million records walk out the door.
This is the third major education-sector breach in three months. Infinite Campus (11M students, March 2026). Now Canvas (275M claimed, May 2026). The pattern says ed-tech is a soft target with high-value data and inadequate vendor security review. That's not the ed-tech vendors' fault alone. It's also a procurement failure at every district that didn't ask hard questions.
Class action filings against Instructure within the next 60 days are essentially guaranteed. Whether they change anything is a different question. The Crunchyroll, Bumble, and Kemper class actions from earlier in this campaign are still wending through the courts. Settlements, if they come, will land long after the data is fully sold off.
What Happens Next
Three things to watch:
- Sample data drop. ShinyHunters typically posts a teaser within 7-14 days of a leak-site listing. That'll tell us whether the 275M number is real.
- Salesforce confirmation or denial. Instructure has been silent on whether its Salesforce instance was compromised. Either way, that answer matters: it tells the other 400+ Salesforce-customer victims something about the campaign's reach.
- Regulator response. The FTC, state AGs, and the Department of Education's Student Privacy Office will all be watching. So will plaintiff's lawyers.
For now, the data is up for sale. The schools haven't been told what to tell parents. And Instructure is on its second public breach in less than 12 months.
Sources
- BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack (May 2026)
- SecurityWeek: Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats (May 2026)
- DataBreaches.net: Instructure discloses second data breach in less than a year (May 3, 2026)
- Cybernews: Canvas breach? Hackers threaten to leak messages of 275M users (May 2026)
- TechRepublic: Canvas Breach May Put 275M Users, 9,000 Schools at Risk (May 2026)
- GBHackers: Canvas Confirms Data Breach Following ShinyHunters Claim (May 2026)
Published: May 4, 2026