Instructure, the EdTech company behind the Canvas learning management system, confirmed a data breach in early May 2026. The incident, which appears to stem from a vendor compromise, led to unauthorized access to user data. Notifications to affected customers, such as Rutgers University, South Puget Sound Community College, and Mid-Del Schools, began around May 6, 2026.
Affected data types include names, email addresses, student ID numbers, and the content of private messages within Canvas. Instructure has stated that there is no evidence of passwords, birth dates, government IDs (such as SSNs), or financial information being compromised. While Instructure confirmed unauthorized access, the exact number of individuals affected has not been independently verified; however, claims from the threat actor ShinyHunters suggest approximately 231 million to 275 million individuals globally may be impacted.
Details about this breach may continue to emerge as investigations proceed, and notices to individuals may be delayed as educational institutions process the impact.