In May 2026, a data breach affecting customers of Instructure, an educational technology vendor known for its Canvas Learning Management System (LMS), was reported. The ShinyHunters hacking group claimed responsibility, stating that the incident affected nearly 9,000 schools and 275 million individuals. Instructure publicly acknowledged an investigation into the incident.
Confirmed data types exposed in the breach include names, email addresses, student ID numbers, and some private messages. Instructure stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. While ShinyHunters claimed 275 million affected individuals, this figure has not been confirmed by Instructure. The extent of states affected is not specified in the available information.
Details surrounding the breach, including the exact number of affected individuals and any regulatory notifications, may still emerge. Official notices to consumers may also be delayed as the investigation progresses.