In 2026, the University of Pennsylvania was identified as a potential victim in a data breach impacting Instructure Inc., a third-party vendor providing the Canvas learning management system. The breach, attributed to ShinyHunters, involved claims of compromising data from nearly 9,000 educational institutions worldwide. Instructure Inc. publicly acknowledged an ongoing investigation into the incident, stating that indications suggest user identifying information may have been exposed.
The compromised data types confirmed by Instructure include names, email addresses, student ID numbers, user-to-user messages, and some phone numbers. The company has explicitly stated that there is no evidence of passwords, dates of birth, government identifiers such as SSNs, or financial information being involved. While ShinyHunters claimed to have compromised 275 million individuals, Instructure has not disclosed the total number of affected individuals. The breach affects institutions globally, including those in U.S. states like Pennsylvania.
This incident is currently under active investigation by Instructure Inc., and the scope of the breach may change as more details emerge. Official notifications to consumers have not yet been publicly released.