Instructure confirmed a security incident affecting its cloud-hosted Canvas environment after the group ShinyHunters said it had taken data tied to around 9,000 schools and institutions worldwide, claiming roughly 275 million records relating to students, teachers and staff.
Exposed data included names, email addresses, messages sent through Canvas and student identification numbers. The company said it had found no evidence that passwords, dates of birth, government IDs or financial information were involved, and traced the entry point to an issue affecting free teacher accounts.
Schools caught mid-term
Unauthorised access began around 25 April and was detected days later; the platform went dark in early May, in some cases during final exams. Named victims spanned large K-12 districts — Orange County in Florida, Arlington in Virginia, San Diego Unified — as well as universities, a reminder of how much student data now sits with a small number of edtech vendors, and how little redundancy schools have when one of them fails.
Sources
EdWeek — A cyberattack on Canvas could cause lasting aftershocks for schools · CNN — What we know about the Canvas cyberattack · US Department of Education — Technology security alert: Canvas incident


