Canvas/Instructure Cyberattack — Key Developments
Originally reported viaInstructure Security Incident Notice — May 2026 · EdSurge · EDUCAUSE Security AdvisoryInstructure, the company behind Canvas LMS — used by more than 6,000 educational institutions worldwide — confirmed on 14 May 2026 that it had identified unauthorised access to systems containing customer data. The incident affects Canvas SaaS customers and involves potential exposure of student records, course data, and institutional configuration files.
What happened: confirmed timeline
Instructure's incident notice states that initial unauthorised access occurred on approximately 28 April 2026, with the intrusion detected on 12 May 2026 — a 14-day dwell time. The company states that attackers accessed systems through a compromised third-party integration partner. Exposed data may include student names, email addresses, course enrolment data, and for some institutions, grade records.
Institutional impact and required actions
Educational institutions using Canvas SaaS should treat this as a potential FERPA (US) or GDPR/UK-GDPR (EU/UK) notifiable incident pending Instructure's formal scope determination. Legal counsel should be engaged to assess notification obligations. IT teams should review Canvas API integrations and third-party LTI tools connected to their Canvas instance, revoking any that are not actively in use.
- Contact your Instructure account team to determine if your institution is within the confirmed breach scope.
- Audit all Canvas API integrations and LTI tool connections — revoke any not actively in use.
- Engage legal counsel to assess FERPA or GDPR notification obligations given the potential student record exposure.
- Reset Canvas admin credentials and audit admin account access logs for the period 28 April – 12 May 2026.
- Notify affected students and staff consistent with your institution's breach notification policy once Instructure confirms scope.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.