Canvas Data Breach 2026: The Largest Education Sector Breach Ever Disclosed

Quick Answer: The Canvas Data Breach of 2026 is the largest education-sector data breach ever recorded.

Hackers from the ShinyHunters group broke into Instructure’s Canvas LMS systems in late April and early May 2026.

Claiming to have accessed data on approximately 275 million users across 8,809 institutions worldwide. Instructure paid a ransom to have the stolen data deleted.

Canvas Breach Personal Risk Checker

Podcast – The Biggest Education Breach Ever, Explained

Key Takeaways

  • 275 million user records were reportedly accessed across 8,809 institutions globally [1]
  • Attackers gained access on April 29 and May 7, 2026, causing outages during finals season [1][3]
  • The hacker group ShinyHunters carried out the attack and demanded a ransom [5]
  • Instructure paid the ransom and reached a deal for the data to be deleted [3][5]
  • Exposed data includes names, email addresses, student IDs, and Canvas messages [2][4][6]
  • No evidence that passwords, financial data, or government IDs were taken [2][6][7]
  • Canvas is used by roughly 41% of higher-education institutions in North America [1][5]
  • Affected schools include Rutgers, University of Utah, St. Petersburg College, and thousands more [2][6][7]
  • Students should reset passwords, enable MFA, and watch for phishing emails immediately [4][9]
  • This breach dwarfs previous education-sector incidents in both scale and global reach [1]

What Exactly Happened in the Canvas Data Breach?

The Canvas Data Breach was a ransomware and extortion attack against Instructure. The company that runs Canvas LMS. Attackers broke into Canvas databases. Stole a massive amount of user data, and then threatened to release it unless Instructure paid.

Here is a simple timeline of what happened:

  • April 29, 2026 — First unauthorized access to Canvas databases confirmed [1][3]
  • May 2, 2026 — Universities like the University of Utah received notice of a “nationwide cybersecurity incident” [7]
  • May 6, 2026 — Rutgers University published an update warning students and staff [2]
  • May 7, 2026 — Second confirmed access event by attackers [1]
  • May 11, 2026 — Canvas systems restored and “fully operational” ahead of summer semester [7]
  • Mid-May 2026 — Instructure confirmed it paid a ransom and reached a deal for data deletion [3][5]

The attack hit during exam and finals periods. Causing real disruption for students and teachers across the country and around the world.

How Many Student Records Were Exposed?

The attackers claimed to have accessed data on approximately 275 million users and stolen 3.65 terabytes of information. Including private messages sent inside Canvas [1][3][5].

That number — 275 million — is staggering. For context, Canvas serves an estimated 41% of higher-education institutions in North America alone [1][5]. The breach touched 8,809 universities, education ministries, and other institutions globally [1].

“This is not just the largest education breach — it’s one of the largest data breaches of any kind in recent memory.” — cybersecurity analysts cited in public reporting [1][5]

For a broader look at how this fits into the growing trend of massive data theft, see our coverage of 33.7 million stolen data records and the OpenAI data breach.

What Kind of Data Was Leaked?

The exposed data is primarily basic platform and personal information — not the most sensitive category, but still serious. Based on statements from Instructure and multiple affected schools [2][4][6][7]:

Data that was exposed:

  • Full names
  • Email addresses
  • Student ID numbers
  • Messages sent within Canvas (student-to-instructor, student-to-student)

Data that was NOT compromised (per Instructure):

  • Passwords
  • Dates of birth
  • Social Security numbers or government IDs
  • Financial or payment information

Common mistake: Many students assume “no passwords stolen” means they are safe. That’s not quite right. Email addresses and names are enough for targeted phishing attacks, so caution is still needed.

Which Schools Were Most Impacted?

Thousands of institutions were affected. Named schools in public reporting include:

InstitutionNotification DateSource
University of UtahMay 2, 2026[7]
Rutgers UniversityMay 6, 2026[2]
St. Petersburg CollegeMay 2026[6]

Because Canvas is used by 41% of North American higher-ed institutions and thousands more worldwide, the full list of affected schools is enormous [1][5]. If your school uses Canvas, assume it was touched.

How Does This Compare to Other Education Data Breaches?

The Canvas Data Breach is the largest education-sector breach ever disclosed. By a wide margin [1]. Previous major education breaches — including incidents at Pearson and various K-12 school districts — affected millions of records. This one claims 275 million.

For comparison, the cybersecurity incident affecting 33.7 million data records made headlines as a major breach. The Canvas incident is roughly eight times that size in claimed scope.

The education sector has become a top target for hackers. Because schools hold large amounts of personal data. But often have smaller security budgets than corporations.

This is a pattern security researchers have flagged repeatedly. For more on how AI-powered hackers are changing the threat landscape, see why business security can’t stop AI hackers.

Is My Personal Information at Risk?

Yes, if you use Canvas at any institution, your basic data was likely exposed. The risk level depends on what attackers do with it next.

Your biggest risks right now:

  • Phishing emails — attackers know your name, school, and email address, so fake messages can look very convincing
  • Credential stuffing — if you reuse passwords across sites, attackers may try your Canvas email on other platforms
  • Social engineering — scammers may call or email pretending to be your school or Instructure

Lower risk (based on current evidence):

  • Identity theft using government IDs (no evidence these were taken) [2][6]
  • Financial fraud from this breach alone (no financial data reportedly stolen) [4]

How Long Did Canvas Know About the Breach Before Telling People?

Based on public timelines, the first access event was April 29, 2026. Some universities received notifications as early as May 2, 2026 — roughly three days later [1][7]. Rutgers published its update on May 6, 2026 [2].

Whether that timeline meets legal disclosure requirements depends on jurisdiction. Many U.S. states require breach notification within 30 to 72 hours of discovery. Regulatory and legal scrutiny of Instructure’s response timeline is ongoing [10].

Can I Sue Canvas for the Data Breach?

Potentially, yes. Affected users and institutions may have legal options, though outcomes vary. Law firms are already examining the incident [10].

Key factors that affect your ability to sue:

  • Whether Instructure violated applicable data protection laws (FERPA, state breach notification laws, GDPR for international users)
  • Whether you suffered documented harm (financial loss, identity theft, emotional distress)
  • Class action lawsuits may emerge, which would allow affected users to join without filing individually

Practical step: Document any harm you experience. Keep copies of breach notification letters. Monitor your email for class action notices. Consult a consumer protection attorney if you experience real financial damage [10].

Will Canvas Offer Free Credit Monitoring?

As of early June 2026, Instructure has not publicly announced a free credit monitoring program for all affected users.

Check your school’s official communications and Instructure’s website directly. As offers may be announced institution by institution [4][9].

What to do if no monitoring is offered:

  • Request a free credit report at AnnualCreditReport.com (U.S. users)
  • Place a free fraud alert with the three major credit bureaus
  • Consider a free credit freeze if you are concerned about identity theft

How Can I Check If My Data Was in the Leaked Records?

There is no single official lookup tool confirmed for this breach as of June 2026. Here is what to do instead:

  1. Check HaveIBeenPwned.com — this site tracks known data breaches and will flag your email if it appears in leaked datasets
  2. Read your notification letter carefully — your school or Instructure should specify what data was involved
  3. Contact your institution’s IT department directly for confirmation
  4. Monitor your email for unusual login attempts or password reset requests you did not initiate

What Should Students and Families Do Right Now?

This is the most important section. Here is a clear, practical checklist for students, parents, and school administrators.

✅ Immediate Action Checklist

For students:

  • Reset your Canvas password immediately, even if you were not directly notified
  • Enable multi-factor authentication (MFA) on Canvas and your school email
  • Change passwords on any other accounts where you used the same password as Canvas
  • Watch for phishing emails that mention Canvas, your school, or “data breach notifications”
  • Do not click links in unsolicited emails — go directly to your school’s official website

For families:

  • Ask your student to confirm they have reset their credentials
  • Watch for suspicious calls or texts claiming to be from the school
  • Review your student’s financial accounts if they are linked to any school systems

For school administrators:

  • Send a clear, plain-language notice to all students and staff
  • Explain exactly what data was and was not exposed
  • Provide a direct contact for questions
  • Work with IT to audit access logs and strengthen endpoint security [9][10]

How to Read Your Breach Notification Letter

Breach notification letters can be confusing. Look for these key sections:

  • What happened — the date and nature of the incident
  • What information was involved — the specific data types exposed
  • What we are doing — steps the company is taking
  • What you can do — recommended actions for you
  • Contact information — who to call with questions

If the letter does not clearly answer all five points, contact your institution’s IT or privacy office directly.

For broader context on how data breaches affect everyday people, see our data breach tag page and this analysis of digital copy of 151 million workers and AI.

Are Online Learning Platforms Safe Anymore?

Online learning platforms carry real risks. But abandoning them is not realistic for most schools. The better question is: what should platforms do differently?

What needs to change in EdTech security:

  • Stronger encryption for stored messages and user data (see our encryption tag for more)
  • Regular third-party security audits
  • Faster breach detection and response
  • Mandatory MFA for all users, not just administrators
  • Clearer data minimization — only collect what is truly needed

The Canvas incident is a signal that education technology has a serious security gap. Schools should ask their LMS vendors hard questions about security practices before renewing contracts [9][10].

FAQ

Q: What is the ShinyHunters Canvas breach?
A: ShinyHunters is a well-known hacker group that carried out the 2026 Canvas LMS breach. Claiming to steal 275 million user records from Instructure’s systems across 8,809 institutions worldwide [1][5].

Q: Did Instructure pay the ransom?
A: Yes. Instructure confirmed it paid a ransom and reached a deal with the attackers to delete the stolen data [3][5].

Q: Was my password stolen?
A: Instructure states there is no evidence that passwords were compromised. However, resetting your password is still strongly recommended as a precaution [2][6].

Q: Which universities were affected?
A: Confirmed affected schools include Rutgers University, the University of Utah, and St. Petersburg College, among thousands of others globally [2][6][7].

Q: What is FERPA and does it apply here?
A: FERPA (Family Educational Rights and Privacy Act) is a U.S. law protecting student education records. It may apply to some of the data exposed in this breach, and Instructure’s compliance obligations are under review [10].

Q: How is this different from the Pearson breach?
A: The Canvas breach is far larger in claimed scope. 275 million records versus the millions affected in previous education breaches. Making it the largest education-sector breach ever disclosed [1].

Q: Should I stop using Canvas?
A: Most students do not have a choice since Canvas is required by their institution. Focus on securing your account with a strong, unique password and MFA instead.

Q: Will my grades or academic records be affected?
A: There is no evidence that academic records were altered. The breach involved data access, not data modification [4][7].

Q: How do I know if my school was affected?
A: If your school uses Canvas, assume it was affected. Check your school’s official communications and contact your IT department for confirmation.

Q: What is the long-term risk from this breach?
A: The main long-term risks are targeted phishing attacks using your name and email. Also a potential sale of your data on dark web markets. Monitor your accounts and email carefully for the next 12 to 24 months [4][9].

Conclusion

The Canvas Data Breach of 2026 is a landmark event in cybersecurity. Not just for education, but for any sector. An estimated 275 million users across nearly 9,000 institutions had their basic personal data exposed.

Instructure paid a ransom. Systems went down during finals. And millions of students are now wondering what happens next.

The good news: passwords and financial data appear safe. The bad news: names, emails, and private messages are out there, and phishing attacks will follow.

Your next steps are clear:

  1. Reset your Canvas password today
  2. Turn on MFA everywhere you can
  3. Read your breach notification letter carefully
  4. Watch your inbox for suspicious messages
  5. Check HaveIBeenPwned.com to monitor your email address

Schools and EdTech platforms need to treat this as a turning point. Better encryption, mandatory MFA, and faster breach response are not optional extras — they are basic responsibilities to the millions of students who trust these platforms every day.

References

[1] 2026 Canvas Data Breach – https://en.wikipedia.org/wiki/2026_Canvas_data_breach
[2] Update Nationwide Security Breach Involving Canvas – https://canvas.rutgers.edu/2026/05/06/update-nationwide-security-breach-involving-canvas/
[3] edweek – https://www.edweek.org/technology/deal-reached-with-hackers-to-delete-data-stolen-fom-the-canvas-educational-platform/2026/05
[4] Canvas Data Breach – https://www.staysafeonline.org/articles/canvas-data-breach
[5] Instructure Pays Ransom Canvas Hackers – https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers
[6] Instructure Cybersecurity Incident – https://www.spcollege.edu/spc-newsroom/instructure-cybersecurity-incident
[7] Uit Responding To Canvas Security Incident – https://attheu.utah.edu/students/uit-responding-to-canvas-security-incident/
[9] Canvas Data Breach Update 2026 – https://www.1kosmos.com/resources/blog/canvas-data-breach-update-2026
[10] Canvas/Instructure Cyberattack Key Developments And Action Items For Higher Education Institutions – https://www.reedsmith.com/articles/canvasinstructure-cyberattack-key-developments-and-action-items-for-higher-education-institutions/