Canvas intrusion, data theft, and portal defacement
Case score 70
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 70
- Main story score
- 65
- Related evidence lift
- +5 / 20
- Contributing updates
- 1
- Context updates
- 0
- Incident Primary intrusion and service-impact event with confirmed data theft, institutional reach, and recovery timeline. main
- Data Leak Confirms exposed data categories and documents response steps such as patches, key rotation, and monitoring. contributes
- Vulnerability Explains the Canvas web-application weakness and follow-on access path used for portal defacement and privileged actions. main
Overview
Latest development Open development history Threat actor gains additional access and defaces Canvas login pages On May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability and changed the pages shown to students and teachers, with a defacement message appearing on approximately 330 institutional Canvas login pages.
-
Instructure detects unauthorized activity in Canvas
Instructure detected unauthorized activity in Canvas, marking the start of the incident response for the learning management system used by education customers.
-
Cyber Monitoring Centre shares Canvas incident analysis and guidance
The UK’s Cyber Monitoring Centre shared its analysis of the Canvas cyber incident affecting Instructure’s learning management system, said about 160 UK higher education institutions and roughly 9,000 educational institutions worldwide were affected, and recommended clearer incident communication and maintained customer contacts for software providers.
-
Canvas returns fully online and available for use
On May 9, 2026, Instructure confirmed Canvas was fully online and available for use after the incident.
-
Instructure discovers Canvas network breach
On April 29, Instructure discovered that its network had been breached and immediately revoked the unauthorized party's access, started an investigation, and engaged outside forensic experts.