Find notable cyber news and cases, enriched with sources, timelines, and signals.
Incident Data Leak Vulnerability

Canvas intrusion, data theft, and portal defacement

Updated 26.06.2026 11:00
Case score 70
Members 3 First seen 04.05.2026 01:16 Latest activity 26.06.2026 11:00

Overview

Attackers compromised **Instructure's Canvas**, stole confidential course and user data, and later reused a **Canvas** application weakness to alter institutional login pages. The activity affected about **160 UK higher education institutions** and roughly **9,000 educational institutions worldwide**, while confirmed exposed data included user personal information and messages among users. Response actions included temporary service disruption, shutdown of **Free-for-Teacher** accounts until issues were resolved, patches, key rotation, increased monitoring, and customer API re-authorization. **Canvas** was reported fully online by **May 9, 2026**, but the stolen data leaves a continuing phishing, smishing, and vishing risk, and some claimed exfiltration scale details remain unverified.
Latest development Open development history 4 earlier developments Threat actor gains additional access and defaces Canvas login pages On May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability and changed the pages shown to students and teachers, with a defacement message appearing on approximately 330 institutional Canvas login pages.
  1. Earlier development

    Instructure detects unauthorized activity in Canvas

    Instructure detected unauthorized activity in Canvas, marking the start of the incident response for the learning management system used by education customers.

  2. Earlier development

    Cyber Monitoring Centre shares Canvas incident analysis and guidance

    The UK’s Cyber Monitoring Centre shared its analysis of the Canvas cyber incident affecting Instructure’s learning management system, said about 160 UK higher education institutions and roughly 9,000 educational institutions worldwide were affected, and recommended clearer incident communication and maintained customer contacts for software providers.

  3. Earlier development

    Canvas returns fully online and available for use

    On May 9, 2026, Instructure confirmed Canvas was fully online and available for use after the incident.

  4. Earlier development

    Instructure discovers Canvas network breach

    On April 29, Instructure discovered that its network had been breached and immediately revoked the unauthorized party's access, started an investigation, and engaged outside forensic experts.

Signals

Impact signals
Exploitation
Affected impact
Geographic context
Remediation
Status
Threat context
Data exposure

Threat actor context

5 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Incident Instructure's Canvas hit by data theft breach
Updated 26.06.2026 11:00 Lead Contribution 65
Incident Disclosed

The **Canvas** incident at **Instructure** exposed confidential **course and user data** after **unauthorized activity** and a later access event, affecting about **160 UK higher education institutions** and roughly **9,000 institutions worldwide**. Instructure detected the activity on **April 29, 2026**, and the same threat actor gained additional access on **May 7, 2026** through a second Canvas vulnerability. Canvas was reported **fully online** by **May 9**, but the stolen data creates a continuing risk of **phishing, smishing, and vishing**.

Data Leak Instructure user personal information breach
Updated 04.05.2026 01:16 Scoring Support Contribution 1
Data Type Email Addresses Data Status Partially Leaked Patch Patch Available

Instructure confirmed a **data breach** that exposed **users' personal information**, putting students, teachers, and staff at risk across affected institutions. The exposed material includes **names**, **email addresses**, **student ID numbers**, and **messages among users**, while the company said it found no evidence that **passwords** or **financial information** were involved. A group calling itself **ShinyHunters** claimed responsibility and said the data was stolen through a **patched vulnerability**, but that claim remains unverified. Instructure said it deployed **patches**, increased monitoring, and rotated application keys as part of its response.

Vulnerability Canvas Free- -Teacher actively exploited XSS vulnerabilities cross-site scripting flaw
Updated 11.05.2026 18:26 Scoring Support
Exploitation Active Exploitation

**Canvas Free-for-Teacher** was affected by **multiple XSS vulnerabilities** that let attackers obtain **authenticated admin sessions** and carry out **privileged actions**. The flaws were abused to **deface login portals** and post an **extortion message**, turning a web-app weakness into a visible service and trust failure. The issue mattered because the affected environment is used by educators, and the same flaw was reused after the initial breach.