Canvas / Instructure Security Incident
May 2026. Instructure, the Utah maker of Canvas, was hit by a two-wave security incident in late April and early May 2026. What happened, what was exposed, what Utah law requires districts to do, and what to tell families.
Latest update: June 12, 2026
Status moved to monitoring. No material new developments surfaced in the first two weeks of June across press, legal trackers, or regulator notices. The owed June 5 and June 12 Friday updates are this single note rather than manufactured news. Four open threads we are watching:
- Congressional briefing — still no public readout. The House Homeland Security Committee's May 11 request to CEO Steve Daly and the May 21 briefing deadline have produced no published outcome or follow-up.
- Litigation — no consolidation yet. The federal suits (six in Utah, one in San Diego) are still proceeding individually. No JPML consolidation or multidistrict transfer order has been reported.
- Free-For-Teacher accounts — no confirmed restoration date. Instructure's status thread is not publicly machine-readable; we could not verify a June restoration. Treat as unresolved.
- Utah AG — notification, not a confirmed probe. USHE notified the Utah Attorney General on behalf of affected institutions. No standalone Utah AG investigation has been publicly confirmed. Legal commentary still projects possible state-AG or multistate action by June 30.
Previous update: May 29, 2026
Four developments since the May 22 update:
- Instructure is distributing preliminary data findings to Canvas administrators. Per Instructure's May 20 update: “We will be providing Canvas Administrators with preliminary findings about the data fields that were exfiltrated. Instructions for how to access this information will be provided directly to Canvas account administrators.” If your district has a Canvas account administrator, that person may now be receiving district-specific information through their Instructure contact. This is the first move toward per-institution specificity on what was actually taken.
- Jordan School District issued a parent notification today confirming it was on Instructure's affected list. Jordan School District, one of Utah's largest K-12 districts, published a notification to families via ParentSquare today stating the district “was included in their breach, along with thousands of other education institutions.” (The word “breach” is Jordan SD's own language.) Per the notification, data confirmed compromised includes student usernames and student ID numbers. The notification also states Instructure “has not provided a list of the individual JSD students impacted.” Jordan SD is the first Utah K-12 district, not a higher-ed institution, to issue a public parent notification confirming inclusion on Instructure's affected-customer list.
- The Congressional briefing deadline has passed with no public readout. The May 21 closed-door briefing requested by Chairman Andrew R. Garbarino (R-NY) has passed. The U.S. House Homeland Security Committee has not released a public readout or announced follow-up actions as of this update.
- Free-For-Teacher accounts remain offline with no restoration date announced. Instructure has stated it is “working on solutions that will allow us to bring it back online without exposing the rest of the Canvas community to undue risk.” No timeline has been publicly announced.
Previous update: May 22, 2026
Nine days of developments as of that update. Material changes:
- USHE published an Instructure Data Incident Public Notice. The Utah System of Higher Education has notified the Utah Cyber Center and the Utah Office of the Attorney General on behalf of affected USHE institutions and encouraged students to remain vigilant for 12 to 24 months. First formal Utah AG involvement on record.
- Lawsuit count has grown from one to at least seven federal suits. Six of the new filings are in the U.S. District Court for the District of Utah. KKR, Instructure's private-equity owner, was named alongside Instructure in at least one filing. First-filed Utah case is Jabon Peterman v. Instructure.
- Congressional briefing was requested by May 21. Chairman Andrew R. Garbarino (R-NY) sent a May 11 letter to Instructure CEO Steve Daly asking the company to participate in a closed-door briefing no later than May 21. No public readout has been released.
- TrendAI Research identified 8,809 institutions in the leaked data, spanning 50 countries. The figure replaces the earlier “approximately 9,000” framing as the most defensible institutional count. Included: all eight Ivy League universities, 1,616 K-12 school districts (Clark County NV, Houston ISD, Miami-Dade FL among them), Oxford, Cambridge, NUS, Melbourne.
- Confirmed-affected school district list expanded outside Utah. Charlotte-Mecklenburg Schools, Cabarrus County, Catawba County, Kannapolis City, and Union County in North Carolina confirmed impact; reporting also names districts in California, Florida, Georgia, Oklahoma, Oregon, Nevada, Tennessee, Texas, Virginia, and Wisconsin.
- Attack-vector framing shifted. USHE's public notice describes the vector as “application programming interfaces (APIs) within Instructure's data systems used to communicate data between applications.”
- State AG / multistate action timing. Legal commentary projects either a Utah AG enforcement action or a multistate investigation announcement by June 30, with the Utah AG as the home-state regulator on point.
- Federal Student Aid (FSA) Technology Security Alert. The U.S. Department of Education's Federal Student Aid office issued a Technology Security Alert on May 12 covering the ongoing incident. First federal-agency acknowledgment beyond the Congressional inquiry.
TL;DR
Instructure, the Utah-based maker of Canvas, was hit by a two-wave security incident in late April and early May 2026. A criminal extortion group named ShinyHunters defaced Canvas login pages at roughly 330 institutions on May 7 and claimed to have stolen 3.65 TB of data covering about 275 million users across 8,809 organizations. Instructure took Canvas offline May 7, restored paid service May 8, and announced a ransom agreement with ShinyHunters on May 11 that included shred-log confirmation of data destruction. By May 29, at least seven federal class actions had been filed (six in Utah), USHE had notified the Utah Cyber Center and Utah AG, the U.S. House Homeland Security Committee's May 21 briefing deadline passed with no public readout, Instructure began distributing preliminary data findings to Canvas administrators, Jordan School District issued Utah's first K-12 parent notification confirming inclusion on the affected list, and Free-For-Teacher accounts remain offline with no restoration date announced.
Confirmed exposed data: names, email addresses, student ID numbers, and Canvas messages. Confirmed not exposed: passwords, dates of birth, government IDs, financial information. The 275M user count is still attacker-claimed; the 8,809 figure now has third-party research backing.
What happened
Instructure detected unauthorized access to its systems on April 29, 2026. USHE's public notice clarifies the unauthorized actor compromised APIs used by Instructure to move data between applications, then used those APIs to extract user data. “Free-For-Teacher” account types were identified by Instructure as one entry vector and Instructure temporarily shut down those account types. Those accounts remain offline as of this update, with no restoration date announced.
On May 7, a criminal extortion group known as ShinyHunters defaced Canvas login pages at roughly 330 institutions across the United States, the United Kingdom, Australia, New Zealand, Sweden, and the Netherlands. The login pages displayed an extortion message giving Instructure a deadline of May 12 to pay or the data would be released. Instructure took Canvas offline proactively to contain the activity. Paid Canvas was restored on May 8.
On May 11, Instructure CEO Steve Daly announced the company had reached an agreement with ShinyHunters. The agreement included return of the taken data, digital confirmation of data destruction (shred logs), and a statement that “no Instructure customers will be extorted as a result of this incident, publicly or otherwise.” Instructure also acknowledged “there is never complete certainty when dealing with cyber criminals.” No dollar figure was disclosed; unconfirmed reporting suggests roughly US$10 million. Follow instructure.com/incident_update for the latest from the vendor directly.
Same facts for every audience. The action items are what change.
The facts (same for everyone)
- A criminal group called ShinyHunters accessed Canvas user data in late April and again on May 7, 2026.
- Exposed: names, email addresses, student ID numbers, and messages sent inside Canvas.
- Not exposed: passwords, dates of birth, government IDs (SSN, driver's license), financial information.
- Instructure took Canvas offline May 7, restored paid service May 8, and announced a ransom agreement on May 11.
- At least seven federal class actions have been filed (six in Utah, one in San Diego). The U.S. House Homeland Security Committee's May 21 briefing deadline has passed with no public readout. USHE has notified the Utah Cyber Center and Utah AG.
- Jordan School District (one of Utah's largest K-12 districts) issued a parent notification on May 29 confirming Instructure placed them on the affected list.
- Instructure is distributing preliminary per-institution data findings to Canvas administrators as of May 20.
- Core learning data (course content, assignments, gradebook credentials) was not compromised.
- This page is now in monitoring mode: it updates when there is a material change rather than on a fixed weekly cadence.
For parents — what to do
- Watch for phishing emails or texts that reference Canvas, your child's school, or Instructure. The data taken (names + email + student ID) is exactly what makes a believable phishing message.
- Do not click links in unexpected messages about Canvas. Go directly to your district's site if you need to verify something.
- Talk to your child about not sharing screenshots of Canvas messages with anyone they don't know in person.
- If your district sends a notification letter, keep it. It documents your standing if identity-protection services or class-action claims become available.
- You do not need to change Canvas passwords yet (passwords were not exposed), but it is a low-cost habit.
For teachers — what to do
- Same phishing alertness as parents, plus: assume any private Canvas message you sent could surface. Adjust future communication accordingly.
- If you used a Free-For-Teacher account, those accounts remain offline as of this update. Instructure has not announced a restoration date.
- Do not change your grading workflow because of this incident. Core learning data was not compromised.
- If your district has a designated cybersecurity SPOC under HB 42, route any concerns or observed phishing to that person.
For district administrators — what to do
- Confirm whether your district was on Instructure's notified-customer list. If yes, notify USBE within 24 hours per HB 42 (Katy Challis, Jeremy Zabriskie, or Nichole Clark; a brief email is sufficient as the initial step). Coordinate with UETN on the UETN Statewide Agreement.
- Check your DPA with Instructure for identity-protection-service funding triggers before committing district budget.
- Designate your HB 42 cybersecurity SPOC if you have not already.
- Document this incident in your § 53E-9-302 student data inventory.
- Prepare your parent-notification letter under FERPA and Utah Code §13-44-202. The vendor's notification to you does not replace your obligation to families.
For board members — what to do
- Ask the superintendent: have we notified USBE, designated our HB 42 SPOC, and started the parent-notification process?
- Ask: what does our DPA with Instructure say about identity-protection-service funding?
- Ask: which other vendors hold similar categories of student PII, and what is our exposure if one of them is hit next?
- Do not authorize emergency budget for identity protection until the DPA-funding question is answered. The vendor may be obligated.
For community members — what to do
- The story here is governance working as designed: signed agreements, regulatory notification paths, and active litigation. The system is responding.
- If you are a community partner or volunteer who has had Canvas access (mentoring programs, after-school, etc.), you are in the same exposure category as teachers.
- If you are a journalist or researcher writing about this, cite the 8,809-institutions figure (TrendAI Research) rather than the attacker-claimed 275M users.
What Instructure has confirmed was exposed
- Names
- Email addresses
- Student ID numbers
- Messages exchanged within Canvas
In a May 8 letter to customers, CEO Steve Daly described the involved data fields as including “usernames, email addresses, course names, enrollment information and messages.” Instructure noted it was “still validating all findings.” As of May 20, Instructure is distributing preliminary per-institution findings to Canvas administrators. The final confirmed scope per district may differ from the general list above.
Per Instructure's public statements, the following were not exposed: passwords, dates of birth, government identifiers, financial information. Core learning data (course content, submissions, gradebook credentials) was not compromised.
Disputed and attacker-claimed scope
| Figure | Source | Attestation |
|---|---|---|
| 3.65 TB of data | ShinyHunters claim, referenced in Instructure's May 11 statement | Vendor-referenced. Quote with attribution. |
| 8,809 affected institutions | TrendAI Research, May 2026 | Third-party research. Most defensible institutional count. |
| ~275 million users | ShinyHunters claim | Attacker-claimed only. Do not cite as fact. |
| ~330 institutions login-page defaced (May 7) | The Hacker News, observed defacements | Reported with specificity. |
| ~US$10 million ransom paid | Unconfirmed reporting | Unconfirmed. Do not cite as fact. |
Current USBE guidance: At this time, no specific action is required from students or families. Out of caution, students, families, and educators should remain alert to unexpected emails or messages that may be phishing attempts related to this incident.
Utah district deadlines — the clocks running right now
Canvas in Utah is covered under the UETN Statewide Agreement. HB 42 §53G-8-903(2)(b) requires districts to coordinate with UETN when the incident involves UETN-provided services. Contact UETN in parallel with USBE.
Instructure owns the incident. Your district owns the notification.
Under FERPA (20 U.S.C. §1232g), the LEA, not the vendor, carries the parent notification obligation when education records are improperly disclosed. Canvas holds education records. Instructure failing to secure its systems does not transfer that obligation to Instructure. Your district has to communicate with families on its own timeline, on its own terms.
Notify families before they read it elsewhere. In a small or mid-size community, word travels before the news cycle does. If a parent finds out from a news alert or a neighbor before you've sent a letter, the rest of your communication is damage control.
What to tell families
Keep it plain. Families need three things, and only three:
- What happened — Instructure, the company that runs Canvas, had its systems accessed without authorization. Name the vendor, name the tool.
- What data was involved — Based on Instructure's confirmed statements: names, email addresses, student ID numbers, and Canvas messages. Be specific. Do not make parents guess whether their child's information was in scope.
- What you are doing about it — You signed a legal agreement with Instructure requiring them to protect student data. They failed to uphold that agreement. You are now holding them accountable and have notified the state. Tell parents that.
If your district had a signed Data Privacy Agreement or operated under a statewide contract with Instructure, say so explicitly. “We had a legal contract with this vendor requiring them to protect your child's data, and we are enforcing it” is a factually accurate, materially stronger statement than silence or a generic apology.
If sensitive data was involved
Instructure's current confirmation does not include SSNs or medical information. If that changes, or if your district's own Canvas data included fields beyond what Instructure has publicly confirmed, offer identity protection services to affected individuals. The established standard from comparable incidents (PowerSchool 2025, Illuminate 2023) is two years of credit monitoring through Experian for students and two years through TransUnion for adults who have reached the age of majority.
Your district's DPA or statewide agreement with Instructure may require Instructure to fund this. Check the contract before committing district budget.
Immediate steps for district leaders
- Lock in your discovery date. Every deadline above runs from this date. Document it now.
- Notify USBE within 24 hours (HB 42 §53G-8-903(2)(a)). Call or email the USBE Student Privacy office before you finish the formal report.
- Coordinate with UETN if Canvas was deployed through the statewide agreement. HB 42 requires it, and UETN may have additional details on exposure scope.
- Designate a Single Point of Contact (SPOC) for all external communications — parent questions, media inquiries, Cyber Center correspondence. HB 42 §53G-8-903(4)(b) requires a named primary cybersecurity contact. All responses go through one person to keep the message consistent.
- Confirm what Canvas data your district actually held. Pull your data inventory for Canvas. The gap between what Instructure confirmed as exposed and what your district authorized Canvas to collect is the number your notification letter needs to be built around. Utah Code §53E-9-302 requires LEAs to maintain a current vendor data inventory. If yours is not current, this week is the forcing function.
- Draft your parent notification letter before the news cycle frames it for you. A direct, factual letter from the superintendent or technology director, sent before a parent asks, is the difference between leading the narrative and chasing it.
- File all required state reports on the timelines above. Keep documentation of every action and its date.
The pattern
This is not an isolated incident. PowerSchool was hit in December 2024, exposing the records of tens of millions of students and teachers. Illuminate Education reached an FTC settlement over its 2021 breach of more than 10 million students' records: the order was proposed in December 2025 and given final approval on June 5, 2026, a 10-year consent order. Canvas is the third major K-12 EdTech vendor to suffer a serious security incident in 17 months.
The common thread is not any particular security failure. It is that districts without a documented vendor inventory and signed agreements face the same response problem every time: they do not know what they authorized, so they cannot tell families what was actually at risk.
Utah legislation in effect right now
HB 42 — School Cybersecurity Amendments took effect May 6, 2026. It requires LEAs to notify the State Board within 24 hours of a security incident, coordinate with UETN on UETN-service incidents, and designate a named primary cybersecurity contact who interfaces with the Cyber Center, USBE, and UETN.
SB 267 — Software in Education Amendments (enrolled Substitute #5, signed 2026-03-18) takes effect July 1, 2026. The enacted bill directs USBE to study software use in public schools and publish guidance to LEAs before July 1, 2027. It does not add new LEA reporting or disclosure obligations on the effective date. Districts continue to operate under FERPA, COPPA, and Utah Code §53E-9 (Student Privacy and Data Protection).
The USBE Student Privacy office and the Utah Student Privacy Center are the primary state resources for LEAs navigating incident reporting obligations. USBE has published a Data Breach Reporting and Notification Requirements reference document specifically for this incident. (USBE's document title uses the word “breach”; this page uses “security incident” in body prose and preserves “breach” only inside source-document titles, Utah statute names, and direct quotes.)
USBE reporting contacts for this incident
[email protected] — Katy Challis, Director of Privacy
[email protected] — Jeremy Zabriskie
[email protected] — Nichole Clark
A brief email stating your LEA was impacted satisfies the initial 24-hour USBE notification requirement while your full report is being prepared.
Sources
URLs verified 2026-05-29. Full citation list is maintained in the canonical record at wiki/abya/canvas-instructure-incident-2026-05.md.
- Inside Higher Ed — Instructure Pays Ransom to Canvas Hackers (2026-05-11)
- Wikipedia — 2026 Canvas security incident
- Instructure — Security Incident Update & FAQs
- CNN — Canvas hack: What we know (2026-05-07)
- Quartz — Instructure pays ransom to ShinyHunters (2026-05-12)
- Deseret News — Hackers target Canvas system used by many Utah school districts (2026-05-08)
- ABC4 Utah — Data breach of Utah-based company leads to nationwide issues
- University of Utah @theU — UIT responding to Canvas security incident
- KSL — Utah-based tech company Instructure hacked
- USBE Student Privacy office
- Bleeping Computer — Instructure reaches 'agreement' with ShinyHunters
- KQED — Canvas Hack: Instructure Agrees to Ransom Deal
- Idaho Education News — Canvas data breach resolved, Instructure CEO apologizes
- The Hacker News — Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
- NBC 7 San Diego — Lawsuit filed in San Diego vs. Canvas developer
- 10News — Lawsuit filed in San Diego vs. Canvas developer
- ClassAction.org — Instructure Data Breach Confirmed, Attorneys Investigating
- Schubert Jonckheer & Kolbe — Instructure's Canvas LMS Under Investigation
- Stueve Siegel Hanson — Instructure, Canvas Data Breach Lawsuit Investigation
- TechCrunch — US lawmakers demand answers from Instructure (2026-05-13)
- The Record — Instructure pays ransom after Canvas incident as Congress announces investigation
- Utah HB 42 — School Cybersecurity Amendments (effective 2026-05-06)
- Utah SB 267 — Software in Education Amendments
- Fox News — Canvas data breach exposes student emails and IDs but not passwords
- USBE — Data Breach Reporting and Notification Requirements (May 2026)
- Utah Code §13-44-202
- Utah Code §53E-9-302
- ABYA internal — docs/canvas-incident-deploy.md and docs/canvas-incident-seed.sql
- Utah System of Higher Education — Instructure Data Incident Public Notice
- ABC4 Utah — Three separate lawsuits filed against Instructure
- Bloomberg Law — KKR, Instructure Sued After Canvas EdTech Tool Data Breach
- Frankfurt Kurnit Klein & Selz — Canvas Gets Schooled (Holly Melton)
- U.S. House Committee on Homeland Security — Chairman Garbarino Seeks Information from Canvas Developer (2026-05-11)
- U.S. House Committee on Homeland Security — Letter to Steve Daly (PDF, 2026-05-11)
- Bleeping Computer — US govt seeks Instructure testimony on massive Canvas cyberattack
- WCNC Charlotte — Cybersecurity breach hits Canvas learning platform used by CMS
- K-12 Dive — Instructure confirms cybersecurity incident
- IsDown / StatusGator — canvas-instructure status reports
- Dixie Technical College — Instructure Data Security Incident Public Notice
- The Harvard Crimson — Harvard Canvas Site Goes Down (2026-05-08)
- U.S. Department of Education FSA — Technology Security Alert (2026-05-12)
- Jordan School District parent notification via ParentSquare (2026-05-29). Published by JSD Communications at 1:31 PM MT. Page requires login; screenshot on file.
- Instructure — Security Incident Update, May 20 entry: preliminary data findings being distributed to Canvas administrators
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].