Hackers breach Canvas learning platform serving millions, steal student data


Listen to this article

Instructure, the company behind Canvas, one of the world’s most used learning management systems, has been dealing with a cybersecurity incident. The developer is currently investigating the impact of the incident.

Key takeaways:

“Instructure recently experienced a cybersecurity incident perpetrated by a criminal threat actor. We are actively investigating this incident with the help of outside forensics experts,” Steve Proud, Chief Information Security Officer (CISO) at Instructure, said in a press release.

ADVERTISEMENT

“We are working quickly to understand the extent of the incident and actively taking steps to minimize its impact. Maintaining your trust is our highest priority, and we are committed to transparency throughout this process.”

To reduce the impact of the incident, Instructure has revoked privileged credentials and access tokens associated with affected systems. Additionally, patches have been deployed to enhance system security.

jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google

Furthermore, monitoring across all platforms has been increased. And lastly, out of caution, certain keys have been reissued, even though there was no evidence they were misused. This requires end users to re-authorize access to those tools.

According to Instructure’s initial findings, attackers may have viewed or exfiltrated certain user-identifying information, including full names, email addresses, student ID numbers, and messages.

The learning management systems developer says there’s no evidence that passwords, dates of birth, government identifiers, or financial information were exposed.

“If that changes, we will notify any impacted institutions,” Instructure promises.

Has your password leaked?

Enter your password to check if it has leaked. Having a leaked password creates the risk of identity theft, financial damages, and worse!
35,607,543,468
Exposed Passwords
Ad
Protect your personal information from cybercriminals and get 50% off the top-rated password manager
link_title link_title
ADVERTISEMENT

On Saturday, Proud claimed that the incident had been contained.

“Thank you for your patience as we work to resolve this matter. We sincerely regret any inconvenience or concern this may cause. We will continue to keep you apprised as our investigation progresses,” he concluded.

Hackers are increasingly targeting developers of educational software because they hold vast amounts of personal information of students and teachers.

In January 2025, PowerSchool disclosed that it was being extorted by a threat actor who claimed to have stolen personally identifiable information of millions of students. A 19-year-old college student from Massachusetts was sentenced to four years in prison for his role in the ransomware attack.

In March 2026, Infinite Campus confirmed that a threat actor targeted the company’s Salesforce instance, which consisted of names and contact information for school staff members.

FAQ by nexos.ai, reviewed by Cybernews staff.


Unlock more exclusive Cybernews content on YouTube.

ADVERTISEMENT