Instructure Canvas cyber incident

Unauthorized activity in Canvas detected on April 29, 2026, involving data access through a Free-for-Teacher account. Exposure associated with the first Canvas incident; the fields involved varied and included account identifiers, contact information, course and enrollment information, and messages.

Last modified

Summary

  • Environment: Canvas by Instructure
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Instructure detected unauthorized activity in Canvas on April 29, 2026, involving data access through a Free-for-Teacher account. [1]

Impact

Exposure associated with the first Canvas incident; the fields involved varied and included account identifiers, contact information, course and enrollment information, and messages. [1]

Documented data types include:

  • Message content — Messages; Instructure described the listed fields as examples, so presence may vary by record. [1]
  • Education records — Course names and enrollment information; Instructure described the listed fields as examples, so presence may vary by record. [1]
  • Usernames and account identifiers — Usernames; Instructure described the listed fields as examples, so presence may vary by record. [1]
  • Contact information — Email addresses; Instructure described the listed fields as examples, so presence may vary by record. [1]

A cited record reports 3,400 individuals (Massachusetts residents in report 2026-811; jurisdiction-scoped and not an overall incident total; as of 2026-05-19). [1][2]

The Australian privacy regulator said education providers including universities, vocational providers, and some state schools in Australia were affected by the global Instructure incident. [1][3]

On May 11, Instructure said it had reached an agreement under which the data was returned, it received digital destruction confirmation in the form of shred logs, and it was informed that customers would not be extorted. [1]

Timeline

  1. Discovery

    Date Instructure says it detected the first unauthorized activity; the source does not establish when that access began.

    [1]
  2. Documented activity ended

    Instructure said it detected and disabled the second attack approximately ten minutes after it began.

    [1]
  3. Activity began

    Calendar date of the second access event; Instructure did not state a precise timestamp.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The incident involved Canvas by Instructure. [1]

The incident involved Canvas by Instructure. [1]

Instructure said the actor used a Free-for-Teacher account and exploited a support-ticket vulnerability in that environment; the company did not publish a CVE or technical vulnerability identifier. [1]

Instructure said core learning data—course content, submissions, and credentials—was not compromised. [1]

Instructure said no additional data was accessed or exfiltrated during the second attack. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The unauthorized actor changed pages shown to some students and teachers while they were logged in, and Instructure temporarily put Canvas into maintenance mode. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]