---
title: "Instructure Canvas cyber incident"
description: "Evidence-backed account of Instructure Canvas cyber incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/instructure-canvas-cyber-incident-2026"
markdown_url: "https://www.ally.security/incidents/instructure-canvas-cyber-incident-2026.md"
stix_url: "https://www.ally.security/incidents/instructure-canvas-cyber-incident-2026/stix.json"
---

# Instructure Canvas cyber incident

Unauthorized activity in Canvas detected on April 29, 2026, involving data access through a Free-for-Teacher account. Exposure associated with the first Canvas incident; the fields involved varied and included account identifiers, contact information, course and enrollment information, and messages.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Canvas by Instructure
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Instructure](https://www.instructure.com/) detected unauthorized activity in Canvas on April 29, 2026, involving data access through a Free-for-Teacher account. [1](#source-1)

## Impact

Exposure associated with the first Canvas incident; the fields involved varied and included account identifiers, contact information, course and enrollment information, and messages. [1](#source-1)

Documented data types include:

- Message content — Messages; Instructure described the listed fields as examples, so presence may vary by record. [1](#source-1)
- Education records — Course names and enrollment information; Instructure described the listed fields as examples, so presence may vary by record. [1](#source-1)
- Usernames and account identifiers — Usernames; Instructure described the listed fields as examples, so presence may vary by record. [1](#source-1)
- Contact information — Email addresses; Instructure described the listed fields as examples, so presence may vary by record. [1](#source-1)

A cited record reports 3,400 individuals (Massachusetts residents in report 2026-811; jurisdiction-scoped and not an overall incident total; as of 2026-05-19). [1](#source-1) [2](#source-2)

The Australian privacy regulator said education providers including universities, vocational providers, and some state schools in Australia were affected by the global Instructure incident. [1](#source-1) [3](#source-3)

On May 11, Instructure said it had reached an agreement under which the data was returned, it received digital destruction confirmation in the form of shred logs, and it was informed that customers would not be extorted. [1](#source-1)

## Timeline

### April 29, 2026 — Discovery

Date Instructure says it detected the first unauthorized activity; the source does not establish when that access began. [1](#source-1)

### May 7, 2026 — Documented activity ended

Instructure said it detected and disabled the second attack approximately ten minutes after it began. [1](#source-1)

### May 7, 2026 — Activity began

Calendar date of the second access event; Instructure did not state a precise timestamp. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The incident involved Canvas by Instructure. [1](#source-1)

The incident involved Canvas by Instructure. [1](#source-1)

Instructure said the actor used a Free-for-Teacher account and exploited a support-ticket vulnerability in that environment; the company did not publish a CVE or technical vulnerability identifier. [1](#source-1)

Instructure said core learning data—course content, submissions, and credentials—was not compromised. [1](#source-1)

Instructure said no additional data was accessed or exfiltrated during the second attack. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The unauthorized actor changed pages shown to some students and teachers while they were logged in, and Instructure temporarily put Canvas into maintenance mode. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/instructure-canvas-cyber-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Security Incident Update & FAQs

official · Instructure, Inc.

<https://www.instructure.com/incident_update>

<a id="source-2"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-3"></a>

### Statement on Instructure (Canvas) cyber incident

regulatory · Office of the Australian Information Commissioner · May 8, 2026

<https://www.oaic.gov.au/news/media-centre/statement-on-instructure-canvas-cyber-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: Instructure said the actor used a Free-for-Teacher account and exploited a support-ticket vulnerability in that environment; the company did not publish a CVE or technical vulnerability identifier.
2. **Used Product · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: Canvas by Instructure
3. **Ended At · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: 2026-05-07
4. **Resulted In · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: April 2026 Canvas data exposure
5. **Exposed Data Category · 100% confidence · current**  
   April 2026 Canvas data exposure: Message content
6. **Exposed Data Category · 100% confidence · current**  
   April 2026 Canvas data exposure: Education records
7. **Exposed Data Category · 100% confidence · current**  
   April 2026 Canvas data exposure: Usernames and account identifiers
8. **Affected Organization · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: Instructure, Inc.
9. **Exposed Data Category · 100% confidence · current**  
   April 2026 Canvas data exposure: Contact information
10. **Resulted In · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: The Australian privacy regulator said education providers including universities, vocational providers, and some state schools in Australia were affected by the global Instructure incident.
11. **Began At · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: 2026-05-07
12. **Resulted In · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: On May 11, Instructure said it had reached an agreement under which the data was returned, it received digital destruction confirmation in the form of shred logs, and it was informed that customers would not be extorted.
13. **Affected Organization · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: Instructure, Inc.
14. **Resulted In · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: The unauthorized actor changed pages shown to some students and teachers while they were logged in, and Instructure temporarily put Canvas into maintenance mode.
15. **Affected Individual Count · 100% confidence · current**  
   April 2026 Canvas data exposure: 3,400 individual
16. **Resulted In · 100% confidence · current**  
   April 2026 Canvas data exposure: Instructure said core learning data—course content, submissions, and credentials—was not compromised.
17. **Resulted In · 100% confidence · current**  
   May 2026 Instructure Canvas page-modification attack: Instructure said no additional data was accessed or exfiltrated during the second attack.
18. **Discovered At · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: 2026-04-29
19. **Used Product · 100% confidence · current**  
   April 2026 Instructure Canvas unauthorized access: Canvas by Instructure

</details>
