Canvas Hacked: What Happened in the 2026 Data Breach?

Quick Answer:  Yes, Canvas was hacked in 2026. Instructure says unauthorized access was first detected on April 29 and the same threat actor got into Canvas again on May 7 through another vulnerability. Information such as usernames, email addresses, course names, enrollment details and messages was involved. Instructure says Canvas is now back online and its forensic partner has found no evidence that the attacker still has access.

Introduction

If you use Canvas for school or university, you may have heard people saying “Canvas got hacked” back in May. Some users even saw strange hacker messages instead of the normal Canvas page. At first it looked like one of those screenshots that spreads around social media, but the incident was real.

Instructure, the company behind Canvas LMS, later confirmed that attackers had gained unauthorized access to the platform. The timing made things worse because many colleges were in the middle of exams and final assignments when Canvas access was disrupted.

There has also been a lot of confusion about exactly what was stolen. Some numbers came from the hackers themselves while other details were confirmed by Instructure and the U.S. Department of Education. This article explains what happened to Canvas, what information was involved and what students or teachers should know now.

What Happened in the Canvas Hack?

What Happened in the Canvas Hack?

The Canvas incident wasn’t just one moment where someone broke in and everything ended. There were two separate periods of unauthorized access.

April 29 – First Unauthorized Access

Instructure says it detected unauthorized activity inside Canvas on April 29, 2026. The company revoked the attacker’s access and brought in outside forensic experts to investigate what had happened. Data was accessed during this first incident.

The company later said the attackers had used an issue connected to its Free-for-Teacher environment. That service allowed educators to use a free version of Canvas without going through a school-wide paid account. Instructure eventually discontinued Free-for-Teacher after the incident.

May 7 – Attackers Got Back Into Canvas

Things became much more visible on May 7.

According to Instructure, the same threat actor found a second Canvas vulnerability and managed to get access again. This time some users saw pages that had been changed by the attackers. Instructure says its added monitoring caught the second attack in around ten minutes.

The company says no additional data was accessed or stolen during this second incident.

Canvas Was Temporarily Taken Offline

Instructure then put Canvas into maintenance mode while its teams checked the system and closed off the attacker’s access.

That meant students and teachers at many schools couldn’t reach assignments, course material or other Canvas features. The outage landed at a pretty bad time for colleges because many students were preparing for finals or trying to submit end-of-semester work.

May 9 – Canvas Returned Online

By May 9, Instructure said Canvas was fully back online. The company also brought in CrowdStrike to help with the forensic investigation and security review.

The investigation didn’t end there though. As late as July, Instructure was still sending institutions detailed information about which data from their own users had been taken. Message data was still going through a separate forensic review.

Who Was Behind the Canvas Cyberattack?

The cybercrime group ShinyHunters claimed responsibility for the attack. The U.S. Department of Education also identified the group in its security notice about the Canvas incident.

This is where it’s important to separate confirmed information from claims made by the attackers.

ShinyHunters claimed it had stolen around 6.65 TB of data connected with nearly 9,000 schools worldwide. Those figures were reported by Reuters, but they came from the group itself rather than from a final Instructure count.

The group also made much larger claims about how many individual people could be affected. Again, those numbers shouldn’t be treated as confirmed just because they appeared in ransom messages or leak-site posts.

Instructure later said it reached an agreement with the unauthorized actor. The company says the stolen data was returned and it received digital destruction records known as shred logs. That still doesn’t give anyone a perfect way to prove that every copy disappeared, which is one reason schools have continued reviewing their own exposure.

What Data Was Exposed in the Canvas Breach?

This is probably the part students care about most.

According to Instructure and the U.S. Department of Education, the data involved included usernames, email addresses, course names, enrollment information and messages. Messages are worth paying attention to because people sometimes put personal information into conversations even when a system isn’t designed to store that kind of data.

At the same time, Instructure says its investigation has not identified core learning data such as course submissions or credentials as part of the compromised information.

Data Reported as Involved Not Identified as Involved
Usernames Passwords
Email addresses Dates of birth
Course names Government identifiers
Enrollment information Financial information
Messages Grades
Course submissions

One thing I’d keep in mind is that the review has been happening institution by institution. Instructure started delivering school-specific data packets in July so administrators could see what information from their own organization appeared in the stolen files.

So a general breach report can’t tell you exactly what happened to your personal account.

Were Canvas Passwords or Grades Hacked?

Based on Instructure’s current findings, passwords have not been identified as part of the exposed data.

The company says the affected fields weren’t designed to store passwords, dates of birth, Social Security numbers, financial information, student grades or disciplinary records. It has also said core learning data including course content, submissions and credentials was not identified as involved.

That doesn’t mean every student should assume there is zero risk from the breach. Names, emails, course details and messages can still be useful to scammers because they make fake emails look much more believable.

But there’s an important difference between that and saying Canvas passwords were dumped online. Instructure has not reported that.

Why Did Some Canvas Users See a Hacker Message?

The strange page some students saw wasn’t necessarily a sign that their own laptop or phone had been hacked.

During the May 7 incident, the attackers changed customer-facing pages inside Canvas. Instructure says this included changes to page styling and in some cases authentication settings, which is why some people ended up seeing unusual Canvas pages when trying to log in.

That lines up with screenshots posted by students at different schools showing a ShinyHunters message instead of the normal experience.

The message itself made threats about releasing school data and tried to direct schools toward the attackers. Those claims were part of the extortion attempt. Seeing the page meant Canvas had been affected, not that the attacker had suddenly taken control of every student’s personal device.

Is Canvas Safe to Use Now?

At the moment, Canvas is back online and Instructure says it is safe to use.

The company says the known vulnerabilities and privilege escalation paths used in the attack were fixed. Its external forensic partner has also found no evidence that the threat actor currently has access to the platform.

Canvas’s public status page currently shows Canvas LMS and its other main services as operational.

That doesn’t mean anyone can promise Canvas will never have another security problem. No major online service can really make that promise. What it means is that the specific unauthorized access behind this incident has been contained according to the latest public information.

The data review is still important. Instructure’s July update said institutions were receiving their own exfiltrated user and provisioning data while some message information was still undergoing forensic review.

What Should Students and Teachers Do After the Canvas Breach?

You probably don’t need to panic or stop using Canvas. A few sensible checks are more useful:

  • Read any breach or security notice sent by your school because it can tell you whether your institution was affected.
  • Be careful with emails that mention your school, course or Canvas account and then pressure you to open a link.
  • Report suspicious Canvas-related emails or messages to your school’s IT team.
  • If you’ve reused the same password on other websites, change those reused passwords even though Canvas credentials haven’t been identified in the stolen data.
  • Contact your school if it sends you a notice saying your information was involved.

The last point matters most. Instructure has been giving institutions their own data findings, so your school is in a better position to tell you about your personal exposure than a random list circulating online.

FAQs

Was Canvas Really Hacked in 2026?

Yes. Instructure confirmed unauthorized access beginning on April 29 and another incident involving the same attacker on May 7.

Who Hacked Canvas?

ShinyHunters claimed responsibility for the attack. The group is also named in the U.S. Department of Education’s security notice about the incident.

Were Canvas Passwords Leaked?

Instructure says passwords and credentials have not been identified among the data involved in the breach.

Did Hackers Steal Canvas Messages?

Yes, messages were among the data fields involved. What was inside those messages will depend on what individual users had written.

Is Canvas Still Hacked?

There is currently no evidence that the attacker still has access. Canvas is online and its public status page shows the service as operational.

Final Thoughts

The Canvas hack was real. Attackers gained access to Canvas, took user-related information and later returned through a second vulnerability that caused some users to see altered pages. The breach was disruptive and the full data review has taken months.

The good news is that passwords, grades and course submissions have not been identified among the compromised core data. Usernames, emails, enrollment information and messages were involved though, so affected students should still pay attention to notices from their own school and be a little more careful with convincing-looking phishing emails.

Scroll to Top
Scroll to Top