[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f20m8yg5g2cyja":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":13,"affectedCountUnit":25,"hasEnglishDescription":4,"contentLocale":26,"availableLocales":27,"translations":29,"severity":32,"dataClasses":33,"description":41,"seoTitle":42,"seoDescription":43,"logoUrl":44,"isVerified":4,"isSensitive":4,"isSpamList":45,"isMalware":45,"company":46},"6a46d51bbe81ad318fce5f47","CanvasLMSInstructure2026","Canvas LMS (Instructure) 2026 Data Breach","canvas-lms-instructure-2026","instructure.com","2026-04-29T00:00:00.000Z","2026-07-02T21:16:10.984Z",null,"2026-07-13T06:05:54.816Z","2026-07-19T00:10:20.893Z","Verified breach record","https:\u002F\u002Fwww.instructure.com\u002Fincident_update",[17,19,20,21,22],"https:\u002F\u002Ffsapartners.ed.gov\u002Fknowledge-center\u002Flibrary\u002Felectronic-announcements\u002F2026-05-12\u002Ftechnology-security-alert-ongoing-cybersecurity-incident-involving-canvas-learning-management-system-updated-may-29-2026","https:\u002F\u002Fapnews.com\u002Farticle\u002Fcanvas-outage-college-students-exams-grades-3d55b9399ae87d49276f354e1c34c180","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fbusinessinsights\u002Ftechnical-advisory-shinyhunters-breach-instructure-canvas-lms","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fcanvas-data-breach-2026",275000000,"known","unknown","en",[26,28],"tr",{"en":30,"tr":31},{"slug":9},{"slug":9},"Critical",[34,35,36,37,38,39,40],"Names","Usernames","Email addresses","Student IDs","Course names","Enrollment information","Private messages","\u003Cp>The Canvas LMS (Instructure) 2026 data breach is a critical security incident affecting student, teacher, and staff accounts through the learning management system used by educational institutions. Unauthorized access was first detected on April 29, 2026, and it was reported that on May 7, 2026, the same threat actor briefly gained additional access through a second vulnerability. The incident is not just an account security issue for a single institution, as it affected many schools and universities; it increases the risk of targeted phishing and identity impersonation across the education ecosystem through email, usernames, course associations, and private message content.Although the information made public indicates that the scope is associated with approximately 275 million users, detailed data analysis on the institution's side is ongoing on an institution basis. Therefore, users with a Canvas account should treat the incident as a real data breach risk, but they should not generate unnecessary panic based on unverified claims of passwords or financial information.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified risk areas are first and last name information, usernames, email addresses, student ID numbers, course names, enrollment and course membership information, and private messages between users. When evaluated together, these types of data can help attackers understand which student is associated with which institution, course, or faculty member. Email addresses and usernames provide a direct target list for account matching and phishing attempts. Course names and enrollment information can make messages appear more convincing; for example, fake messages sent under the pretext of exams, grades, assignment submissions, scholarships, remote education access, or course materials can more easily gain the user's trust.\u003C\u002Fp>\n\u003Cp>Private messages create a separate layer of risk. Message contents can provide context about users' academic status, communication habits, teacher-student interactions, or internal institutional processes. Student ID numbers should also be carefully protected, as in some institutions they can be used as additional identifiers in support requests, portal verifications, or administrative processes. On the other hand, verified information does not include passwords, birth dates, government IDs, or financial data. This boundary does not mitigate the risk; however, it clarifies which security measures should be prioritized. The main risk for Canvas users is targeted phishing linked to educational identities, account takeover attempts on institutional accounts, and social engineering attempts based on message contents.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In the Canvas LMS incident, the verified timeline starts with the unauthorized access detected on April 29, 2026, and expands with the second access attempt seen on May 7, 2026. There is no verified evidence that additional data was extracted during the second access, but it has been noted that there was an attempt to modify pages visible on the platform. In the initial incident, the affected data included username, email address, course name, enrollment information, and message data. Independent news and security assessments reported that name, student ID number, and message fields are also part of the at-risk data group. The approximate user count of 275 million is cited in wide-ranging reports; the institution's final user-based notification proceeds with separate data packages for each educational institution.\u003C\u002Fp>\n\u003Cp>Boundaries should be kept open. Verified findings do not show that passwords, birth dates, government-issued ID numbers, or financial information have been exposed. It has also been indicated that course content, assignment submissions, and basic learning data are outside the general scope. This distinction does not prevent users from immediately changing their password; especially those who use weak passwords on other services with the same email address should still strengthen their account. However, when assessing the Canvas breach, the main priority is fake notifications coming through the educational account, misleading messages sent on behalf of the institution, support line deception attempts using student ID information, and personalized phishing scenarios.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group includes students, faculty members, school staff, and institutional administrators who actively use their Canvas accounts. Users who access the institutional portal, student information system, email inbox, and third-party educational tools with the same email address in particular should be cautious. Course registration information and private messages provide attackers the opportunity to generate personalized text. An attacker who knows that a student is enrolled in a specific course may attempt to collect credentials using content that appears as fake assignment links, exam schedules, grade appeal forms, or course material sharing. For faculty members and administrative staff, the risk can expand through student lists, course management, grading systems, and internal message traffic.\u003C\u002Fp>\n\u003Cp>Graduates, former students, and long-unused Canvas accounts should not be overlooked. Old email addresses may still receive active forwarding in the institution's systems, or the same username may be used on other services. When the student ID number is requested for verification purposes in some support processes, it creates an additional risk. In K-12 institutions, parents and families can also be indirect targets; messages that appear to be sent on behalf of the student may contain phishing attempts under the pretext of payment, document submission, or account verification. Therefore, the risk is not limited to technical account security; it also encompasses social engineering scenarios targeting educational relationships, family communication, and institutional trust.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>People who use a Canvas account should first check their institution's official security announcements and notifications from Canvas administrators. Instead of clicking on suspicious links from emails, it is safer to access the institution's portal by typing the domain into the browser themselves or through a trusted bookmark. Multi-factor authentication should be enabled on Canvas, the student information system, and the institution email account. Even if a password leak has not been confirmed, if the same password has been reused on other services, a unique and strong password should be used on all related accounts. The recovery email, phone, and session history used for the institution account should also be reviewed.\u003C\u002Fp>\n\u003Cp>Users should be especially cautious about messages regarding courses, exams, grades, payments, scholarships, support requests, and account verification. The presence of the actual course name, faculty member's name, or student ID number in a message alone is not proof of reliability. Institution administrators should review Canvas integrations, third-party app permissions, administrator accounts, login logs, and bulk message traffic. Short, clear warnings in line with the institution's branding should be sent to students and staff; however, links requesting a password, one-time code, or private information from the user should not be used in any announcement. Suspicious messages should be reported to the institution's security team, and if the same content has been sent to multiple users, it should be blocked centrally.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>For educational institutions, this incident demonstrates how critical identity and message data tied to a single learning platform are. In the long term, role-based access, privileged account auditing, third-party integration monitoring, log review, and incident response drills should be strengthened. The principle of least privilege should be applied in systems carrying student data, application keys should be rotated at regular intervals, and unused integrations should be disabled. Institutions should request from external service providers a post-incident data field dictionary, an institution-based impact list, and a notification timeline. This way, it becomes clearer which user is affected by which data field.\u003C\u002Fp>\n\u003Cp>Long-term protection on the user side relies on unique passwords, multi-factor authentication, and the habit of regularly reviewing account notifications. Students and teachers should be aware that private messages they share on educational platforms are considered institutional data and could be used as context in future targeted attacks. Institutions can organize phishing simulations and awareness training, especially during the end-of-term, exam, and registration periods. In addition, the lifecycle of old accounts, alumni accounts, and temporary teaching accounts should be clarified. When unused accounts are closed, the risk arising from old usernames and message relationships decreases.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The Canvas LMS (Instructure) 2026 check on LeakData helps you determine whether your email address is associated with this data breach. If the result is positive, first check your institution's official security announcement and make sure multi-factor authentication is enabled for your account. If your Canvas account, institutional email, and student information system share the same password history, set a unique password for each. Review suspicious messages in your inbox regarding courses, grades, exams, scholarships, or account verification; before clicking any links, check the domain, sender, and whether the message aligns with your institution's usual communication style.\u003C\u002Fp>\n\u003Cp>Even if your email address does not appear in this breach, if you are a student, teacher, or staff at an institution that uses Canvas, the risk is not completely eliminated. Institution-specific notifications may arrive on different dates, and some data fields may vary by institution. Therefore, regularly check the session history, connected apps, and notification settings in your Canvas account. Follow official guidelines from your institution's security team, report suspicious messages, and request additional verification for requests containing student ID numbers or course information. Protecting your educational account not only safeguards your own account but also protects other users who share the same class, course, or institutional network.\u003C\u002Fp>","Canvas LMS (Instructure) 2026 Data Breach (275 Million Reported Records)","Canvas LMS (Instructure) 2026 Data Breach. 275 Million reported records are reported. Reported data: Names, Usernames, Email addresses. Review the scope…","\u002Fuploads\u002Flogo\u002Fcanvas-lms-2026.svg",false,{"name":47,"sector":48,"country":49,"website":10,"websiteArchiveUrl":50,"websiteStatus":50,"websiteCheckedAt":13},"Instructure","Education technology \u002F Learning management system","United States",""]