Bleepingcomputer Major Data Breach at Canvas Affects 275 Million Users
Article Content
- •Instructure confirmed a data breach affecting 275 million users of Canvas LMS.
- •ShinyHunters claims to have stolen over 3.65TB of data, including sensitive user information.
- •Instructure is investigating the breach and has implemented security measures to mitigate impact.
Instructure, the company behind the Canvas learning management system, confirmed a significant data breach involving the ShinyHunters hacking group. The attackers claim to have stolen over 3.65TB of data, potentially impacting up to 275 million users, including students, teachers, and staff from nearly 9,000 institutions worldwide. The exposed information includes names, email addresses, student ID numbers, and private messages, although there is no evidence that passwords or financial data were compromised. Instructure is currently working with cybersecurity experts and law enforcement to investigate the breach and has implemented security measures, including patching vulnerabilities and increasing monitoring. The attackers have threatened to leak the data unless their demands are met, with a deadline set for May 6, 2026. The incident highlights the growing trend of cyberattacks targeting educational technology firms, which hold vast amounts of personal information.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (590)
Following this threat?
Track Scattered Spider and ADT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested…