The 2026 Canvas data breach exposed approximately 275 million records — students, faculty, and staff at more than 8,800 institutions — after ShinyHunters exploited Instructure's free-for-teachers signup program in late April 2026. Stolen fields include names, institutional email addresses, student ID numbers, and years of private Canvas messages. If you have ever used Canvas, treat your inbox and phone as compromised, rotate your school password, enable multi-factor authentication, and remove your data from people-search sites so the leaked email cannot be turned into a complete identity profile.
What Happened
Canvas, made by Instructure Holdings, is the largest learning management system in U.S. higher education — used by roughly 40% of U.S. schools and thousands more K-12 districts and corporate training programs worldwide. On April 29, 2026, Instructure detected unauthorized access to its systems. Attackers had entered around April 25 by exploiting Canvas's free-for-teachers account program, which let anyone claim an educator account without institutional verification.
On May 3, 2026, the cybercriminal group ShinyHunters posted a ransom note claiming to have exfiltrated 275 million individuals' data and billions of private messages. On May 7, ShinyHunters defaced Canvas login pages with the ransom demand, locking students and instructors out of grading, assignments, and finals-week exams. On May 11, Instructure reportedly paid a ransom (unconfirmed reports put it at roughly $10 million) one day before ShinyHunters' May 12 leak deadline, and the hackers returned the stolen dataset.
A Paid Ransom Is Not a Guarantee
Even when a ransomware group returns or promises to delete stolen data, there is no way to verify that copies were not retained, resold, or already shared with other actors. Assume the Canvas dataset is now in circulation on criminal markets regardless of Instructure's payment.
What Data Was Stolen
According to Instructure's disclosures, the breach exposed:
- Full name
- Institutional email address
- Student identification number
- Private Canvas messages (potentially years of course discussions and DMs)
- Course enrollment and grading metadata
Instructure reported no indication that the following were exposed:
- Passwords
- Date of birth
- Government identifiers (SSN, driver's license)
- Financial account information
The message content is what makes this breach unusually damaging. Canvas messages routinely contain sensitive academic conversations — grade disputes, disability accommodations, mental health disclosures, plagiarism investigations, and off-the-record faculty communications — that were never intended to be public.
Who Is Affected
You are likely in the affected group if any of the following are true:
- You are a current or former student at a college, university, or K-12 school that used Canvas
- You are faculty, staff, or an administrator at a Canvas institution
- You have ever logged into Canvas — even briefly, as an alumnus or a visiting instructor
- You are a parent whose email was on file with a K-12 Canvas district
With 8,800+ institutions and 275 million records affected — including Duke, most of the University of California system, and thousands of community colleges and K-12 districts — most Americans who have been in school in the last decade are at least partially exposed.
Step 1: Rotate Your Canvas and School Passwords
Even though passwords were not exposed, rotate the password on your Canvas account and any linked institutional single-sign-on (SSO) system. If you reused the same password anywhere else — personal email, banking, social media — change it there too. Use a password manager to generate a unique password per service going forward.
Step 2: Enable Multi-Factor Authentication
Turn on MFA on your school account, personal email, banking, and any service linked to your institutional email address. Prefer authenticator apps (Authy, Google Authenticator) or a hardware key over SMS. SIM-swap attacks are trivial once your phone number is on a breach list.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 3: Watch for Targeted Phishing and Sextortion
The private-message piece of this breach opens two dangerous playbooks:
- Targeted phishing: attackers can quote real Canvas conversations to impersonate professors, TAs, or classmates and trick you into clicking a malicious link or wiring money
- Extortion: attackers can threaten to publish embarrassing message content unless you pay a cryptocurrency ransom
Do Not Pay a Sextortion or Extortion Demand
Paying does not delete the data. Report the demand to the FBI's IC3 at ic3.gov and to your school's IT security team. If threats reference specific Canvas messages, ask your institution whether it received a formal notification from Instructure.
Step 4: Check for Related Breach Exposure
Enter every email address you have used — school, personal, and any old alumni addresses — into haveibeenpwned.com. If the Canvas breach appears in your results, screenshot it. Also look for the Salesloft Drift, TransUnion, and Aura breaches, all attributed to the same ShinyHunters crew — data from those breaches is being cross-referenced with Canvas data to build complete identity profiles.
Step 5: Freeze Your Credit at All Three Bureaus
Even though Canvas did not expose SSNs, your leaked name, address, and email will be combined with data from other 2026 breaches (the first half of 2026 saw 471 million breach notices) to build a fraud-ready profile. A credit freeze is free, does not affect your credit score, and blocks new credit accounts from being opened in your name.
- Equifax: equifax.com/personal/credit-report-services
- Experian: experian.com/freeze
- TransUnion: transunion.com/credit-freeze
Also freeze at Innovis (innovis.com) and NCTUE (nctue.com), which mobile carriers and utilities often check instead of the big three.
Step 6: Remove Your Data From People-Search Sites
The Canvas breach handed attackers your name and school email. What makes those fields dangerous is what they connect to next — the home address on Spokeo, the phone number on BeenVerified, the relatives on Whitepages. Removing yourself from those public people-search databases raises the cost of turning a leaked school email into a complete attack kit.
PrivacyOn continuously removes your information from 100+ data broker sites, monitors the dark web for your exposed details, and covers up to 5 family members on a single plan starting at $8.33/month. For students still on a family plan, that means one subscription can protect the whole household.
Frequently Asked Questions
How do I know if I was affected by the Canvas data breach?
If your school uses Canvas and you have logged in at any point in the past decade, assume you are affected. More than 8,800 institutions were impacted. Check your school email on haveibeenpwned.com; the Canvas dataset has been indexed there. Your institution should also send a formal notification letter or email — but do not wait for it.
Were my Canvas passwords or SSN stolen?
No. Instructure reported that passwords, dates of birth, government identifiers, and financial information were not exposed. The stolen data was limited to names, institutional emails, student ID numbers, private Canvas messages, and course metadata. That said, rotating your Canvas password and enabling MFA is still a smart precaution.
Instructure paid the ransom — is my data safe now?
No. Even when a ransomware crew returns or claims to delete stolen data, there is no way to verify that copies were not retained, sold to other actors, or already shared. Treat the Canvas dataset as if it is in permanent circulation on criminal markets.
Can I sue Instructure or my school?
Class action law firms opened investigations shortly after the May 2026 disclosure, and multiple suits have been filed in federal court. Whether a class is certified and whether it results in a settlement will take months to years. Watch your notification letter for opt-in details or contact a consumer protection attorney if you have suffered downstream fraud.
What is ShinyHunters and are they still active?
ShinyHunters is one of the most prolific extortion crews of 2025-2026, responsible for the Salesloft Drift wave (700+ Salesforce customers), the TransUnion breach (4.4M records), the March 2026 Aura breach (900K records), and now the Canvas breach (275M records). They combine social engineering — usually vishing — with data theft and pay-or-leak extortion. They are still active as of August 2026.
How do I stop the extortion emails referencing my Canvas messages?
Do not reply, do not pay, and do not click any links in the extortion email. Report the message to your school's IT security team and to the FBI's IC3 portal at ic3.gov. Change your email password and enable MFA on the account. If the extortion continues, consult a lawyer familiar with cyber-extortion cases.
Protect Yourself Long-Term With PrivacyOn
The Canvas breach is a reminder that even seemingly-benign data — a school email, a student ID — becomes dangerous when combined with public data broker records. The best long-term defense is layered: unique passwords per service, hardware-key MFA on your most sensitive accounts, a permanent credit freeze at all five bureaus, and continuous removal of your data from the broker sites that turn a leaked email into a complete identity profile. PrivacyOn handles the broker-removal layer for you — 100+ sites, 24/7 dark web monitoring, and up to 5 family members on a single plan from $8.33/month. Start with a free scan to see exactly what is exposed today — no credit card required.