Canvas Breach Hits Schools
Coverage from WRAL, WLOS, and others

A cybersecurity incident involving Instructure's Canvas learning platform exposed student and staff information used by schools and universities.
Reporting indicates the compromised data likely included names, email addresses, student ID numbers, and messages, while passwords, financial data, and government identifiers were not believed to be affected. The main concern is not system-wide disruption but downstream misuse of exposed data for phishing and other social engineering attacks across education networks.
The story has broadened beyond North Carolina districts to include UK higher-education customers and a wider education-sector impact assessment. New reporting also clarifies that the main residual risk is phishing from exposed identifiers, while forensic review continues and excludes several highly sensitive data categories.
