Instructure Breach Exposes Canvas Data
Coverage from Berkshire Eagle, BleepingComputer, and others

Instructure’s Canvas learning management platform was compromised in incidents reported on April 29 and May 7, exposing or potentially exposing usernames, email addresses, student identifiers, course and enrollment information, and messages across schools and universities.
The incidents disrupted Canvas access and some integrations, including PowerSchool connections, while Instructure and affected institutions investigated the scope. ShinyHunters claimed responsibility and reported a much larger number of affected records than has been independently verified, prompting congressional and cybersecurity scrutiny.
The main update is added official scrutiny: the US House Homeland Security Committee and CISA reviewed Instructure’s response and coordination. The rest of the story is largely reaffirmed, with the same compromise timeline, exposed data types, and unverified ShinyHunters claims.
The story now has more concrete incident timing and a clearer technical picture of what was exposed and disrupted, while Instructure also added a stronger rebuttal to the largest theft claims. The alleged scope remains large, but independent verification is still lacking.
