⚠️ Canvas Breach: 275M Students Exposed – Safety Guide
On this page
On May 7, 2026, the cybercrime group ShinyHunters defaced the login page of Canvas — the learning management system used by nearly 9,000 schools and universities — with a ransom demand that threatened to leak data on 275 million students and faculty. The breach forced Canvas parent company Instructure to take the platform offline during final exam season, leaving millions of students locked out of their coursework.
We’ve analyzed the breach data, tracked the timeline of events, and compiled the exact steps you need to take right now to protect your accounts. Here’s what happened and how to secure your family’s digital life.
What Happened in the Canvas Breach
The attack unfolded over two weeks in a pattern that security experts say reveals a coordinated, multi-stage campaign. On May 1, ShinyHunters demonstrated they had breached Instructure’s systems. By May 2, Instructure’s Chief Information Security Officer Steve Proud declared the incident “contained.”
That containment didn’t hold. On May 6, Instructure issued a formal statement confirming that stolen data included names, email addresses, student ID numbers, and internal messages. The company said it found no evidence that passwords, financial data, or government IDs were compromised. By midday May 7, students and faculty at dozens of schools woke up to find the Canvas login page replaced by an extortion message from ShinyHunters.
ShinyHunters has breached Instructure again, the defacement message read. Instead of contacting us to resolve it they ignored us and did some ‘security patches.’
Instructure responded by pulling Canvas offline entirely, replacing the portal with a “scheduled maintenance” notice — a description that security experts quickly called misleading. Dipan Mann, founder and CEO of Cloudskope, pointed out that this is at least the third time in eight months that ShinyHunters has breached Instructure. A September 2025 attack on the University of Pennsylvania was later determined to have used a Canvas-mediated access path.
The September 2025 Penn breach was the proof of concept, Mann wrote. The May 1, 2026 incident was the production run. The May 7, 2026 recompromise was ShinyHunters demonstrating publicly that the May 2 containment did not happen.
Who Was Affected
ShinyHunters claims to have stolen data from 275 million students and faculty across nearly 9,000 educational institutions using Canvas. The affected data includes:
- Names, email addresses, and student ID numbers
- Private messages between students and teachers (ShinyHunters claims billions of messages)
- Phone numbers (according to ShinyHunters)
Instructure has stated the breach did not include passwords, financial information, dates of birth, or government identifiers. But the combination of email addresses, student IDs, and personal messages is more than enough for phishing attacks, social engineering, and identity theft attempts.
If your child uses Canvas for school, or if you are a university student yourself, your data is almost certainly in this breach. The ransom deadline was set for May 12, 2026, and multiple universities have reportedly already contacted ShinyHunters to negotiate separate payments.
Why This Breach Matters for Your Passwords
Even though passwords were not stolen from Canvas directly, the breach creates a cascade of password-related risks. Here is why you should take it seriously:
Credential Stuffing Risk
ShinyHunters now has your email address and student ID. If you use the same password for Canvas that you use for other accounts — and 65% of people reuse passwords across multiple sites according to the 2024 Verizon Data Breach Investigations Report — attackers can try that combination on your email, banking, and social media accounts. This attack technique, called credential stuffing, is one of the most common breach follow-up tactics.
Phishing Attacks Targeting Students
With access to student emails, private messages, and course data, attackers can craft highly convincing phishing emails that reference your actual classes, assignments, and instructors. These spear phishing attacks have a much higher success rate than generic spam.
University Email as a Recovery Vector
Many students use their .edu email as the recovery address for personal accounts (banking, social media, shopping). If that email is now known to attackers, and the password for that email is weak or reused, your other accounts could be compromised through password reset requests.
Step-by-Step: How to Protect Your Accounts
Here is exactly what to do, in order of priority:
Step 1: Change Your Canvas Password Immediately
Even though Instructure says passwords were not stolen, change yours immediately as a precaution. Use our password generator to create a strong, unique password:
- At least 16 characters — length beats complexity for resistance against brute-force attacks
- Mix of uppercase, lowercase, numbers, and symbols
- Completely unique — never reuse this password anywhere else
NIST SP 800-63B guidelines recommend passwords of at least 8 characters for user-chosen passwords, but for machine-generated passwords, aim for 16+ characters. Canvas supports passwords up to 128 characters, so there is no reason to go short.
Step 2: Enable Multi-Factor Authentication
Multi-factor authentication (MFA) is your single best defense against credential stuffing. Even if an attacker has your password from another breach, they cannot log in without the second factor. Start with these accounts:
- Email (personal and university .edu accounts)
- Learning management systems (Canvas, Blackboard, Google Classroom)
- Banking and financial accounts
- Social media
Step 3: Run a Breach Check
Visit HaveIBeenPwned.com and check every email address you use. This will tell you which breaches your data has appeared in and whether your passwords have been exposed.
Step 4: Switch to a Password Manager
The single most effective thing you can do is stop managing passwords in your head. A password manager generates, stores, and autofills unique passwords for every site you use. You only need to remember one master password. The best options in 2026 offer end-to-end encryption, cross-platform sync, built-in breach monitoring, and automatic password generation. For students and families, Bitwarden offers a generous free tier. 1Password and Dashlane offer family plans that cover up to five members.
Step 5: Monitor for Phishing Attempts
In the weeks following this breach, expect an increase in phishing emails targeting students. Watch for emails claiming to be from Canvas Support asking you to verify your password, messages urging you to click here to secure your account, or emails referencing your specific class or instructor. When in doubt, navigate to Canvas directly by typing the URL into your browser — never click links from emails.
Step 6: Update Recovery Email for Critical Accounts
If you use your .edu email as the recovery address for personal accounts, consider switching to a personal email (Gmail, Outlook, or ProtonMail) for account recovery. This isolates your personal accounts from the education ecosystem that was just compromised.
What Instructure Is Doing Now
On May 8, Instructure published an updated incident report. The company confirmed that Canvas was back online and that the breach exploited a vulnerability related to Free-for-Teacher accounts. As a result, Instructure made the difficult decision to temporarily shut down Free-for-Teacher accounts.
Instructure stated that affected organizations were notified on May 6 and that they would directly contact all verified affected institutions. Security experts remain skeptical given ShinyHunters’ track record of re-breaching organizations that claim to have contained incidents.
The ransom deadline of May 12 means the next few days will be critical.
FAQs
Should I change my Canvas password if I use a strong one?
Yes. Even though passwords were not stolen in this breach, changing your password is a basic precaution. Use a unique, machine-generated password of at least 16 characters.
Can I still use Canvas for my classes?
Yes. Canvas is back online and functional as of May 8. Instructure has disabled Free-for-Teacher accounts as a security measure. If your school’s Canvas instance is affected, your institution will contact you directly.
What data did ShinyHunters steal from Canvas?
According to Instructure’s May 6 statement, the stolen data includes names, email addresses, student ID numbers, and internal messages. ShinyHunters claims it also includes phone numbers and billions of messages. Instructure says passwords, financial data, and government IDs were NOT compromised.
Will ShinyHunters release the stolen data?
The ransom deadline is May 12, 2026. Multiple universities have reportedly begun negotiating separate payments with ShinyHunters. The group has removed Instructure from its leak site and removed data samples — typically a sign that a payment or negotiation is underway. However, given this group’s track record, data publication is still a real risk.
How do I create a strong password for my Canvas account?
Use our free password generator to create a 16+ character password with a mix of uppercase, lowercase, numbers, and symbols. Never reuse this password on any other site. Store it in a password manager like Bitwarden or 1Password so you do not have to remember it.
What should parents do if their child uses Canvas?
Talk to your child about phishing awareness — attackers will likely send emails that look like they are from teachers or the school. Help them set up a password manager and enable two-factor authentication on their email account. Monitor for unusual activity on their accounts over the next few weeks.
Does this breach affect K-12 schools or just universities?
Both. Canvas is used by K-12 districts, universities, and even some businesses. The 9,000 affected institutions span all levels of education. Instructure is contacting affected organizations directly.
What is ShinyHunters known for?
ShinyHunters is a prolific cybercrime group specializing in data theft and extortion. They typically gain access through voice phishing and social engineering, often impersonating IT personnel. Recent victims include ADT (5.5 million customers), Medtronic, Rockstar Games, McGraw Hill, 7-Eleven, and Carnival Cruise Line.
How is password cracking research relevant here?
Kaspersky’s latest research found that 60% of MD5 password hashes can be cracked in under an hour using modern GPU hardware. This underscores why even strong-looking passwords can be vulnerable if they are stored using weak hashing algorithms. Use a password manager to generate truly random passwords that resist both brute-force and dictionary attacks.
Is it safe to use my university email for personal accounts?
After this breach, it is safer to use a personal email address for banking, social media, and shopping accounts. University email addresses are now widely known and could be targeted for phishing and credential attacks. Keep your .edu email for academic use only.
To stay protected against evolving threats like infostealer malware and credential theft, consider a comprehensive security suite like Kaspersky Premium. It includes advanced malware protection, password monitoring, and breach alerts that help you detect compromised credentials early.