Instructure's Canvas LMS Breach Exposes 275 Million Users' Data, Highlighting Vendor Vulnerability
Instructure, the company behind the Canvas learning management system (LMS), has experienced a significant data breach, marking the largest education data breach in history. The breach, executed by the hacking group ShinyHunters, compromised 3.65 terabytes of data from 275 million users across nearly 9,000 educational institutions worldwide. This includes private messages between students and teachers. The breach was not a direct attack on schools but rather on Instructure, the vendor responsible for managing the data. This incident follows a previous breach in September 2025, also attributed to ShinyHunters, which exploited a vulnerability in Instructure's Salesforce environment. The recent breach exploited a vulnerability in Instructure's production systems, which has since been patched. The exposed data includes names, email addresses, student identification numbers, and Canvas Inbox and Discussion messages.