Skip to content
>_ITDITDWeb Security Platform

Security Guides

Not grades, but who is in which class — and the messages: what students, teachers and schools should do after the Canvas breach

Instructure, the company behind the Canvas LMS, says an April–May 2026 intrusion exposed usernames, email addresses, course names, enrollment information and messages. Based on its official updates: what students, teachers and school IT admins should check.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 15 min read

For: students and families who use Canvas, teachers, and school IT staff (universities, K–12 and others). This article is based on the official updates from Instructure, the company that runs Canvas, and does not cover attack techniques.

What students and families should do

1

Ask your school, not Instructure, whether you are affected

Instructure delivers data per institution, to the security contacts each school registered, and it tells students and families to direct questions to their school. If you are concerned, contact your school's IT or academic office. If a school decides individual notice is required, Instructure offers to send it on the school's behalf through an outside provider, and in some places the notice may include complimentary identity monitoring (24 months). If you receive such a notice, check that the same notice appears on your school's official website or portal before you act on it.

2

Do not open links in messages claiming to be Canvas or your school

With names, email addresses and enrolled courses, it is easy to write convincing messages about "resubmitting an assignment", "checking your grade", "updating enrollment" or "an apology and compensation for the data breach". Do not sign in from links in emails or texts; open your school's usual Canvas address or app yourself. Never give a password or MFA code in response to a message (see What is phishing?).

3

Take stock of any secrets you sent in Canvas messages

Messages are among the fields involved. If you ever sent a password, a login for another service, your address or phone number, or health or family matters in a Canvas message, assume that content may be known. For passwords and logins, change them on that service now; for personal matters, be ready to ignore any contact that uses them as bait.

4

Stop reusing passwords and turn on MFA

Instructure says it has no evidence that credentials were compromised. It still encourages changing passwords, especially for users who are not on SSO and MFA. If your Canvas password is used anywhere else, separate them. If your school offers MFA, turn it on (Choosing a password manager / Choosing MFA).

What teachers should do

1

Tell students to verify anything that doesn't come through Canvas

Course names and enrollment data make it easier to write messages that impersonate a teacher to students, or impersonate students or staff to a teacher. Tell students that course communications come only through set channels, such as Announcements inside Canvas, so they can treat anything else with suspicion.

2

Tell school IT about student information you sent in messages

Teacher–student conversations are among the fields involved. If past messages included student accommodations, health conditions or family circumstances, tell your school's IT or privacy office. According to Instructure, it is the school that decides whether end users need notice, and schools may need to reassess that decision once the message review is complete. The teacher who wrote the messages is the person who knows what is in them.

3

Stop sending sensitive information through Canvas messages

From now on, handle anything that would hurt if leaked, such as passwords or personal circumstances, through a channel your school designates. LMS messaging is for course communication, not a place to keep secrets.

4

Keep your own copy of course materials

Canvas was put into maintenance mode on May 7, and end-of-semester teaching was disrupted. Instructure notes that course export tools and APIs let you keep data outside Canvas. Exporting your courses at the end of each term reduces the impact the next time the service is unavailable. Free-for-Teacher has been permanently discontinued, and the windows to download materials (May 28–29 and July 28–29) have closed.

What school IT admins should do

1

Register security contacts in Canvas and save delivered data before the link expires

Instructure delivers each affected institution's data to up to two security contacts registered in Canvas account settings. Contacts must be individuals, not shared inboxes or distribution lists, and institutions with several Canvas instances need contacts for each instance. There is no hard cutoff; the company says it sends data to new contacts every other week. The delivery link expires after 30 days, so download the files if you need to keep them. If nothing arrived, Instructure gives three possible reasons (no contact registered, only message data involved and still pending, or further review found no user records from your institution) and will confirm which applies if you ask.

2

Decide on notification, and verify senders against Instructure's official page

Instructure's view is that most jurisdictions do not require individual notice for the user and provisioning data, but if a school decides notice is required, Instructure will coordinate notifications through an outside provider only after the school opts in. Message data was reviewed separately, and on September 29 the company announced its forensic review was complete. It says institutions whose data includes messages may need to reassess notification decisions. The sender addresses for data-delivery and notification emails are listed in Instructure's customer FAQ. Check them against that official page, not against information inside the email itself.

3

Review logs for support-agent access on April 25–30 and May 7

According to Instructure, your logs may show access from Canvas customer support representative accounts between April 25 and April 30, and briefly on May 7. Patterns such as rapid access to many courses or user accounts, or access to accounts and courses your support staff would not normally touch, that do not match legitimate support tickets you submitted in those periods may indicate the attacker. Canvas Data and administrative access logs can be used for the review. An interim fact sheet from the company's forensic firm, including known indicators of compromise, is posted in the Instructure Community.

4

Require MFA for administrator accounts

Instructure recommends MFA regardless of authentication method and specifically recommends enabling Canvas MFA for all administrators. For schools using SSO, it says MFA is generally best enforced through the identity provider's policies. Canvas-authenticated accounts can use Canvas's native MFA, enabled for all users or only for administrators.

5

Review integrations (SIS, LTI, API keys)

Instructure says it has found no evidence that partner credentials, API keys or developer tokens were exfiltrated, and it is not asking institutions to broadly rebuild or rotate integrations. If SIS rostering or grade sync stopped working, however, your keys may have been rotated on Instructure's side, and you should ask for updated credentials. You can also proactively cycle API keys or reauthorize integrations. Use the moment to inventory tokens with no expiry and unused developer keys.

6

Plan for teaching continuity when Canvas is down

The outage came at the end of the semester. Instructure notes that APIs, Canvas Data, course exports and standards-based export formats let institutions run independent backups. Before next term, decide which data you back up outside the LMS, how often, and where, and how assignments and grade submission will work if the LMS is down for days (see Backup essentials).

What happened (from Instructure's updates)

Everything below is as stated on Instructure's incident page and its customer, faculty and student pages. Dates are US dates.

  1. April 25–30, 2026

    Period in which school logs may show access from Canvas customer support representative accounts (per the company).
  2. April 29

    Instructure detects unauthorized activity in Canvas, revokes the access immediately, starts an investigation and engages outside forensic experts.
  3. May 7

    The same actor gains access again through a second Canvas vulnerability and alters pages shown when some students and teachers were logged in. Detected and disabled in about 10 minutes; Canvas is put into maintenance mode. The company says it has found no evidence that data was taken that day.
  4. May 8

    The CEO apologizes. Free-for-Teacher is temporarily disabled.
  5. May 9

    Canvas is fully back online.
  6. May 11

    Instructure announces an agreement with the actor: the data was returned, it received digital confirmation of destruction, and it was informed no customers would be extorted.
  7. May 21

    Canvas administrators receive preliminary findings about the data fields exfiltrated.
  8. June

    Free-for-Teacher is permanently discontinued. A feature for registering institutional security contacts is added to Canvas.
  9. July 26 onward

    After a pause to assess the safety of the outside delivery service, delivery of user and provisioning data to affected institutions' security contacts begins.
  10. September 29

    The company says its forensic review of the data is complete and it has entered the final phase of delivering data to remaining institutions. Further updates go directly to affected institutions.
April 29
Date unauthorized activity was detected in Canvas
~10 min
To detect and disable the second intrusion on May 7
~300 orgs
Organizations where the altered page (ransom message) was visible on May 7
Undisclosed
Total affected people or institutions (as of September 30, 2026)
What Instructure has disclosed
Data fields involved
Usernames, email addresses, course names, enrollment information and messages. Enrollment information means the relationship between a user and a course, term or section, and may include enrollment status and role (student, teacher, TA, observer), but not submissions, quiz responses or course content
Not involved, per the company
Course content, submissions and credentials. The fields involved are not designed to store passwords, dates of birth, healthcare information, Social Security numbers, financial information, grades or disciplinary records
Entry point
The actor created a Free-for-Teacher account and submitted a support ticket containing malicious code. When a customer service agent opened it, a cross-site scripting (XSS) vulnerability was triggered, giving the actor an authorization token and elevated access within Canvas. On May 7, a second, unpatched XSS vulnerability in the discussion feature was used
Other products
No evidence that other Instructure products, such as Parchment, were affected
Remediation
Fixed the vulnerabilities and privilege-escalation paths. Restricted administrative access to trusted locations and tightened API access controls. Proactively cycled employee sessions, internal access tokens and many partner tokens. Permanently discontinued Free-for-Teacher. Rolling out enforced token expiration, removal of lifetime tokens and other controls in phases
Authorities
Notified law enforcement, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and international partners
Agreement with the actor
On May 11, announced an agreement under which the data was returned and digital confirmation of destruction was received. The company also says there is never complete certainty when dealing with cybercriminals

Reading note: '~300 organizations' is not the size of the breach

Instructure gives roughly 300 as the number of organizations that saw the altered pages on May 7. It is not the number of schools or people whose data was exfiltrated. As of September 30, 2026, the company had not published a total for affected people or institutions. If you see a figure elsewhere, check whether it traces back to Instructure's own statements.

Why "mundane" fields are dangerous

Email + course names + enrollment

↓

Fake messages that name real courses

→ Don't follow links; open your usual Canvas

Messages (free text)

↓

Anything anyone typed may be included

→ List secrets you sent; change what can be changed

Role (student/teacher/TA) + username

↓

Impersonating teachers or staff

→ Fix course channels and tell students

The exposed fields matter more in combination than alone. For each combination: how it can be misused, and the matching action.

Not involved, per Instructure

  • Passwords and credentials (no evidence of compromise, per the company)
  • Grades and disciplinary records
  • Dates of birth, health information, Social Security numbers, financial information
  • Course content, submissions, quiz responses

Involved

  • Usernames and email addresses
  • Course names and enrollment (which class, in which role)
  • Messages (free text; depends on what was written)

This site's view: the most powerful access sits with support staff

In Instructure's account, the way in was a support ticket sent from a Free-for-Teacher account, and access was taken when a support agent opened it. Support staff, by the nature of the role, can reach courses and accounts across many schools (which is why the company asks schools to check logs for support-agent account access). In this incident, then, input anyone can send (a ticket) met broad privileges (support) on the same screen.

This is not unique to LMSs. If you run any service with a contact form or an admin console, the internal screens that display what users submitted need XSS protection at least as much as public pages do, and the staff who use those screens should hold privileges limited in scope and time. After the incident, Instructure says it restricted administrative access to trusted locations, and that it is working on restoring some support-agent administrative privileges. For the organizational side, see The security baseline for organizations.

Sources (public record)

The facts in this article come from the public sources below. We do not cover attack techniques or information identifying the attackers.

  • Instructure, "Security Incident Update & FAQs" (incident page, including updates from May 8 to September 29, 2026) — instructure.com
  • Instructure, "Security Incident Update: For Customers" (FAQ for schools and admins: data delivery, notification, log review, MFA, integrations) — instructure.com
  • Instructure, "Security Incident Update: For Faculty" — instructure.com
  • Instructure, "Security Incident Update: For Students & Families" — instructure.com
  • Instructure Community, "How do I set details for an account?" (registering a security contact) — community.instructure.com

Update history

2026-09-30: First version, based on Instructure's incident page (through the September 29 update) and its customer, faculty and student pages. The company has said it intends to share root-cause details and lessons learned, and that further updates will go directly to affected institutions; we will update this page as more becomes public.

FAQ

QWhat was exposed in the Canvas breach?
A

According to Instructure, the data fields involved include usernames, email addresses, course names, enrollment information (the relationship between a user and a course, term or section, including enrollment status and role such as student, teacher, TA or observer) and messages. It says course content, submissions and credentials were not involved, and that the fields involved are not designed to store passwords, dates of birth, healthcare information, Social Security numbers, financial information, student grades or disciplinary records.

QHow do I find out whether my data was included?
A

Instructure delivers data for each affected institution directly to the security contacts that institution registered. It tells students and families to direct questions to their school. Students and teachers should ask their school's IT or academic office. If a school decides that individual notice is required, Instructure offers to send notifications on the school's behalf.

QShould I change my Canvas password?
A

Instructure says it has no evidence that credentials were compromised. It still encourages strong password hygiene and regular changes, especially for users who are not on single sign-on (SSO) and multi-factor authentication. If you use your Canvas password anywhere else, change it there too.

QWere the contents of Canvas messages exposed?
A

Instructure says messages are among the data fields involved. Because of the volume and the need to review each message, message data was reviewed separately from user data. In its September 29, 2026 update, the company said its forensic review of the data was complete and it had begun delivering data to the remaining institutions. Messages are free text, so if you ever wrote a password or personal information in one, assume it may be known.

QI heard the attacker deleted the data. Is it safe now?
A

On May 11, Instructure said it reached an agreement with the unauthorized actor, that the data was returned, that it received digital confirmation of data destruction, and that it was informed no customers would be extorted. The company itself also says there is never complete certainty when dealing with cybercriminals. Keep your guard up against scams that use information that may already be known, such as names, email addresses and courses.

QWhat was the cause?
A

According to Instructure, the actor created a Free-for-Teacher account and submitted a support ticket containing malicious code. When a customer service agent opened the ticket, a cross-site scripting (XSS) vulnerability was triggered, letting the actor obtain an authorization token and elevated access within Canvas. On May 7, a second, unpatched XSS vulnerability in the discussion feature was used. The company says it remediated the vulnerabilities and privilege-escalation paths and has permanently discontinued Free-for-Teacher.

QHow many people or schools were affected?
A

As of September 30, 2026, Instructure had not published a total number of affected people or institutions. It says the ransom message posted on May 7 was visible to roughly 300 organizations. That is the number of organizations that saw the altered pages, not the number whose data was exfiltrated.