OptMsg Breach Breakdown: Canvas

OptMsg Breach Breakdown: Canvas

Accounts Impacted: Attacker claim only — ShinyHunters lists 280 million records across 8,809 institutions. Instructure has not confirmed any figure
Breach Occurrence Date: April 29, 2026 (second attack: May 7, 2026)
Added to Breach Breakdown: May 2026

The Canvas Data Breach: What Happened

Canvas is a cloud-based learning platform used by more than 30 million students and teachers at 8,000 institutions worldwide. In May 2026, it suffered two serious security attacks. ShinyHunters carried out the Canvas data breach. This is the same criminal group behind major attacks on Ticketmaster, AT&T, Panera Bread, CarGurus, and SoundCloud. Canvas is run by its parent company, Instructure. It serves 41% of all higher education institutions in the US, as well as thousands of K-12 schools globally.

Instructure first found the unauthorized access on April 29, 2026. The company said it had contained the breach the following day. However, that was not the end of it. On May 7, 2026, ShinyHunters struck again. This second attack hit during finals week. Students at Harvard, Princeton, Columbia, Duke, MIT, UCLA, and the University of Pennsylvania logged into Canvas. Instead of their coursework, they saw a ransom note from ShinyHunters. The Canvas data breach had taken down one of the most important tools in education at the worst time of the year.

How ShinyHunters Got In and the Ransom Resolution

ShinyHunters found a weak spot in Instructure’s Free-For-Teacher account program. This program let teachers create Canvas accounts without a verified school email. That gap gave the attackers a way into the same system that millions of paid users relied on. When Instructure ignored the first ransom demand and applied security patches, ShinyHunters responded by taking over the Canvas login page. They set a deadline of May 12, 2026 to pay or face a full data release. To prevent the public exposure of student information, Instructure ultimately confirmed on May 12, 2026, that it reached a financial agreement with the hackers to delete the pilfered records. While Instructure received digital “shred logs” confirming the data’s destruction, they acknowledged to the public that total certainty is impossible when dealing with cybercriminals. Instructure has permanently shut down the Free-For-Teacher program while they complete a full security review with CrowdStrike.

What Data Was Exposed in the Canvas Data Breach

Instructure confirmed the Canvas data breach exposed the following data for students, teachers, and staff:
  • Full names
  • Email addresses
  • Student ID numbers
  • Private messages sent between students and teachers inside Canvas (including sensitive academic and medical accommodations)
Instructure Chief Information Security Officer Steve Proud confirmed that ShinyHunters did not access passwords, dates of birth, Social Security numbers, or financial data. However, the threat actors exfiltrated roughly 3.65 terabytes of data, meaning millions of private inbox threads are involved.

Why the Canvas Data Breach Is So Dangerous

No passwords or financial data leaked. However, the Canvas data breach still creates serious risks. Criminals now have names, emails, student IDs, and private messages. Together, that data lets them:
  • Send convincing phishing emails that pose as Canvas, your school, or a professor. They can use your real name and quote your private messages to seem real.
  • Impersonate professors and school staff to send fake grade notices, fake assignment links, or fake login pages built to steal your password.
  • Target students with extortion using private messages that may include personal details, health information, or other sensitive content.
  • Run credential stuffing attacks on other platforms using your email address. Therefore, if you reuse passwords elsewhere, those accounts are also at risk.
  • Exploit finals week stress to make scam messages feel urgent. Students under pressure are less likely to stop and question a suspicious email.
Moreover, the Canvas data breach affects more than students. Parents of K-12 children, teachers, and school staff all face the same risks. As a result, the harm from this breach spreads far beyond individual schools.

What You Should Do Now If You Were Affected by the Canvas Data Breach

If you are a student, teacher, parent, or staff member at a school that uses Canvas, act now. Here are the steps to take:
  1. Follow your school’s official guidance first. Your school’s IT team knows the specific impact for your institution. Check your school’s website and email for updates.
  2. Change your Canvas password right away if your school advises it. Also update any account where you used the same password.
  3. Turn on two-factor authentication (2FA) on your Canvas account and your email address.
  4. Watch for phishing emails, texts, and Canvas messages about your courses, grades, or assignments. Do not click links. Go to your school’s website directly instead.
  5. Never give your password or login code to anyone. This includes anyone claiming to be IT support, a professor, or Canvas staff, by email, phone, or message.
  6. Report anything suspicious to your school’s IT team right away. Criminals may use details from your private Canvas messages. Be careful about contact from anyone who knows things you only shared inside Canvas.
  7. Switch to a secure, opt-in email service like OptMsg to stop phishing emails from the Canvas data breach from reaching your inbox.

How OptMsg Helps After the Canvas Data Breach

The Canvas data breach gave criminals your name, email, student ID, and private messages. Even though Instructure negotiated for the destruction of the data, the threat of follow-up social engineering remains high. OptMsg gives you the tools to stop those attacks before they reach you:

  • You decide who can email you. OptMsg’s patent-pending opt-in router technology means only people you approve can reach your inbox. Therefore, even if criminals have your email from the Canvas data breach, they cannot send you fake school emails or phishing attempts.
  • No password to steal. OptMsg does not use a password to protect your account. So when other platforms leak credentials, attackers find nothing to exploit here.
  • We don’t collect your personal data to sell to advertisers. Unlike free inboxes that profit from your data, OptMsg charges a small fee. We do not treat you as the product.
  • OptMsg does not scan your emails to sell ads. In short, your inbox belongs to you, not to advertisers or AI training systems.

Why the Canvas Data Breach Matters to Every Student and Parent

The Canvas data breach is the largest school security breach on record. In a single attack, ShinyHunters disrupted finals week for millions of students. Harvard, MIT, Princeton, Duke, UCLA, and thousands of other schools all felt it. Many students could not submit papers, check exam details, or reach their professors. It happened at the worst time of the academic year.

Moreover, the Canvas data breach reveals how much schools now depend on a small number of digital platforms. When one of those platforms goes down, every student, teacher, and parent connected to it pays the price. Furthermore, private messages between students and teachers leaked in this breach. That makes it far more personal than a typical contact data leak.

The real problem, however, does not end when Canvas comes back online. Even with shred logs delivered to Instructure, data often leaks through secondary channels in extortion rings. OptMsg ensures that no matter what data criminals hold, they cannot use your email address to reach you without your explicit approval.

Your Inbox. Your Rules.
Take control of your inbox today. Download OptMsg on iOS, Android, or use it on the web.

Helpful Links

Stay informed. Stay secure. OptMsg actively protects your email from data breaches and cyber threats. Our Breach Breakdown blog alerts you when companies expose personal information, so you can take action before criminals do.
Scroll to Top