the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Hackers steal students’ data during breach at education tech giant Instructure

ArticlesNewsletters
ArticlesNewsletters
Enterprise/SaaS

Hackers steal students’ data during breach at education tech giant Instructure

The data breach at education tech giant Instructure includes students' private data, according to a sample of the allegedly stolen data seen by TechCrunch.

by The Tech Buzz

PUBLISHED: Tue, May 5, 2026, 3:48 PM UTC | UPDATED: Fri, Sep 4, 2026, 3:32 PM UTC

Add as a preferred source on Google
Hackers steal students’ data during breach at education tech giant Instructure

AI-generated image

This article was generated with AI assistance

Instructure, the education technology giant behind Canvas LMS used by thousands of schools worldwide, just confirmed a major data breach that exposed students' private information. According to a sample of stolen data verified by TechCrunch, hackers successfully infiltrated the company's systems and extracted sensitive student records. The notorious hacking group ShinyHunters has claimed responsibility for the attack, marking yet another high-profile breach in the education sector that puts millions of students at risk.

Instructure is scrambling to contain a data breach that's sending shockwaves through the education technology sector. The Salt Lake City-based company, which powers Canvas LMS for thousands of K-12 schools and universities, confirmed that hackers infiltrated its systems and made off with student records.

TechCrunch independently verified the breach after reviewing a sample of the allegedly stolen data. The records contain private student information, though the full scope of what was compromised remains unclear. Instructure hasn't disclosed how many students are affected, but given Canvas serves over 30 million users globally according to the company's own figures, the potential exposure is massive.

The attack bears the hallmarks of ShinyHunters, a hacking collective that's been on a tear lately. The group has claimed credit for the Instructure breach, adding it to their growing list of high-profile victims. ShinyHunters previously hit AT&T, Ticketmaster, and Santander Bank in separate incidents, consistently targeting companies with vast troves of consumer data.

What makes this breach particularly concerning is Instructure's central role in education infrastructure. Canvas isn't just a learning management system - it's where teachers post grades, students submit assignments, and administrators store everything from attendance records to disciplinary notes. Schools trusted Instructure to safeguard some of their most sensitive data, and that trust just took a serious hit.

Advertisement

The timing couldn't be worse for the edtech industry. Educational institutions have been pouring money into digital platforms since the pandemic forced remote learning, but security hasn't always kept pace with adoption. According to K-12 Security Information Exchange data, cyberattacks on schools have tripled since 2020, with student data becoming an increasingly valuable commodity on dark web marketplaces.

Instructure went public in 2015 before being taken private by Thoma Bravo in a $2 billion deal in 2020. The private equity firm merged it with Anthology in 2024, creating an edtech behemoth. But consolidation doesn't automatically mean better security, and this breach proves even major players with deep pockets aren't immune to sophisticated attacks.

Schools now face an uncomfortable reckoning. District IT administrators are fielding panicked calls from parents wanting to know if their children's information was exposed. Meanwhile, legal teams are reviewing contracts to determine liability. Most education technology agreements include lengthy liability waivers, but that won't stop the lawsuits if sensitive student data ends up for sale online.

The breach also raises questions about third-party risk management in education. When schools sign up for platforms like Canvas, they're essentially handing over the keys to student data. But how many districts actually audit their vendors' security practices? How many have incident response plans for when - not if - a breach occurs?

Instructure hasn't said how the hackers got in. Was it a phishing attack? Unpatched vulnerability? Insider threat? The company's silence on technical details is frustrating security researchers who want to understand the attack vector. Without that information, other edtech companies can't adequately protect themselves against similar breaches.

Advertisement

What's clear is that ShinyHunters is getting bolder. The group operates with near impunity, stealing data and selling it or leaking it for notoriety. Law enforcement agencies have struggled to shut them down, partly because the collective appears to operate across multiple jurisdictions with members scattered globally.

For students caught in the crossfire, the implications are serious. Student records often contain Social Security numbers, addresses, disciplinary records, and health information. That data can be used for identity theft, targeted phishing, or worse. And unlike adults who can freeze credit reports and monitor for fraud, minors have limited options to protect themselves.

Instructure needs to move fast on breach notification and remediation. Schools deserve detailed information about what was taken, when the breach occurred, and what safeguards failed. Students and parents need credit monitoring services and clear guidance on protecting themselves. Anything less is unacceptable given the magnitude of the breach and the vulnerable population affected.

The Instructure breach is a wake-up call for the entire education sector. As schools increasingly rely on third-party platforms to manage everything from grading to communications, the attack surface for hackers keeps expanding. This isn't just about one company's security failure - it's about systemic vulnerabilities in how we protect student data. Schools need to demand better security standards from vendors, implement rigorous third-party risk assessments, and prepare for the reality that breaches will happen. For Instructure, the path forward requires radical transparency about what went wrong and concrete steps to prevent it from happening again. Anything less puts millions of students at continued risk.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Instructure, the company behind Canvas LMS used by thousands of schools, confirmed hackers infiltrated its systems and stole student records. The attack was verified by TechCrunch and the hacking group ShinyHunters claimed responsibility, exposing sensitive student data from Canvas's 30+ million global users.

Instructure hasn't disclosed the exact number of affected students, but Canvas LMS serves over 30 million users globally across thousands of K-12 schools and universities. The full scope of exposed data remains unclear, making the potential exposure massive given the platform's widespread educational use.

ShinyHunters is a prolific cybercriminal collective that claimed responsibility for the Instructure breach. The group has previously targeted major companies including AT&T, Ticketmaster, and Santander Bank. They operate across multiple jurisdictions with scattered members and have evaded law enforcement shutdown attempts.

The Instructure breach exposed sensitive student records including Social Security numbers, addresses, disciplinary records, and health information stored in Canvas LMS. Students also submitted assignments and teachers posted grades on the platform, creating a comprehensive repository of educational data.

The Instructure breach raises serious security concerns about Canvas LMS. While Instructure is a major edtech company owned by private equity firm Thoma Bravo and merged with Anthology in 2024, this breach demonstrates that even large platforms with significant resources aren't immune to sophisticated cyberattacks.

Students affected by the Instructure breach should monitor for identity theft and fraudulent accounts using their exposed personal information. Consider credit monitoring, freeze credit reports if eligible, and watch for phishing emails targeting student accounts. Schools should provide breach notification details and protective guidance.

More in Enterprise/SaaS

Adobe Taps Anil Chakravarthy to Replace Narayen as CEO

Adobe Taps Anil Chakravarthy to Replace Narayen as CEO

Zscaler Beats Estimates, Bets Big on Agentic AI

Australia's Data Centre Boom Sparks Resource Fight

Australia's Data Centre Boom Sparks Resource Fight

Google Adds Voice Commands to Gmail, Docs, Keep

Google Adds Voice Commands to Gmail, Docs, Keep

Palo Alto Networks Buys Console for $500M

Palo Alto Networks Buys Console for $500M

Microsoft to Finally Reveal Azure's Real Dollar Revenue

Microsoft to Finally Reveal Azure's Real Dollar Revenue

More Articles

Snowflake Stock Jumps 22% on AI Coding Agent Boost

Snowflake Stock Jumps 22% on AI Coding Agent Boost

Sep 2

150M Driver's License Photos Allegedly Stolen

150M Driver's License Photos Allegedly Stolen

Sep 2

Palo Alto CEO: AI Exposes $1T Security Gap

Palo Alto CEO: AI Exposes $1T Security Gap

Sep 2

Palo Alto CEO: $1T in Cyber Infrastructure Not AI-Ready

Palo Alto CEO: $1T in Cyber Infrastructure Not AI-Ready

Sep 2

Palo Alto Networks Stock Soars on AI Security Boom

Palo Alto Networks Stock Soars on AI Security Boom

Sep 1

Dell Stock Jumps 9% as AI Server Sales Forecast Triples

Dell Stock Jumps 9% as AI Server Sales Forecast Triples

Sep 1