Instructure initially reported API-related disruptions before confirming the incident was the result of a cyberattack.
According to the company, external forensic experts were engaged to investigate the scope and impact.
By May 2, Instructure stated that the incident had been contained, although analysis and recovery efforts remained ongoing.
Preliminary findings indicate that the compromised data includes:
Importantly, Instructure emphasized that there is currently no evidence of exposure involving:
The company noted that affected institutions will be notified if additional sensitive data exposure is discovered during the ongoing investigation.
Instructure implemented several immediate containment and remediation measures to limit the impact of the breach:
A notable operational impact included forced reauthorization for users after application keys were reissued.
These new keys include timestamps in their names to help users identify legitimate credentials during the reauthorization process.
The incident caused temporary disruptions to developer tools and data services. Canvas Data 2 experienced outages but was restored by May 3, 2026.
However, Canvas Beta and Test environments remained under maintenance at the time of the latest update.
The company acknowledged that some customers experienced degraded functionality due to API key issues during the incident response phase.
While Instructure has not officially attributed the attack, the timing aligns with claims from the ShinyHunters group, a well-known cybercriminal collective linked to multiple high-profile data breaches targeting cloud services and SaaS platforms.
ShinyHunters typically exploits misconfigured databases, exposed credentials, or third-party integrations to gain unauthorized access and exfiltrate data for sale or extortion.
Instructure stated that the investigation is still active, with continuous updates being shared via its status page.
The company reiterated its commitment to transparency and emphasized that additional findings will be disclosed as they are confirmed.
Security experts note that incidents involving educational platforms can have wide-reaching impacts due to the volume of student and institutional data processed by such systems.
This breach highlights the continued targeting of SaaS-based education platforms and reinforces the importance of strong credential management, API security, and continuous monitoring in cloud environments.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Canvas Parent Instructure Confirms Data Breach After ShinyHunters Claims Attack appeared first on Cyber Security News.
It’s May 4 — a date that happens to sound similar to “May the Force,”…
The Mandalorian & Grogu is coming to theaters on May 22, but before then you…
If you frequently bring several electronics along with you on your travels but you don't…
Disney+ is offering subscribers a free Marvel Rivals skin through its Disney+ Perks program. The…
There has been a ton of buzz around Dishonored's future, following a rather innocuous post…
Capcom wants players to know that old age won't keep Leon Kennedy out of games…
This website uses cookies.