{"id":60621,"date":"2026-05-10T00:00:00","date_gmt":"2026-05-10T00:00:00","guid":{"rendered":"urn:uuid:08d2fb38-f9e5-03b6-d11e-d0b04931f5fa"},"modified":"2026-05-10T00:00:00","modified_gmt":"2026-05-10T00:00:00","slug":"what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/","title":{"rendered":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/instructure-canvas-breach-thumbnail:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/26\/instructure-canvas-breach-thumbnail.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><b><span class=\"main-subtitle-black\"><span class=\"body-subhead-title\"><i>Summary<\/i><\/span><\/span><\/b><\/p>\n<p><i>In May 2026, SHADOW-AETHER-015 exposed data from 8,809 Canvas customers across 50 countries in what appears to be a backend compromise of parent company Instructure\u2019s platform. The breach affects universities, K\u201312 school districts, and teaching hospitals globally, including eight Ivy League institutions. Because Canvas stores sensitive personal disclosures, for example, medical accommodation requests and private advisor conversations, the primary risk is highly targeted spear\u2011phishing using real institutional context. The immediate risk is follow\u2011on social engineering, credential abuse, and targeted phishing campaigns.<\/i><\/p>\n<p>When a learning management system is breached, the impact&nbsp;isn\u2019t&nbsp;just technical. Canvas is where students share medical needs, seek support from advisors, and navigate some of the most personal moments of their academic lives. The confirmation of a breach at Instructure&nbsp;&#8211;&nbsp;Canvas\u2019s parent company&nbsp;&#8211;&nbsp;means that sensitive information entrusted to those systems may now be in the wrong hands. We want to help you understand what happened, what it means in practice, and what to do next.<\/p>\n<p>Security and IT teams across&nbsp;thousands of&nbsp;institutions running Canvas are already in response mode. This&nbsp;update&nbsp;is intended to support that work with clear intelligence, honest context, and practical guidance.<\/p>\n<p><span class=\"body-subhead-title\">What&nbsp;is the Instructure Canvas&nbsp;breach?<\/span><\/p>\n<p>Canvas is the learning management system of choice for tens of millions of students and educators worldwide. It is used for distributing coursework, recording grades, managing API integrations with dozens of third-party tools, and&nbsp;&#8211;&nbsp;critically&nbsp;&#8211;&nbsp;facilitating&nbsp;private conversations between students and faculty, advisors, and support staff.<\/p>\n<p>According to&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/about\/threat-research.html\">TrendAI\u2122 Research<\/a>, threat actor SHADOW-AETHER-015 has released a document&nbsp;containing&nbsp;8,809 educational institution names&nbsp;&#8211;&nbsp;almost certainly&nbsp;a dump of Canvas LMS customer accounts and instances. The full scope of what was accessed is still being&nbsp;established, but the nature of Canvas\u2019s role in institutional life makes this data exposure more sensitive than a typical&nbsp;platform&nbsp;breach.<\/p>\n<table>\n<tbody readability=\"4\">\n<tr readability=\"8\">\n<td><b>8,809<\/b><br \/>institutions in leaked data<\/td>\n<td><b>50<\/b><br \/>countries affected<\/td>\n<td><b>1,616<\/b><br \/>K\u201312 districts confirmed<\/td>\n<td><b>8<\/b><br \/>Ivy League universities<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span class=\"body-subhead-title\">Why&nbsp;is the Canvas&nbsp;breach&nbsp;serious?<\/span><\/p>\n<p>Not all data breaches are equal.&nbsp;These&nbsp;warrants close attention for several reasons:&nbsp;<\/p>\n<ul>\n<li><span class=\"rte-circle-bullet\">Canvas holds unusually sensitive personal information.&nbsp;Students&nbsp;disclose&nbsp;medical conditions for accommodation requests, share personal circumstances with advisors, and communicate with advocates.&nbsp;<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">The breach enables highly convincing follow-on attacks.&nbsp;Threat actors now potentially have real names, institutional email addresses, course context, and private message history&nbsp;&#8211;&nbsp;making it possible to craft phishing messages&nbsp;nearly indistinguishable&nbsp;from legitimate institutional communications.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">API integrations amplify the impact.&nbsp;Because Canvas connects to dozens of third-party applications via API keys, the breach forced institutions to re-authorize&nbsp;all external integrations&nbsp;&#8211;&nbsp;disrupting tools many depended on during final exam periods.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">The reach is global and cross-sector.&nbsp;Canvas is embedded across K\u201312, higher education, and&nbsp;&#8211;&nbsp;through medical school programs&nbsp;&#8211;&nbsp;healthcare institutions. The downstream risk does not stop at one&nbsp;institution&nbsp;type or one region.<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">How&nbsp;many&nbsp;institutions&nbsp;are&nbsp;affected by&nbsp;the Canvas&nbsp;breach?<\/span><\/p>\n<p>TrendAI\u2122 analysis of the data released by SHADOW-AETHER-015 reveals the full scale of this breach. The leaked list spans&nbsp;thousands of&nbsp;institutions across 50 countries and 6 continents&nbsp;-making&nbsp;this one of the most geographically widespread education sector exposures on record.<\/p>\n<table>\n<thead>\n<tr>\n<th>Region<\/th>\n<th>Institutions<\/th>\n<th>Share of Total<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>North America<\/td>\n<td>~8,361<\/td>\n<td>94.9%<\/td>\n<\/tr>\n<tr>\n<td>Europe<\/td>\n<td>~196<\/td>\n<td>2.2%<\/td>\n<\/tr>\n<tr>\n<td>Asia-Pacific<\/td>\n<td>~175<\/td>\n<td>2.0%<\/td>\n<\/tr>\n<tr>\n<td>Latin America<\/td>\n<td>~55<\/td>\n<td>0.6%<\/td>\n<\/tr>\n<tr>\n<td>Middle East &amp; Africa<\/td>\n<td>~12<\/td>\n<td>0.1%<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The United States accounts for 94.6% of affected institutions (8,335). Australia (122), the United Kingdom (70), and Brazil (29) are the most significantly impacted countries outside North America. In total, 46 countries are represented.<\/p>\n<p>Of the 8,809 entries, confirmed figures include 2,514 higher education institutions&nbsp;&#8211;&nbsp;among them all eight Ivy League universities, major state university systems, and internationally&nbsp;recognized&nbsp;institutions including Oxford, Cambridge, NUS, and the University of Melbourne&nbsp;&#8211;&nbsp;and 1,616 K\u201312 school districts, including large urban systems such as Clark County (Las Vegas), Houston ISD, and Miami-Dade.<\/p>\n<p>The presence of development, UAT, and staging instances in the data points toward backend infrastructure access or a platform-level compromise&nbsp;&#8211;&nbsp;a detail that distinguishes this from a surface-level attack.<\/p>\n<p><span class=\"body-subhead-title\">How did SHADOW-AETHER-015&nbsp;carry&nbsp;out the&nbsp;attack?<\/span><\/p>\n<p>The&nbsp;extortion&nbsp;group&nbsp;demonstrates&nbsp;medium-to-high capability, with the ability to extract large-scale platform data&nbsp;indicating&nbsp;backend system access or sophisticated API exploitation.<\/p>\n<p>SHADOW-AETHER-015&nbsp;was also involved in a 2025 compromise of Instructure\u2019s Salesforce environment, according to&nbsp;<a href=\"https:\/\/www.securityweek.com\/hundreds-of-salesforce-customers-allegedly-targeted-in-new-data-theft-campaign\/\" target=\"_blank\">SecurityWeek<\/a>, resulting in millions of data records being compromised and leaked. Their documented approach is&nbsp;often to&nbsp;exploit a trusted third-party integration to reach a higher-value target.<\/p>\n<p><span class=\"body-subhead-title\">What&nbsp;cyber&nbsp;attacks&nbsp;should Canvas&nbsp;institutions&nbsp;expect&nbsp;next?<\/span><\/p>\n<p>The most significant risk from this breach is not what happened&nbsp;&#8211;&nbsp;it is what comes next. The weeks following a large-scale data exposure typically bring:<\/p>\n<ul>\n<li><span class=\"rte-circle-bullet\">Spear-phishing campaigns&nbsp;using real institutional context&nbsp;&#8211;&nbsp;referencing actual courses, advisors, and student circumstances&nbsp;&#8211;&nbsp;targeting faculty, staff, and students<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Credential abuse attempts&nbsp;against institutional systems, particularly where Canvas credentials overlap with other internal accounts<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Targeted social engineering&nbsp;of individuals whose sensitive personal disclosures were captured in Canvas messages, including medical and personal circumstances<\/span><\/li>\n<\/ul>\n<p>Institutions with large graduate and professional programs face elevated risk. Medical institutions on the list&nbsp;&#8211;&nbsp;including Weill Cornell Medical College, the University of Nebraska Medical Center, and several Brazilian hospital systems&nbsp;&#8211;&nbsp;should treat HIPAA implications as part of their response planning. K\u201312 institutions must address FERPA and COPPA obligations given that minor children\u2019s data is involved.<\/p>\n<p><span class=\"body-subhead-title\">How&nbsp;can&nbsp;institutions&nbsp;protect&nbsp;themselves&nbsp;after the Canvas&nbsp;breach?<\/span><\/p>\n<p>Detecting post-breach social engineering requires correlating communication&nbsp;behavior&nbsp;across&nbsp;the entire attack surface&nbsp;&#8211;&nbsp;not&nbsp;just&nbsp;filtering for known malicious indicators, which will not appear in attacks built from legitimate&nbsp;compromised&nbsp;institutional data.<\/p>\n<p>Any&nbsp;organization&nbsp;holding critical and sensitive data needs a proactive approach:&nbsp;a way to&nbsp;discover their entire attack surface,&nbsp;identify&nbsp;and&nbsp;prioritize&nbsp;risk assets, gain visibility into the attack paths a threat actor could take, and implement mitigating controls that lower the risk of breach.<\/p>\n<p>What comes next&nbsp;won&#8217;t&nbsp;arrive with obvious warning signs. It will look like a message from a familiar name, referencing a real course or a real conversation. The best defense&nbsp;isn&#8217;t&nbsp;faster filtering&nbsp;&#8211;&nbsp;it&#8217;s&nbsp;broader visibility, connecting the signals across&nbsp;the environment&nbsp;to spot what&nbsp;doesn&#8217;t&nbsp;fit before it becomes a problem.<\/p>\n<p><span class=\"body-subhead-title\">TrendAI\u2122 customers are already being&nbsp;monitored&nbsp;for Canvas-related activity<\/span><\/p>\n<p>TrendAI\u2122 Research is actively tracking the spear-phishing campaigns, credential abuse patterns, and social engineering activity that typically follow large-scale education data exposures. That intelligence feeds directly into <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\">TrendAI Vision One\u2122<\/a> protection&nbsp;&#8211;&nbsp;so customers&nbsp;benefit&nbsp;from what our research teams are seeing across the global threat landscape, not just what is happening inside their own environment.<\/p>\n<p><span class=\"body-subhead-title\">About&nbsp;TrendAI\u2122 Research<\/span><\/p>\n<p>Decades of human intelligence, now accelerated by&nbsp;nearly 20&nbsp;years of applied AI in cybersecurity, give our teams an unusually deep view of how adversaries&nbsp;operate&nbsp;&#8211;&nbsp;who they target, how they move, and what they do with what they find. That foresight is what we bring to situations like this: not just to understand what happened, but to help organizations stay ahead of what comes next.<\/p>\n<p><span class=\"body-subhead-title\">Frequently Asked Questions: The Instructure Canvas Breach<\/span><\/p>\n<p>The following questions address what institutions, students, and security teams are asking about the Canvas breach.<\/p>\n<p>TrendAI\u2122 Research has&nbsp;identified&nbsp;8,809 institutions in the leaked data, spanning 50 countries. All eight Ivy League universities are confirmed in the list, along with major US state university systems, 1,616 K\u201312 school districts, and international institutions including Oxford, Cambridge, NUS, and the University of Melbourne.&nbsp;&nbsp;<\/p>\n<p>The data exposed is what institutions and users had stored and exchanged within Instructure\u2019s Canvas platform. This&nbsp;likely includes&nbsp;personally identifiable information (PII), and&nbsp;&#8211;&nbsp;given Canvas\u2019s role in education&nbsp;&#8211;&nbsp;may include medical accommodation requests, private advisor conversations, and sensitive personal disclosures. It does not include access to institutions\u2019 internal IT systems.<\/p>\n<p>Canvas is commonly used by students to&nbsp;disclose&nbsp;medical conditions for accommodation requests and to communicate privately with advisors and advocates. Those communications are likely within the scope of the breach. Institutions should treat this as a potential exposure&nbsp;of&nbsp;sensitive personal information and communicate accordingly with their communities.<\/p>\n<p>No. The breach is of Instructure\u2019s Canvas platform, not of institutional internal systems. Threat actors do not have direct access to your internal environment&nbsp;because&nbsp;of this breach. However, the stolen data enables highly convincing phishing and social engineering attacks that could lead to credential compromise if not addressed.<\/p>\n<p>Immediately: alert staff, faculty, and students to expect highly convincing phishing emails referencing real course and advisor names. Review and re-authorize&nbsp;Canvas API integrations. Audit whether Canvas credentials overlap with other internal systems and enforce MFA. K\u201312 and medical institutions should begin FERPA, COPPA, and HIPAA communications planning. Engage&nbsp;TrendAI\u2122 to&nbsp;monitor&nbsp;for downstream threat activity.<\/p>\n<p>SHADOW-AETHER-015&nbsp;demonstrates&nbsp;medium-to-high capability. Their approach involves exploiting trusted third-party integrations to reach higher-value targets.&nbsp;TrendAI\u2122 Research is actively tracking this group.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/What-Is-the-Instructure-Canvas-Breach.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Instructure Canvas breach affects universities, K\u201312 school districts, and teaching hospitals globally. This blog entry intends to provide context and practical guidance. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":60622,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510],"class_list":["post-60621","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-10T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/instructure-canvas-breach-thumbnail:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do\",\"datePublished\":\"2026-05-10T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/\"},\"wordCount\":1622,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/\",\"name\":\"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg\",\"datePublished\":\"2026-05-10T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/","og_locale":"en_US","og_type":"article","og_title":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-05-10T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/instructure-canvas-breach-thumbnail:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do","datePublished":"2026-05-10T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/"},"wordCount":1622,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/05\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg","keywords":["Trend Micro Research : Articles, News, Reports"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/","url":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/","name":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/05\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg","datePublished":"2026-05-10T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/05\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/05\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do.jpg","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/what-is-the-instructure-canvas-breach-impact-risks-and-what-institutions-should-do\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60621"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60621\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/60622"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}