Description

Instructure, a U.S.-based provider of digital learning solutions and creator of the widely used Canvas platform, has confirmed a cybersecurity incident that led to unauthorized access to user data. The company disclosed that it is actively investigating the breach with the assistance of external cybersecurity experts and law enforcement agencies. According to Instructure, the exposed data includes certain personally identifiable information (PII) belonging to users at affected institutions. This may include names, email addresses, student ID numbers, and messages exchanged between users. The company clarified that, based on current findings, there is no evidence that highly sensitive data such as passwords, dates of birth, government-issued identifiers, or financial information has been compromised. The incident has been claimed by the cyber extortion group ShinyHunters, which has listed Instructure on its data leak portal. The group alleges that the breach impacts thousands of educational institutions worldwide and involves a massive dataset containing records of students, teachers, and staff, along with private communications. It also claims that additional systems, including Salesforce instances, were affected. ShinyHunters stated that the breach was carried out by exploiting a vulnerability in Instructure’s systems, which has since been patched. While these claims suggest a large-scale compromise spanning multiple regions, including North America, Europe, and Asia-Pacific, they have not been independently verified. In response, Instructure has implemented remediation measures such as patching vulnerabilities, increasing monitoring, and rotating application keys. Customers are required to reauthorize API access. The company continues to investigate and will share updates as new information emerges.