Data Breaches

Canvas Breach Exposes Shared Student Identity Data

The real risk is not a single school’s breach. It is that Canvas sits in the middle of student identity and communication across many institutions, so vendor-held data can be reused to target people who never lost their own local systems.

Instructure said the stolen data includes names, emails, student ID numbers, and messages shared among users. The company says there is no evidence passwords, dates of birth, government IDs, or financial data were taken, and ShinyHunters claims it took 3.65TB tied to roughly 275 million users across 9,000 institutions.

That shifts the story from vendor compromise to downstream exposure. Even if campus systems stay intact, the stolen identity data can still fuel impersonation, targeting, and follow-on abuse across schools and staff.

12 sources · May 14

Timeline

Sources

Part of the PlainSec briefing for 2026-05-05

Every edition of this story: Canvas Breach Exposes Shared Student Identity Data

More from today