How the Canvas LMS Breach Exposed 275 Million Students
ShinyHunters breached Canvas LMS in May 2026, stealing data on 275 million students and educators. Here's exactly what was taken and what to do right now.
What Happened
In May 2026, the hacker group ShinyHunters breached Instructure — the company behind Canvas LMS, used by universities and K-12 schools across 70+ countries.
What was stolen:
- Full names and email addresses (275 million records)
- Institutional affiliations
- Course enrollment data
- In some cases: phone numbers and addresses
The breach was discovered when a dataset appeared on a dark web forum priced at $3,000.
Who Is Affected
If you (or your child) attends a university or school using Canvas LMS — which includes most major US universities — your data was likely in this breach.
Schools confirmed affected: Harvard, MIT, UC system, hundreds of community colleges.
Why This Is Worse Than You Think
Email + institutional affiliation is the perfect combo for spear phishing. Attackers now know you're a student at [specific school], which makes fake IT alerts, financial aid scams, and scholarship phishing far more convincing.
What You Should Do Right Now
- Change your school email password — use a password manager (Bitwarden is free)
- Enable MFA on your school account and personal email
- Watch for phishing emails pretending to be your school's IT department
- Check haveibeenpwned.com — enter your school email to see breach exposure
The Bigger Picture
This is the third major education-sector breach in 18 months. Schools collect huge amounts of sensitive data but spend a fraction of what corporations do on security.
Bottom line: Assume your school email address is now in hacker databases. Treat any urgent email from "IT support" or "financial services" with extreme suspicion.
Source: BleepingComputer, ShinyHunters dark web post (May 2026), Instructure investor filing
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded
