BREACH2026-06-06T14:00:45.865396+00:006 min read

How the Canvas LMS Breach Exposed 275 Million Students

ShinyHunters breached Canvas LMS in May 2026, stealing data on 275 million students and educators. Here's exactly what was taken and what to do right now.

How the Canvas LMS Breach Exposed 275 Million Students

What Happened

In May 2026, the hacker group ShinyHunters breached Instructure — the company behind Canvas LMS, used by universities and K-12 schools across 70+ countries.

What was stolen:

  • Full names and email addresses (275 million records)
  • Institutional affiliations
  • Course enrollment data
  • In some cases: phone numbers and addresses

The breach was discovered when a dataset appeared on a dark web forum priced at $3,000.

Who Is Affected

If you (or your child) attends a university or school using Canvas LMS — which includes most major US universities — your data was likely in this breach.

Schools confirmed affected: Harvard, MIT, UC system, hundreds of community colleges.

Why This Is Worse Than You Think

Email + institutional affiliation is the perfect combo for spear phishing. Attackers now know you're a student at [specific school], which makes fake IT alerts, financial aid scams, and scholarship phishing far more convincing.

What You Should Do Right Now

  1. Change your school email password — use a password manager (Bitwarden is free)
  2. Enable MFA on your school account and personal email
  3. Watch for phishing emails pretending to be your school's IT department
  4. Check haveibeenpwned.com — enter your school email to see breach exposure

The Bigger Picture

This is the third major education-sector breach in 18 months. Schools collect huge amounts of sensitive data but spend a fraction of what corporations do on security.

Bottom line: Assume your school email address is now in hacker databases. Treat any urgent email from "IT support" or "financial services" with extreme suspicion.


Source: BleepingComputer, ShinyHunters dark web post (May 2026), Instructure investor filing

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read

Stay invisible. Follow @hack_decoded