Canvas data breach: how the ShinyHunters attack on Instructure reached Dutch universities
TL;DR
Learning platform Canvas, run by Instructure, was breached in late April 2026 by the extortion group ShinyHunters through its Free-For-Teacher account program. Names, email addresses, student IDs, and some private messages were exposed, with the group claiming data on around 275 million users. In the Netherlands, 44 educational institutions were affected, including several universities that disconnected Canvas from their systems.
Incident Response PlaybookExpand
- Confirm exposure with the vendor. Establish which of your tenants, accounts, and data sets were in scope and over what window.
- Rotate API credentials and integration tokens tied to the platform. Assume anything stored there is now in the wrong hands.
- Force password resets where institutional accounts share credentials with the platform, and enforce MFA.
- Inventory every integration the platform touches. SaaS breaches spread through connections, not just logins.
- Run structured forensic review of access from the platform into your own environment.
- Determine what personal data was exposed and for which individuals: students, teachers, staff.
- Notify legal counsel and assess your own AVG (GDPR) duties as controller, separate from the vendor's.
- Where personal data is involved, notify the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours.
- Warn affected students and staff that the stolen data fuels convincing, personalised phishing.
- Brief your service desk to expect impersonation attempts referencing real course names and messages.
- Re-run your vendor risk assessment for the platform, including its breach history.
- Schedule a phishing simulation aimed at the exact lures this data enables.
A breach that arrived through a trusted vendor
The Canvas data breach shows how an attack on a single education vendor can land on every institution that uses it. In late April 2026, the learning management system Canvas, operated by the private company Instructure, was hit by the extortion group ShinyHunters. The exposed information includes student names, email addresses, student ID numbers, and private messages between users. For Dutch universities and colleges, the problem arrived through a supplier they trusted, not through their own front door, which is exactly what makes this kind of breach hard to plan for.
What happened
Instructure detected unauthorised activity around the end of April and confirmed the breach in early May, according to threat intelligence published by Bitdefender. The exposure window ran from roughly 30 April to 7 May 2026, after which Canvas was restored and the abused account program was shut down. ShinyHunters set a ransom deadline, first for 6 May and then extended to 12 May, and caused an outage during which a ransom note was shown to users, landing during exam periods at some institutions.
On 11 May, Instructure issued an apology for its lack of transparency and said it had reached an agreement with ShinyHunters under which the stolen data was destroyed, adding that Canvas was back online. As with most such claims, that the data was "destroyed" after a deal is not something downstream institutions can independently verify.
How the attack worked
The confirmed entry point was Canvas's Free-For-Teacher program, which let educators create Canvas tenants without institutional verification, as analysis by Rescana set out. That low-friction onboarding created weak trust boundaries between those free accounts and institutional tenants sharing the same underlying infrastructure. In a multi-tenant SaaS environment, customer data is separated by logic rather than by physical isolation, and once the verification gap was abused, that separation could be undermined.
This is the second time ShinyHunters has breached Instructure in eight months. The September 2025 incident targeted Instructure's Salesforce environment through social engineering, a different attack class against different infrastructure. ShinyHunters is an extortion-as-a-service group with a documented history of voice phishing and social engineering for initial access, and security researchers note that the repeat hit suggests systematic targeting of education technology rather than a one-off.
Who is affected
ShinyHunters claimed nearly 9,000 institutions worldwide and around 275 million users, with roughly 3.65 terabytes of data, figures Instructure has not confirmed. Confirmed exposed data is limited to names, email addresses, student IDs, and some private messages, with no evidence that passwords, dates of birth, government IDs, or financial data were involved.
In the Netherlands, 44 educational institutions were affected, and several universities disconnected Canvas from their internal systems as a precaution. The practical risk for those institutions is not the loss of passwords, which were not taken, but the quality of the data that was: real names, real student IDs, and real private messages make for phishing that is far harder to spot than the generic kind.
What this means for your organisation
A few concrete takeaways, whether or not you run Canvas.
The breach you cannot prevent is the one inside your vendor. You can still prepare for it. Keep a current list of which SaaS platforms hold your people's data, and treat a vendor's breach history as a procurement signal. Two breaches of the same supplier in eight months is information, not noise.
Stolen contact data has a long tail. The immediate damage here is reputational and operational, but the lasting risk is targeted phishing. Attackers who hold a student's real ID and a real message thread can write a lure that looks entirely legitimate. Your staff and students will see those messages in the weeks ahead, not the day of the breach.
Notification is your responsibility, not your vendor's. Under the AVG you are the controller for your community's data. The vendor's statement does not discharge your duty to assess exposure and, where required, notify the Autoriteit Persoonsgegevens and the people affected.
The most useful thing you can do now is make sure your people can recognise the phishing this data enables. SecDesk runs phishing simulation and awareness campaigns built around the lures your organisation is actually likely to see. You can find that at secdesk.com/phishing-campaign.
Talk to a senior responder about Canvas data breach: how the ShinyHunters attack on Instructure reached Dutch universities.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders
