HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Instructure Pays Ransom After 3.65 TB Canvas Data Leak Threatens Thousands of Schools

Instructure, the Canvas LMS provider, confirmed a ransomware extortion that resulted in the theft of 3.65 TB of student and staff data. The company reached a ransom agreement to stop the data from being published, raising serious third‑party risk concerns for educational institutions that rely on the platform.

LiveThreat™ Intelligence · 📅 May 12, 2026· 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Instructure Pays Ransom to Stop 3.65 TB Canvas Data Leak Affecting Thousands of Educational Institutions

What Happened — Instructure, the parent of the Canvas learning‑management system, confirmed that a decentralized extortion group accessed its network, exfiltrated approximately 3.65 TB of data, and threatened public release. The company reached a ransom agreement to prevent the leak.

Why It Matters for TPRM

  • Large‑scale student and staff personal data exposure can trigger regulatory fines and reputational damage for partner institutions.
  • Third‑party risk assessments must account for the vendor’s ability to detect, contain, and remediate ransomware incidents.
  • Ongoing reliance on a compromised SaaS platform may affect continuity of academic operations.

Who Is Affected — Higher‑education institutions, K‑12 school districts, and any organization that uses Canvas for course delivery.

Recommended Actions

  • Review Instructure’s incident‑response and data‑protection controls.
  • Verify that contractual clauses address breach notification, data encryption at rest, and ransomware response.
  • Conduct a supplemental risk assessment for any downstream integrations (e.g., SIS, analytics tools).

Technical Notes — The breach appears to have been driven by stolen credentials that enabled lateral movement and mass data exfiltration. No specific CVE was disclosed. Exfiltrated data includes student records, grades, email addresses, and potentially payment information. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.