In spring 2026, Canvas, the learning management system operated by Instructure, suffered one of the largest security incidents reported in education technology. For institutions that run courses, assessments, and student records on Canvas, the breach raised an urgent question: how secure is the platform our learning depends on?
This article explains what happened, what data was affected, and what it means if your organization relies on Canvas. It also outlines the security criteria worth weighing when evaluating any learning platform, so you can make an informed decision rather than a reactive one.
TL;DR
- Between late April and May 2026, attackers accessed Canvas systems operated by Instructure. The group ShinyHunters claimed responsibility.
- Exposed data reportedly included names, email addresses, student ID numbers, and private messages. Instructure stated that passwords, birth dates, government IDs, and financial data were not involved.
- Public reporting put the scale at thousands of institutions and hundreds of millions of users worldwide, with outages affecting some final-exam periods.
- If you are reviewing your options, prioritize platforms with independently audited security: SOC 2 Type II, ISO 27001, and GDPR compliance.
What happened in the 2026 Canvas data breach
According to public reporting and Instructure's own disclosures, unauthorized actors accessed Canvas systems in late April 2026. Instructure detected the intrusion days later, revoked access, and engaged external forensics experts. In early May, the group ShinyHunters posted a ransom demand.
After Instructure indicated the situation was contained, a second intrusion followed in which the Canvas login page was replaced with a ransomware message. Instructure later announced an agreement with the actors and said the stolen data was destroyed. A class action lawsuit and a congressional inquiry followed. For an accessible summary of the timeline, see this overview from the National Cybersecurity Alliance.
What data was exposed
Instructure disclosed that the affected data included names, email addresses, student ID numbers, and messages exchanged between users. The company stated it found no evidence that passwords, dates of birth, government identification, or financial information were accessed.
Even without passwords or financial data, names, institutional email addresses, and student identifiers can be used for targeted phishing and social engineering, which is why many institutions treated the incident as material.
What it means for your institution
The breach coincided with end-of-term exams at some universities, which amplified the operational impact beyond data exposure alone. For administrators, the episode is a reminder that an LMS holds sensitive information and sits at the center of teaching operations, so its security and reliability are not secondary concerns.
A single incident does not automatically mean an institution should switch platforms. It does, however, make a clear case for reviewing your provider's security posture, incident-response track record, and the controls that protect your data day to day.
How to evaluate a more secure learning platform
Whether you stay with your current LMS or explore alternatives, these are the criteria worth checking:
- SOC 2 Type II and ISO 27001: independent, audited proof that security controls exist and are followed over time.
- GDPR compliance: clear handling of personal data, especially for institutions with users in the EU.
- Role-based access control: users only reach the data their role requires.
- A public trust center: transparent, up-to-date visibility into security controls and current status.
- Reliability and uptime: documented monitoring and a strong uptime record.
- Standards-based integration through LTI 1.3: the ability to connect to, or migrate from, existing systems without disruption.
Safer alternatives to consider
If you decide to evaluate other platforms, our full comparison of the best Canvas alternatives breaks down options for K-12, higher education, and corporate training.
Teachfloor is one option built with security and interoperability in mind. It is SOC 2 Type II and ISO 27001 certified and GDPR compliant, with role-based access control and a public trust center. Because it supports LTI 1.3, institutions can connect it alongside existing tools or move to it gradually rather than through a disruptive migration, which suits a complement-or-replace approach.
Other established platforms are worth comparing as well. For feature-level differences, see our detailed comparisons of Moodle vs Canvas and D2L vs Canvas.
Frequently asked questions
Is Canvas safe to use now?
Instructure has stated that it contained the incident and that the stolen data was destroyed under an agreement with the actors. Whether the platform meets your risk tolerance is a decision each institution should make based on its own security requirements and Instructure's ongoing disclosures.
Should we migrate away from Canvas?
Not automatically. Review your provider's security certifications, incident response, and reliability first. If gaps remain after that review, evaluate alternatives that offer audited security and standards-based migration paths.
What certifications should a secure LMS have?
At a minimum, look for SOC 2 Type II and ISO 27001, along with GDPR compliance for handling personal data.






