Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Security

The 275 million figure in the Canvas breach comes from the attackers, and it may not count people at all

Instructure has confirmed that names, email addresses, student ID numbers and user messages were taken from Canvas. It has not confirmed the attackers' totals. The House Homeland Security Committee chairman wrote that the company itself describes Canvas as serving more than 30 million active users worldwide.

Nile.University Computer Laboratory 05
Nile.University Computer Laboratory 05. Photograph: Chris Ikpemi, CC BY-SA 4.0

The Canvas learning management system, operated by Instructure, was breached twice in the space of about a week in 2026 and the incident is routinely described as the largest in the education sector on record, affecting 275 million users. That figure did not come from Instructure. It came from the extortion group that carried out the attack, and the versions in circulation do not even agree with each other.

BleepingComputer, reporting on 12 May 2026, records the ShinyHunters claim as 280 million data records taken from 8,809 colleges, school districts and online education platforms. The figure repeated elsewhere, and in the Wikipedia account of the incident, is roughly 275 million users and 3.65 terabytes of data. Records and users are not the same unit. A single student generates many records across enrolments, messages and course objects.

The scale of the platform is the check. In its letter to Instructure dated 11 May 2026, the chairman of the House Committee on Homeland Security, Andrew R. Garbarino, described the affected service as "a platform that Instructure itself describes as serving more than 30 million active users globally", and said that ShinyHunters "has claimed the incident involves data associated with hundreds of millions of users across nearly 9,000 institutions, though the full scope of the breach remains under investigation". Instructure has not published a count of affected individuals.

What the company has confirmed is narrower and, for school age users, serious. Instructure said the data involved names, email addresses, student identification numbers, and messages exchanged between users, and that it had found no evidence that passwords, dates of birth, government identifiers or financial information were involved. A technical advisory published by Bitdefender on 8 May 2026 sets out those confirmations and states plainly that the attacker's figures remain unverified.

The dates are contested. The Wikipedia account, drawing on reporting by the Los Angeles Times, The New York Times and others, says unauthorised actors accessed Canvas systems on 25 April 2026, that Instructure detected the intrusion four days later, and that it disclosed the incident on its status page on 1 May. BleepingComputer says detection on 29 April and public disclosure on 3 May. Garbarino's letter says the group "first struck on May 1". All accounts agree on the second event: on 7 May 2026 the login pages of hundreds of institutions were replaced with a ransom message. The Register, on 12 May 2026, reported that both intrusions exploited cross site scripting weaknesses in Canvas Free-for-Teacher software, which gave the attackers administrative access, and that the outage landed during final examinations and Advanced Placement testing. Not everyone reads the first intrusion the same way. Security practitioners quoted by SC Media on 13 May argued that the first and more damaging breach was an identity compromise involving privileged access or stolen credentials, and that the cross site scripting defacement came later. Instructure has said only that the actor exploited an issue related to Free-for-Teacher accounts.

On 11 May Instructure apologised on its incident update page for its lack of transparency, and in the same statement said it had reached an agreement with the unauthorised actor and had received digital confirmation of data destruction, described as shred logs. Whether money changed hands has not been stated by the company. TechCrunch, on 13 May 2026, reported that a ShinyHunters representative declined to say how much had been paid. A figure of ten million US dollars circulates as an unconfirmed rumour and should be treated as one.

The consequences are running on two tracks. A proposed class action was filed against Instructure on 13 May 2026 in the United States District Court for the Southern District of California on behalf of a San Diego resident. Garbarino asked Instructure's chief executive, Steve Daly, or a senior representative, to brief his committee no later than 21 May 2026 on the circumstances of both intrusions, the nature and volume of data accessed, the steps taken to contain the threat and notify institutions, and the adequacy of the company's coordination with federal law enforcement and the Cybersecurity and Infrastructure Security Agency. TechCrunch, correcting its own report on 14 May, noted that the committee was seeking a closed door briefing rather than public testimony. His letter also placed the attack in a pattern, naming earlier ShinyHunters claims against Ticketmaster and AT&T and against the education targets Infinite Campus and McGraw Hill.

The reach was international. Institutions in the United Kingdom, Canada, New Zealand, Australia, Sweden, the Netherlands, Hong Kong and Singapore reported disruption or potential exposure. In Australia the National Office of Cyber Security coordinated a response and several universities offered assignment extensions. Queensland's education minister, John-Paul Langbroek, said the attack could have affected the data of 200 million people, another unverified figure repeated by an official.

What is still not known is how many distinct people had data taken, whether the deleted copy was the only copy, whether the closed briefing occurred, and what the committee was told. Until Instructure publishes a count, the largest education breach on record is measured by a number its victim has never stood behind.

Sources

Every factual claim above rests on the 7 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. U.S. House Committee on Homeland SecurityChairman Garbarino Seeks Information from Canvas Developer After Cyberattacks Impact Schools and Universities Nationwide
  2. BitdefenderTechnical Advisory: ShinyHunters Breach of Instructure Canvas LMS
  3. BleepingComputerUS govt seeks Instructure testimony on massive Canvas cyberattack
  4. The RegisterCongress investigates Canvas breach after Instructure cuts deal with ShinyHunters
  5. TechCrunchUS lawmakers demand answers from Instructure after Canvas data breaches
  6. Wikipedia2026 Canvas data breach
  7. SC MediaHouse committee chair calls on Instructure to testify in Canvas hack

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.