Instructure Canvas: Free-For-Teacher path, ShinyHunters claim, AU campuses offline
Instructure detected unauthorised activity in Canvas on 29 April 2026 and a second access on 7 May 2026 that changed pages some students and teachers saw after login. The vendor says both used a Free-For-Teacher account path, took Canvas into maintenance, remediated the privilege-escalation routes, and permanently discontinued Free-For-Teacher. Fields named on the vendor FAQ include usernames, email addresses, course names, enrolment information, and messages; Instructure says core learning data (course content, submissions, credentials) was not compromised, and the US Education Department FSA alert (12 May, updated 29 May) repeats that there is no evidence passwords, dates of birth, government identifiers, or financial information were exposed. ShinyHunters claimed the campaign; Instructure later said it reached an agreement with the unauthorised actor, that data was returned with shred logs, and that customers should not engage the actor. SMH (13 May) put the haul at roughly 3.65 TB across 8809 institutions worldwide, including at least 122 in Australia; Trend Micro separately counted 122 Australian institutions among 8809. Patch posture for customers: rotate Canvas integrations, LTI tools, SSO connectors, and API keys; review logs for 25 April–8 May 2026.
- Product
- Instructure Canvas LMS (Free-For-Teacher path)
- Exploited in Australia?
- yes
- Patch to
- Rotate Canvas integrations, LTI, SSO, and API keys; review auth and integration logs for 25 Apr–8 May 2026; Free-For-Teacher discontinued
Primary: Instructure Security Incident Update & FAQs · Vendor: Instructure · US Dept of Education FSA alert (12 May 2026; updated 29 May)
