Instructure Canvas Breach: 275 Million Students' Data Stolen, Linked to TeamPCP Campaign

How threat actors exfiltrated 275 million user records from Instructure Canvas in one of the largest educational data breaches in history.

Students in a classroom representing the Instructure Canvas data breach affecting 275 million users
📌
Security Roundup Series: Week of May 7, 2026 • 4 min read deep dive
🏛️
Incident Overview: Victim / Target: Instructure Canvas LMS Exposed Records: 275 Million Student & Faculty Records Impact: PII, gradebooks, email directories across US K-12

This article is part of our Week of May 7, 2026 Security Roundup.

ShinyHunters claims to have stolen personal data for approximately 275 million users from Instructure's Canvas learning management system. The breach occurred around April 25, 2026 and affects virtually all US K-12 public schools, having been adopted statewide following a 2015 agreement.

What Was Compromised

Instructure confirmed that names, email addresses, student IDs, and user communications were exposed. Passwords, birth dates, government identifiers, and financial data were not involved. However, context-rich data — real school names, course names, teacher names — makes this extremely useful for targeted phishing against students, parents, and staff.

The TeamPCP Connection

Bitwarden subsequently confirmed the Canvas breach was linked to the Checkmarx supply chain campaign. The audit.checkmarx.cx C2 endpoint appeared in both incidents, suggesting credentials stolen during earlier TeamPCP phases were leveraged to reach Instructure's pipeline. This follows the same credential-cascading pattern from Trivy through LiteLLM, Bitwarden CLI, and now Canvas.

Why Education Is a Persistent Target

Limited budgets, millions of minors' PII, heavy SaaS reliance, and mixed device environments make education an ideal target. A single vendor compromise cascades instantly across thousands of districts. PowerSchool was breached in 2024. Canvas in 2026. The sector needs to be treated as critical infrastructure.

Immediate Actions

Force password resets for all affected accounts. Enable MFA on all portals. Brief staff on phishing using Canvas context. Monitor for credential stuffing against SSO and Google/Microsoft education accounts. Do not click links in breach notification emails — navigate directly to official district or Instructure sites.


References: Bitwarden supply chain link | Malwarebytes coverage | SecurityWeek | WRAL investigation


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther