Instructure Canvas Breach: 275 Million Students' Data Stolen, Linked to TeamPCP Campaign
How threat actors exfiltrated 275 million user records from Instructure Canvas in one of the largest educational data breaches in history.
This article is part of our Week of May 7, 2026 Security Roundup.
ShinyHunters claims to have stolen personal data for approximately 275 million users from Instructure's Canvas learning management system. The breach occurred around April 25, 2026 and affects virtually all US K-12 public schools, having been adopted statewide following a 2015 agreement.
What Was Compromised
Instructure confirmed that names, email addresses, student IDs, and user communications were exposed. Passwords, birth dates, government identifiers, and financial data were not involved. However, context-rich data — real school names, course names, teacher names — makes this extremely useful for targeted phishing against students, parents, and staff.
The TeamPCP Connection
Bitwarden subsequently confirmed the Canvas breach was linked to the Checkmarx supply chain campaign. The audit.checkmarx.cx C2 endpoint appeared in both incidents, suggesting credentials stolen during earlier TeamPCP phases were leveraged to reach Instructure's pipeline. This follows the same credential-cascading pattern from Trivy through LiteLLM, Bitwarden CLI, and now Canvas.
Why Education Is a Persistent Target
Limited budgets, millions of minors' PII, heavy SaaS reliance, and mixed device environments make education an ideal target. A single vendor compromise cascades instantly across thousands of districts. PowerSchool was breached in 2024. Canvas in 2026. The sector needs to be treated as critical infrastructure.
Immediate Actions
Force password resets for all affected accounts. Enable MFA on all portals. Brief staff on phishing using Canvas context. Monitor for credential stuffing against SSO and Google/Microsoft education accounts. Do not click links in breach notification emails — navigate directly to official district or Instructure sites.
References: Bitwarden supply chain link | Malwarebytes coverage | SecurityWeek | WRAL investigation