An attacker claims to have exfiltrated 275 million records from over 8,800 educational institutions, potentially exposing student, faculty, and staff personal data at scale — triggering mandatory breach notification obligations under FERPA, state laws, and GDPR for institutions serving EU-based users. The portal defacement, timed to finals week, disrupted course access and assessment workflows at a moment of maximum operational sensitivity, with direct impact on academic continuity and institutional credibility. Unresolved extortion demands create additional legal and financial exposure, and institutions that delay response risk a second wave of disruptive action before the May 12, 2026 deadline.
You Are Affected If
Your institution uses Instructure Canvas LMS in any deployment configuration, including the Free-for-Teacher environment
Your Canvas instance has internet-facing login portals without a WAF configured to detect and block XSS payload variants
Canvas administrator accounts are not protected by multi-factor authentication or IP-restricted access
Your Canvas environment has not received a vendor-issued patch or server-side mitigation for CWE-79, CWE-87, or CWE-116 since May 7, 2026
Your institution stores student, faculty, or staff personal data within Canvas that would be accessible via a compromised administrator session
Board Talking Points
A threat actor breached Canvas LMS — the platform used by thousands of schools globally — and claims to have stolen 275 million student and staff records, including data potentially belonging to our institution.
We are assessing our exposure now and working with Instructure to apply available mitigations; a full status report will be ready within 24 hours.
Without immediate action, we face regulatory breach notification obligations, potential extortion escalation before May 12, and disruption to ongoing academic operations during finals week.
FERPA — Canvas LMS stores student educational records; unauthorized exfiltration of administrator-accessible data directly implicates FERPA obligations for U.S. educational institutions
GDPR — Institutions with EU-based students or staff face breach notification requirements within 72 hours of confirmed awareness under Article 33
State Breach Notification Laws — Institutions in U.S. states with personal data breach notification statutes must evaluate notification timelines based on the data types accessible via compromised Canvas administrator sessions
COPPA — Institutions serving students under 13 using Canvas face heightened obligations if children's personal data was included in the exfiltrated records