惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
云风的 BLOG
云风的 BLOG
M
MIT News - Artificial intelligence
A
About on SuperTechFans
J
Java Code Geeks
量子位
博客园 - 三生石上(FineUI控件)
博客园 - Franky
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
IT之家
IT之家
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Instructure confirms cybersecurity incident
Anna Merod · 2026-05-08 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

The ed tech company that operates Canvas said information impacted by the data breach includes messages, names, email addresses and student ID numbers.

Published May 8, 2026

A digital depiction of a red triangle sign with an exclamation point in the center with binary code in the background.

Getty Images

First published on

K-12 Dive

Dive Brief:

  • A recent cybersecurity attack at Instructure ed tech company exposed certain student information, the ed tech company confirmed in a status update on its website Friday, but added in a Saturday update that it believes the incident has been contained.
  • Information impacted by the data breach includes messages between users, names, email addresses and student ID numbers, according to Instructure. The company said no passwords, dates of birth, government identifiers, or financial information were believed to have been compromised as of Saturday.
  • While Instructure said it is actively investigating the incident alongside forensics experts, the company has not disclosed how many school districts were affected.

Dive Insight:

Instructure, on its homepage, touts itself the “most-visited education website in the world.” The company operates several ed tech products for K-12 schools, including the widely used Canvas learning management system. 

Canvas has over 6 million “concurrent users,” according to Instructure’s website. Instructure did not explicitly say the breach had affected Canvas, but did report it was investigating disruptions to some Canvas tools and putting the learning management system under maintenance around the same time it announced the data breach. 

Upon request for comment and further details regarding the cybersecurity incident, Instructure told K-12 Dive in a Tuesday email to check the company’s status page, where it said updates on the breach would be provided as they become available. 

In response to the incident, Instructure said on its status page, the company has revoked privileged credentials and access tokens related to the affected systems, deployed patches to increase system security, and heightened monitoring across all of its platforms. 

The incident at Instructure marks the latest known data breach for a large ed tech vendor with sweeping implications for districts’ sensitive student and staff data.    

Other recent high-profile cyberattacks targeted PowerSchool, a cloud-based K-12 software provider, and Illuminate Education, a student information system provider. 

A Monday newsletter post by K12 Security Information eXchange, a K-12 cybersecurity nonprofit, said “small and medium businesses — including the majority of U.S. K-12 education software businesses — are frequent cybersecurity targets.” Some 59% of small and medium-sized enterprises experienced a cyberattack in the past year, according to research K12 SIX cited from Hiscox, an insurance company.

Ed tech companies are increasingly facing heightened accountability over cybersecurity from federal regulators and in the courts. In recent months, for example, the Federal Trade Commission reached a settlement with Illuminate over its 2021 data breach, while PowerSchool announced a $17.25 million settlement in the handling of student data on the Naviance platform. 

Although these cases are “likely to shape market behavior,” K12 SIX said, they “won’t do enough in and of themselves to stem the tide.”