Recently, the threat group known as ShinyHunters breached Instructure, the company behind Canvas, and made off with student records affecting institutions across the country. ShinyHunters is a well-documented, financially motivated group with a long history of large-scale data theft and extortion, previously linked to breaches at Ticketmaster, Santander Bank, and AT&T. Their playbook typically involves compromising credentials or session tokens, moving laterally through connected systems, and exfiltrating bulk data before detection. In the Canvas case, early indicators point to abuse of a third-party integration, which is a common and often overlooked attack surface in learning management systems.
Canvas does not exist in isolation. Most districts connect it to their student information system, their single sign-on provider, and various instructional tools. Each of those connections is a trust relationship, and any one of them, if credentials are compromised or access is misconfigured, can be used as an entry point without ever touching Canvas authentication directly. It’s a pattern that repeats across cloud-hosted education platforms precisely because those integrations are set up once and rarely reviewed.
The Student Data Specific Problem
Student data is not credit card data. You cannot cancel it and reissue it. Student records contain birthdates, home addresses, parent contact information, disability and accommodation records, disciplinary history, and in many cases, Social Security numbers collected for federal aid verification. This data doesn’t expire. A student whose record is stolen at age 12 may not encounter the consequences until they apply for a car loan at 22.
The breach of Canvas is particularly damaging in the education context because of what the Family Educational Rights and Privacy Act (FERPA) does and does not require. FERPA prohibits unauthorized disclosure of student records and gives parents and eligible students the right to be notified when records are shared without consent. But the law was written long before cloud-hosted platforms existed. It has no mandatory breach notification deadline and sets no minimum-security standard for how institutions must protect student data. When a school district is breached, the legal question of what to disclose and when is being resolved in real time, alongside the technical question of what was actually accessed, often by people who have never navigated either.
Why Commercial Solutions Miss the Mark
The cybersecurity industry has built its breach response playbooks around financial services and healthcare, where PCI-DSS and HIPAA have created well-worn incident response procedures. Education has no equivalent framework. Commercial breach response vendors offer services built for enterprises with legal teams, PR departments, and retainer agreements already in place. A rural school district with 3000 students, one IT administrator, and no dedicated security staff has none of those resources.
The other gap is logging. Most districts have no centralized record of what their Canvas instance is doing. Canvas does maintain audit logs of user activity, data exports, and API calls, but many districts are not collecting those logs anywhere outside the platform. When a breach occurs and a forensic team asks which student records were accessed and over what timeframe, the honest answer for most districts is that they don’t know and may never know because the logs no longer exist.
What to Do Now
The time to answer the hard questions is before the phone call comes, not after. Here’s where to focus.
Know your data map.
Pull up your Canvas configuration and document what student data is actually stored there. Some districts store minimal information inside Canvas itself. Others have connected it to their student information system and have effectively made their full records database one hop away from the LMS. If you don’t know what data Canvas holds, you can’t tell families what was exposed. Do this before your next board meeting.
Check your integration inventory.
List every third-party tool connected to your Canvas instance, including LTI tools, SSO providers, and any automated data sync with your SIS. For each one, ask when the access was last reviewed, whether the permissions are scoped appropriately, and whether you have logs of what that integration is doing. Stale or over-permissioned integrations are how attackers move between systems without triggering obvious alerts.
Get your logs off the platform.
If Canvas activity logs exist only inside Canvas, you have a single point of failure for your incident evidence. Work with your IT staff or managed security provider to export and retain those logs in a separate system. You want at least 12 months of login events, data export records, and API activity available if you ever need to reconstruct what happened and when.
Fix your vendor contract language.
Your data processing agreement with Instructure and any LMS you evaluate in the future should clearly state what student data the vendor stores, where it’s stored, how long it’s retained, and how quickly they’ll notify you in the event of a breach. Some vendor agreements use 30-day notification windows buried in boilerplate language. That’s not acceptable when you have an obligation to families. Push for 48 to 72 hours.
Run a tabletop exercise before you need it.
The worst time to design your incident response process is under pressure with media calling. A 90-minute tabletop exercise with your superintendent, IT lead, legal counsel, and communications staff walking through a breach scenario will surface gaps in your communication plan, your notification triggers, and your internal escalation path. nuHarbor has run these for under-resourced organizations before and the value is almost always in what the conversation reveals, not the exercise itself.
We have written about managing communications during an incident before, and this guidance still applies: 10 Things You Must Do to Protect Your Brand During a Cybersecurity Incident.
If You Are a Parent
If your child’s school has notified you of involvement in the Canvas breach, start by requesting a child identity protection freeze through all three credit bureaus: Equifax, Experian, and TransUnion. A minor’s Social Security number typically has no credit file attached to it, which means fraud can go undetected for years. A freeze prevents any new file from being opened in their name. It’s free, takes about 15 minutes per bureau, and is the single most effective thing a parent can do right now. Beyond that, hold on to the breach notification letter your school or district sends, because that’s your documentation if fraud surfaces later. Check whether your district or state has offered any identity monitoring services as part of their breach response, take them up on it even if the monitoring window feels short, and set a calendar reminder to check your child’s credit file the year they turn 18. That first check matters more than any monitoring service active today.
Procurement Guidance for Future Evaluations
School districts evaluating any student-facing platform should require vendors to provide a data processing agreement before signing. It should define what student data is stored, where, and for how long. It should address sub-processor relationships (the other vendors the LMS relies on), and it should include a breach notification timeline measured in hours, not weeks. Vendors who can’t produce a current SOC2 Type II report or a recent penetration test summary on request should be treated as a procurement risk. And a SOC2 report doesn’t necessarily mean their security posture is good; it means they’re doing what they say they’re doing, and an independent firm has verified it. You need to read the SOC2 report and understand what security controls are in place.