Security Incident Update & FAQs

To our Instructure community,

I'll start where I should: with an apology.

Over the past few days, many of you dealt with real disruption. Stress on your teams. Missed moments in the classroom. Questions you couldn't get answered. You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that.

Here's what we know.

This incident involved unauthorized access to part of our environment. The data fields involved include information like usernames, email addresses, course names, enrollment information and messages. Core learning data (course content, submissions, credentials) was not compromised. We're still validating all findings, but we want to be clear about what we understand was and wasn't affected.

We also identified a vulnerability regarding support tickets in our Free for Teacher environment that was exploited. We temporarily disabled Free for Teacher while we complete a full security review. We know that's disruptive, and we didn't make that call lightly. But keeping the entire Canvas platform secure has to come first.

Last week, we made a call to get the facts right before speaking publicly. That instinct isn't wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates. You've been clear about that, and it's fair feedback. We will change that moving forward.

So here's what we're changing.

We've launched a dedicated Incident Update page, a single place with what we know, what we're doing, and what's next. We'll post another update within 48 hours and we're working on delivering a summary of the forensics report; which we'll share as soon as it's ready.

Two things you can count on right now:

  • Canvas by Instructure is fully operational and remains safe to use. Core learning data is not compromised.
  • We'll give you clear guidance if any action is required on your end. Right now, there's nothing you need to do.

Keep reaching out to your Customer Success teams and through our Community channels. Your feedback is shaping how we respond.

Rebuilding trust takes time. We're going to earn it back through consistent action and honest communication. We're in this for you and your community.

Thank you for your patience and for everything you do for learners.

Steve Daly CEO, Instructure


Parchment impact update - 5/13/26

Some questions have come in related to the potential impact on our Parchment product. We want to confirm that our Parchment product was not affected by the recent cybersecurity incident involving our Canvas platform. We have seen no evidence of lateral movement or unauthorized activity from Canvas to Parchment or any other Instructure products, and Parchment servers are distinct from those that support Canvas. Nevertheless, to provide additional confidence in our initial findings, we scanned the Parchment product for all known Indicators of Compromise associated with the actor responsible for the Canvas incident and found no indication of any unauthorized access.

As part of our response, we have rolled out CrowdStrike’s Falcon Endpoint Detection & Response tool across the Instructure network to provide 24/7 monitoring capabilities. CrowdStrike’s Falcon tool has not detected any ongoing unauthorized access to any Instructure product, including Parchment. Further, our forensic partners at CrowdStrike have found no evidence of system-layer access to Instructure systems that would facilitate any unauthorized activity beyond the Canvas platform. Nevertheless, we are continuing eyes-on glass, hands-on-keyboard monitoring of our environment as an additional layer of assurance.

All of the evidence outlined above underscores our firm belief that Parchment was not involved in this incident. As always, we appreciate your continued trust and support.


Please continue to reference https://www.instructure.com/incident_update for the latest information from us.

For information related to Parchment, please visit the Parchment Security Update and Customer FAQs.

Past Updates

Incident Overview

Customer Impact & Data Exposure

Security & Technical Guidance

Support & Next Steps

Status