Latest Update: 7/21/2026
To our Instructure Community,
Last week we paused data delivery while we assessed a security threat disclosed against ShareFile, the secure third-party data-delivery platform. To be clear: this threat did not involve Canvas or any Instructure systems, and your data was never at risk. ShareFile communicated the threat was only to its on-premise servers, entirely separate from the cloud infrastructure we will use. We're confident moving forward, and data delivery will start next week after InstructureCon.
See below for the updated timeline.
- Wednesday, July 22 at 5 pm ET: Add your security contact(s) to Canvas. If you've already done this, you're all set. Here's how to add a security contact. If you add a contact after this date, you will receive your data in a subsequent delivery.
- Beginning Sunday evening, July 26: If user and provisioning data were exfiltrated from your institution, your security contact(s) will receive a secure link to a ShareFile folder, followed by a confirmation email from Instructure.
- July 29–31: Join us for a live webinar for an overview of the data files that were delivered and to answer any questions. Register for a webinar here.
As a reminder, if you determine that notice is required for your institution’s end users, Instructure will coordinate notifications of your users on your organization’s behalf through our third-party consultant, Kroll.
For customers whose exfiltrated data included DAP messaging, that unstructured data is still undergoing forensic review. We are currently targeting a delivery of late September, if this process takes longer, we will update you accordingly.
Thank you for your patience. Protecting your data comes before any timeline, and we're moving forward because we're confident in the path ahead.
Past Updates
Incident Overview
Status