All settlements
Upcoming

Instructure, Inc. (Canvas Learning Management)

Instructure Canvas Data Breach Sparks Lawsuits Over Exposed User Info

Proposed class actions claim Instructure failed to secure Canvas users' names, emails, student ID numbers, and private messages after a 2026 cyberattack tied to the ShinyHunters group. No settlement has been reached yet.

Key facts

Claim deadline
No deadline listed
Potential payment
Payment varies
Proof listed
No proof requirement listed
Status
Upcoming

Plain-language overview

Who may qualify?

Eligibility depends on the dates, products, locations, and other terms listed for this claim. Review any criteria below and the official terms before deciding whether it may apply to you.

Case overview

What this settlement is about

Instructure, maker of the Canvas learning management system, is facing multiple proposed class action lawsuits after cyberattacks reported in late April and May 2026 allegedly exposed user data. The attacks are said to be linked to the ShinyHunters threat group and may have given unauthorized parties access to names, email addresses, student ID numbers, and messages exchanged between users. Instructure says passwords, dates of birth, government ID numbers, and financial information were not compromised, and that it later struck an agreement under which the stolen data was reportedly destroyed.

The lawsuits, filed in U.S. courts on behalf of affected users — including parents of K-12 students and other individuals whose information was allegedly exposed — argue that Instructure failed to use reasonable data security measures, did not adequately safeguard sensitive personal information (including data belonging to minors), and failed to give timely or adequate notice of the breach. Instructure denies any wrongdoing.

Importantly, no settlement exists at this stage. The litigation remains in court rather than arbitration, and no rulings have been finalized. Plaintiffs are seeking monetary damages as well as injunctive relief, such as stronger data security practices and measures like data deletion or added protections for those affected.

Right now, there is no settlement program, no claims process, and no approved compensation or benefit available to affected users.