Will Instructure be subject to another major hack before September 1, 2026?
Predict: Follow
Chance: 15%
5% this week
Top Key Factors
Copycats may target Instructure after breach
Likelihood increases by 20Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure
Likelihood increases by 10CrowdStrike is hardening Instructure's security
Likelihood decreases by 20
Comments
User: jordan1casady
Date: 2 weeks ago (May 28, 2026)
I’m at 22%.
The question is whether Instructure gets hit by another major hack, but I think the key issue is whether the remaining post-breach risk stays inside Instructure/Canvas itself or shifts into the surrounding school ecosystem.
The main thing I’m watching is whether there is still an exploitable Instructure-controlled path large enough to meet the question’s “major hack” threshold. After the recent Canvas incident, I expect a lot of the pressure to move outward first: school-side integrations, API keys, SSO setups, phishing, third-party tools, and institution-level cleanup problems.
...
User: WasteTimeContinuum
Date: 3 weeks ago (May 24, 2026)
Initially, I incorrectly framed this as implying another ShinyHunters strike. My knee-jerk reaction was to go to 25–30% on this one, because Instructure has been breached twice in eight months, paid a rumored $10M ransom, and just had 275 million records and 3.65TB of data walk out the door.
...
User: darkives
Date: May 14, 2026
Thanks for the question! I made a few small edits.
Key Factors Summary
- Copycats may target Instructure after breach (Increases Likelihood: 20)
- CrowdStrike is hardening Instructure's security (Decreases Likelihood: 20)
- Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure (Increases Likelihood: 10)