Will Instructure be subject to another major hack before September 1, 2026?

Predict: Follow

Chance: 15%
5% this week

Top Key Factors

  1. Copycats may target Instructure after breach
    Likelihood increases by 20

  2. Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure
    Likelihood increases by 10

  3. CrowdStrike is hardening Instructure's security
    Likelihood decreases by 20


Comments
User: jordan1casady
Date: 2 weeks ago (May 28, 2026)

I’m at 22%.
The question is whether Instructure gets hit by another major hack, but I think the key issue is whether the remaining post-breach risk stays inside Instructure/Canvas itself or shifts into the surrounding school ecosystem.
The main thing I’m watching is whether there is still an exploitable Instructure-controlled path large enough to meet the question’s “major hack” threshold. After the recent Canvas incident, I expect a lot of the pressure to move outward first: school-side integrations, API keys, SSO setups, phishing, third-party tools, and institution-level cleanup problems.

...


User: WasteTimeContinuum
Date: 3 weeks ago (May 24, 2026)

Initially, I incorrectly framed this as implying another ShinyHunters strike. My knee-jerk reaction was to go to 25–30% on this one, because Instructure has been breached twice in eight months, paid a rumored $10M ransom, and just had 275 million records and 3.65TB of data walk out the door.

...


User: darkives
Date: May 14, 2026

Thanks for the question! I made a few small edits.


Key Factors Summary