Data breach
Instructure (Partial)
- Records
- 2,310,689
- Breach date
- 10 October 2025Estimated
- Added
- 3 October 2025
What was exposed
3 types of data
- Email addresses1
- Home addresses1
- Phone numbers1
About this breach
Instructure, the Utah-based education technology company behind the Canvas learning management system, was caught up in the wave of intrusions that hit Salesforce customers in 2025. According to our investigation team, the listing covers a dataset of 2,310,689 rows drawn from the company's Salesforce environment, and the estimated breach date is October 10, 2025. The amounts of personal information in the dataset are not fully mapped, and no specific group is recorded as formally claiming it. Instructure itself disclosed in September 2025 that attackers used social engineering to reach its Salesforce instance, though the company said no Canvas product data was accessed. Reporting by BleepingComputer attributed the September incident to the extortion group ShinyHunters, which was behind similar attacks on other companies that year. The company has not confirmed how many individuals' records were exposed.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, and home addresses. Our investigation team has not determined how many records contain each type of information.
Instructure's own public statement about the September 2025 incident described the exposed material as largely publicly available business information, such as business names and contact details.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses, phone numbers, and home addresses are the raw material for targeted scams. Attackers can use them to send phishing emails that appear credible because they reference a person's real employer, school, or business relationship. Phone numbers open the door to smishing texts and voice-phishing calls, the same technique used to breach Salesforce environments in 2025. Home addresses carry a physical safety risk, particularly for people in public-facing or education-sector roles, and they are commonly used in identity-related fraud and unwanted contact.
Because the exact contents of this dataset are not fully documented, affected individuals should assume any of the listed data types could be in the hands of criminals and calibrate their caution accordingly.
What Is Instructure (Partial) Doing in Response?
Instructure said in a September 21, 2025 statement that it moved quickly to contain the activity, conducted an investigation with outside security experts, and notified federal law enforcement. The company said it implemented additional security measures to prevent similar incidents and stated that no Instructure products or product data were accessed. It committed to sharing further updates about anything that could affect customers.
Our investigation team has not verified any subsequent notice from the company addressed specifically to the individuals represented in this dataset.
What Should You Do If You Were Affected?
Watch for targeted phishing. Be skeptical of emails or texts that reference your employer, school, or a business relationship, especially any that ask you to approve logins, reset credentials, or open documents.
Do not act on unsolicited requests. Legitimate password resets and account alerts come through official portals, not through links in unexpected messages.
Verify callers. If someone claiming to be from IT, HR, or a vendor pressures you to approve access or share credentials, end the call and contact the organization through a known number.
Limit exposure of your home address. Review what is publicly visible about you and consider requesting removal from data broker sites if the address raises safety concerns.
Monitor your accounts. Check email and financial accounts for unusual activity and turn on multi-factor authentication wherever it is offered.
