The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem
Months after a breach at Instructure, the company behind the Canvas learning management system, affected educational institutions are still waiting for individualized findings. As of early July, Instructure had only begun delivering the first wave of institution-specific data packets, with the forensic review dragging well past initial timelines.
Why this matters: Schools handed Instructure data on students — many of them minors — because they had no real choice. Canvas is everywhere in K-12 and higher education. When the vendor gets breached, institutions cannot fix it, investigate it, or even know what was taken without the vendor's cooperation. Months of waiting for a 'data packet' is not a security process most affected students or parents would recognize as accountability. This is what vendor lock-in looks like when something goes wrong: you wait in line to find out how badly you were exposed.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.