← Back

Wire · opportunities

The Breach That Won't End: An Update on Canvas, and how they created an EdTech's ...

Published

16 July 2026

Topic

opportunities

Sectors

Digital Health

Geography

United States

Source

Read at databreaches.net

Verified

Fusion42 · 16 July 2026 · Fusion42 review

Instructure's forensic response to a second breach in eight months has stalled after the third-party platform chosen to deliver sensitive customer data itself became a security risk, compounding legal exposure and exposing systemic gaps in vendor privilege management across education institutions.

This Wire brief sits within Fusion42's coverage of Digital Health.

◆ The Wire takeaway

If you sell identity, access control, or audit tools to schools and universities, Canvas just became your customer's nightmare scenario—they've now been breached twice through different attack surfaces in eight months, and their own incident response created a third exposure point. Every institution running Canvas now has a credible business case to replace their access and logging infrastructure; the vendor trust is broken and regulators are watching.

Coverage

1 source · 16 Jul 2026

Related on Wire

Topics

Digital Healthbreach-responsevendor-trustedtech-securitysupply-chain-riskcanvas-instructure