What happened, briefly
Unauthorized access to Instructure's Canvas systems began on April 25, 2026 and was detected four days later. An extortion group later published ransom demands and briefly defaced login pages, and Canvas went down for a period during final exams. On May 11 Instructure said it had reached an agreement with the attacker and that the copied data had been destroyed: a claim that, by its nature, nobody outside can verify.
The scale reported is roughly 275 million records across about 8,800 institutions. Canvas is used by something like 40% of American schools, so "was my district affected?" is close to the wrong question. Several Florida districts confirmed they were, including Orange County Public Schools, which notified families directly.
What was taken, and what wasn't
This distinction matters more than the headline number, because it changes what you should actually do.
Reported as taken: names, email addresses, student ID numbers, course names, enrollment information, and messages sent inside Canvas.
Reported as not involved: passwords, dates of birth, government-issued IDs, and financial information. Instructure has stated it found no evidence any of these were affected.
So this is not, mainly, a password emergency. It is a credibility emergency. Someone who has never met your family can now write to you knowing your child's real school, their real course names, and a real teacher's name. That is what makes the next email convincing.
The ten-minute audit worth doing this week
None of this requires technical skill, and all of it is worth doing whether or not you ever use a service like ours.
1. See which apps can reach your Canvas account
Sign in to your district's Canvas in a browser, not the app, then open Account → Settings and scroll to Approved Integrations. Every third-party token ever issued against your account is listed there, with the date it was last used.
Anything you don't recognize, or haven't used in a year, should go. Each entry has a delete button and revoking is immediate. Do this on your own parent or observer account, then have your student do it on theirs: students accumulate far more of these than parents do.
2. Change the Canvas password anyway
Passwords weren't reported as taken, but if your child reuses that password anywhere else, this is a reasonable moment to stop. Reused passwords are how a breach in one place becomes a problem in another.
3. Treat school email as suspect for a while
The realistic attack here is a message that knows your child's teacher and course, asking you to sign in about a grade, a fee, or missing work. The defense is boring and effective: never sign in from a link in an email. Open Canvas or the district portal by typing the address yourself. A real notice will still be there when you arrive.
If your parent access broke recently, this is probably why
As part of its response, Instructure revoked access tokens and rotated keys, and asked institutions to re-authorize their integrations. If your observer link, a pairing code, or a connected app stopped working somewhere between May and now, that is a likely and unalarming explanation.
The fix is the ordinary one: generate a fresh pairing code and reconnect. We wrote up the usual causes and the exact steps in Canvas pairing code not working? Here's the fix. If you're in Orange County, the district-specific walkthrough is in OCPS Canvas for parents, and if you're weighing this against the official app, we compared them in ByBedtime vs the Canvas Parent app.
Where we stand, since we're asking for the same access
It would be strange to write this page without addressing the obvious: ByBedtime asks parents to connect their Canvas account. After a breach, that deserves a straight answer rather than a reassuring one.
We never ask for a school password. Not your child's, not yours. If any service asks for a school login, that alone should end the conversation.
Our access is read-only and parent-authorized. We read assignment and grade information through the access you grant. We cannot submit work, message a teacher, or change anything in Canvas.
You can revoke us in under a minute, without asking us. It's the same Account → Settings → Approved Integrations screen described above. Delete the entry and our access is gone immediately: no email, no support ticket, no waiting on us to do it. We think that's the property that actually matters, and it's the one we'd tell you to demand of any tool you connect, including this one.
You can read exactly what we store, and what we deliberately don't, on our security page and in our privacy policy, and who is behind this on our about page.
Questions parents are asking
Was my child's password stolen in the Canvas breach?
Instructure has said it found no evidence that passwords, dates of birth, government IDs or financial information were involved. What was taken includes names, email addresses, student ID numbers, course names, enrollment information and in-Canvas messages. Changing the password is still sensible hygiene, but the breach is primarily a phishing problem, not a password one.
Is it safe to connect a third-party app to Canvas now?
It depends entirely on what the app can do and whether you can revoke it yourself. Ask three things: does it need your school password (it never should), is its access read-only, and can you revoke it from your own Canvas settings in under a minute without contacting anyone. If you can't answer all three, don't connect it. Any honest service will be glad to tell you how to remove it.
How do I see which apps have access to my Canvas account?
In a browser, sign in to your district's Canvas, then open Account → Settings and scroll to Approved Integrations. Every third-party token issued against your account is listed with the date it was last used, and each has a delete button that revokes it immediately.
Why did my Canvas pairing code or parent link stop working after the breach?
Instructure revoked tokens and rotated keys during its response and asked institutions to re-authorize integrations. A link that broke between May and now was very likely caught in that, and it isn't a sign that something is wrong with your account. Generate a fresh pairing code and reconnect.
What should I actually watch for after the Canvas breach?
Email that knows too much. The stolen data lets a stranger write to you using your child's real school, real course names and a real teacher's name. Treat any message about grades, fees, missing work or account problems as suspect if it wants you to click through and sign in. Go to Canvas directly instead.
Once your access is tidy, put it to work
ByBedtime checks Canvas on a schedule and sends one calm evening brief: new grades, missing work, and what is due tomorrow. Read-only, no school password, and revocable by you at any time from your own Canvas settings.
Start your free trialCreate your account without a card. Your 14-day trial begins only after the first successful Canvas sync.
ByBedtime is an independent service and is not affiliated with, endorsed by, or partnered with Instructure, "Canvas," or any school district. Canvas is a trademark of Instructure, Inc., used here only to describe compatibility. This page summarizes publicly reported information about a security incident at Instructure as of August 2026; it is not legal or security advice, and the authoritative source on what was affected at your child's school is your district and Instructure's own notices. Details may change as investigations continue. ByBedtime reads assignment information through parent-authorized, read-only access and never collects a school password.