On April 29, 2026, Instructure detected unauthorized activity in its Canvas learning platform and publicly confirmed the breach two days later. ShinyHunters, a criminal extortion group, claimed responsibility on May 3, asserting the theft of 275 million user records and publishing a list of nearly 9,000 affected institutions, figures that have not been independently verified in full. On May 6, Instructure stated the incident had been resolved. The following day, users at hundreds of institutions encountered a ransom message on the Canvas login page.
The outage struck during finals week, stalling grade submissions and cutting off faculty-student communication. None of that resulted from a failure in any institution’s own security environment. It resulted from a failure at a vendor that those institutions depended on to operate.
Vendor dependency is an operational risk
Most organizations assess cybersecurity through what they directly control: firewalls, endpoint protection, and access policies. Fewer have mapped what happens when a vendor they depend on is the one that fails.
A law firm dependent on a document management system faces direct operational exposure when that platform goes offline during a trial deadline. A construction firm coordinating subcontractors loses that coordination the moment its project management tool becomes unavailable. An accounting practice running client workflows through cloud applications has no workaround when those applications fail during a filing period. The organization’s own security posture is not the variable. Vendor availability is.
Prior incidents do not guarantee future security
The May 2026 attack was not Instructure’s first. According to public reports, the company disclosed a separate breach in September 2025 involving a third-party Salesforce instance. When Instructure reported on May 6 that the situation was resolved, that statement was contradicted within 24 hours. A vendor’s “resolved” notification reflects what they know at the time of writing, not a guarantee. Organizations that stand down their contingency measures on that basis are working from an incomplete picture.
Most continuity plans have a structural gap
Business continuity planning typically addresses scenarios the organization controls directly: ransomware on internal servers, hardware failure, and a location going offline. Vendor platform outages rarely appear on that list, even when their operational impact exceeds most internal failures.
Leadership teams should be able to answer three questions about every operationally critical vendor:
- Which vendors are critical enough that their unavailability stops a core business function?
- How long can each of those functions operate without them?
- What manual or alternative processes exist in the interim?
That exercise does not require an IT department. It requires a decision to treat vendor risk with the same rigor applied to internal risk.
Communication is a contingency function
After the May 7 outage, Instructure’s status page showed no active incidents while users were encountering ransom messages. When vendor communications fail, your organization is still responsible for its own stakeholders. Without a protocol specifying who communicates, what is said, and on what cadence, the default during a vendor disruption is silence or improvisation. Both carry costs.
The broader lesson
Operational resilience depends on more than protecting your own environment. When a vendor experiences a disruption, the business impact falls on the organizations using them, regardless of who caused it. Identify which systems your organization cannot operate without and determine what happens if each becomes unavailable for 24, 48, or 72 hours. That exercise surfaces risks that standard security assessments frequently miss, because it focuses on operational exposure rather than perimeter defense.
Stay a step ahead. Join business leaders who get our monthly IT insights: straight talk on the decisions that protect operations, reduce risk, and keep technology working for your business.
Subscribe to our Newsletter
Keep reading:
Why IT Problems Hit Some Businesses Harder Than Others