If you use Canvas as part of your work with Braven, you may have heard about a security incident affecting Instructure, the company that runs Canvas. We’ve been tracking this closely since it began, and we now have enough confirmed information to give you the full picture: what happened, what it means for you specifically, how we’ve responded, and what we’re doing going forward.
We know a message like this can be unsettling. Our goal here is to be as clear and complete as possible, so you have what you need without guesswork.
In late April 2026, Instructure discovered that an unauthorized party had gained access to its systems. Instructure has publicly attributed the intrusion to a hacking group known as ShinyHunters, a group that has been linked to a number of large-scale data breaches at other companies and institutions over the past two years — this was not their first incident, and not Instructure’s first encounter with this group either.
Here’s how it unfolded, based on Instructure’s public disclosures:
This was a large-scale incident. Reporting indicates the exposure affected data connected to thousands of schools and organizations that use Canvas, not just Braven. Instructure’s official updates on this incident are available here.
Because this incident affected Instructure’s systems broadly, it took time before individual organizations — including Braven — could get confirmation of exactly what data of theirs, specifically, was involved. Instructure committed to delivering an individualized data report to every affected institution, and that process was delayed multiple times, most recently in mid-July due to a separate security concern with the third-party platform being used to deliver the data.
That delivery process is now complete for Braven. Here is what we know:
What was involved: A list of Braven’s Canvas users — students, volunteers, and staff — including:
What was not involved: No passwords, dates of birth, Social Security numbers, or financial information were part of this exposure, for Braven or more broadly across Instructure’s customer base, according to Instructure’s confirmed findings.
We want to be direct about what this means in practice: your name, email, and course enrollment being exposed does not give anyone access to your accounts. But it does mean you may be a more likely target for phishing attempts — messages designed to look like they’re from Braven, Instructure, or a partner school, trying to trick you into sharing information you shouldn’t. More on that below.
From the moment this incident became public, we made a decision to follow the facts rather than react to speculation. In the early days, unverified lists claiming to show affected institutions circulated online, and Braven’s name appeared on some of them before we had any confirmation from Instructure directly.
Since then, we’ve taken concrete steps to reduce risk going forward, independent of anything Instructure does on its end:
We also worked directly with individual partner schools whose own security teams reached out with questions, to make sure they had accurate, Braven-specific answers rather than general public statements.
Given that names and email addresses were part of this exposure, here’s what we’d ask you to keep in mind:
We know this has been a long process, and that the timeline — an initial disclosure in May, followed by months before individualized confirmation — has likely felt slower than you’d want. Some of that delay was outside of our control (it depended on Instructure’s own investigation and data delivery process, which was itself paused due to a separate security issue). Where we’ve had control, our approach has been to confirm facts before communicating, rather than share things that might change or turn out to be inaccurate.
We’ve arranged complimentary credit monitoring and identity protection for one year through Instructure. You’ll receive details directly from Instructure, separately from this message. We’ll continue to strengthen our security practices as Braven grows, and we’ll keep being straightforward with our community if anything changes. If you have questions about this incident or your data, you can reach out to Braven CTO, Moon Lee — we’re glad to talk through it.
Thank you for your trust and patience through this process.
— The Braven Team