A message to Braven students, volunteers, and staff who use Canvas

If you use Canvas as part of your work with Braven, you may have heard about a security incident affecting Instructure, the company that runs Canvas. We’ve been tracking this closely since it began, and we now have enough confirmed information to give you the full picture: what happened, what it means for you specifically, how we’ve responded, and what we’re doing going forward.

We know a message like this can be unsettling. Our goal here is to be as clear and complete as possible, so you have what you need without guesswork.

What Happened

In late April 2026, Instructure discovered that an unauthorized party had gained access to its systems. Instructure has publicly attributed the intrusion to a hacking group known as ShinyHunters, a group that has been linked to a number of large-scale data breaches at other companies and institutions over the past two years — this was not their first incident, and not Instructure’s first encounter with this group either.

Here’s how it unfolded, based on Instructure’s public disclosures:

  • April 25: The unauthorized access occurred.
  • April 29: Instructure detected the intrusion, cut off the attacker’s access, and brought in outside security investigators.
  • May 1–2: Instructure disclosed the incident publicly and shared an initial description of what data categories were involved across its customer base: names, email addresses, student ID numbers, and messages exchanged between users. Instructure stated it found no evidence that passwords, birth dates, government ID numbers, or financial information were affected.
  • May 6–7: Instructure initially said the situation was resolved, but was compromised again days later, with the group replacing Canvas’s login page with a message demanding ransom.
  • Mid-May: Instructure paid a ransom shortly before the attackers’ deadline to prevent the stolen data from being published, and reported that the data was returned and the attackers’ copies destroyed.

 

This was a large-scale incident. Reporting indicates the exposure affected data connected to thousands of schools and organizations that use Canvas, not just Braven. Instructure’s official updates on this incident are available here.

What This Means Specifically for Braven

Because this incident affected Instructure’s systems broadly, it took time before individual organizations — including Braven — could get confirmation of exactly what data of theirs, specifically, was involved. Instructure committed to delivering an individualized data report to every affected institution, and that process was delayed multiple times, most recently in mid-July due to a separate security concern with the third-party platform being used to deliver the data.

That delivery process is now complete for Braven. Here is what we know:

What was involved: A list of Braven’s Canvas users — students, volunteers, and staff — including:

  • Login ID
  • Name
  • Email address
  • Enrolled course(s)


What was not involved: No passwords, dates of birth, Social Security numbers, or financial information were part of this exposure, for Braven or more broadly across Instructure’s customer base, according to Instructure’s confirmed findings.

We want to be direct about what this means in practice: your name, email, and course enrollment being exposed does not give anyone access to your accounts. But it does mean you may be a more likely target for phishing attempts — messages designed to look like they’re from Braven, Instructure, or a partner school, trying to trick you into sharing information you shouldn’t. More on that below.

How We Responded

From the moment this incident became public, we made a decision to follow the facts rather than react to speculation. In the early days, unverified lists claiming to show affected institutions circulated online, and Braven’s name appeared on some of them before we had any confirmation from Instructure directly.

Since then, we’ve taken concrete steps to reduce risk going forward, independent of anything Instructure does on its end:

  • Enforced multi-factor authentication (MFA) across our systems, adding a required second step beyond just a password to sign in.
  • Built the capability to sign in through partner schools’ own authentication systems (single sign-on), which reduces the number of separate logins and credentials tied to your information across different platforms.
  • Increased monitoring across our platforms to help us catch unusual activity sooner.


We also worked directly with individual partner schools whose own security teams reached out with questions, to make sure they had accurate, Braven-specific answers rather than general public statements.

What You Should Do

Given that names and email addresses were part of this exposure, here’s what we’d ask you to keep in mind:

  • Be alert to phishing. You may receive emails, texts, or calls that appear to reference Braven, Canvas, or Instructure and ask you to click a link, log in, or share information. Treat anything unexpected with caution, especially if it creates urgency.
  • We will never ask for sensitive information over email. Braven will never ask you for your password, Social Security number, or payment details by email.
  • When in doubt, verify directly. If something seems off, reach out to us directly through a channel you already trust — not by replying to or clicking through the message in question.
  • Ensure you have a strong Canvas password. Although Instructure found no evidence passwords were exposed — using MFA and strong unique passwords across your accounts is always good practice.

 

What’s Next

We know this has been a long process, and that the timeline — an initial disclosure in May, followed by months before individualized confirmation — has likely felt slower than you’d want. Some of that delay was outside of our control (it depended on Instructure’s own investigation and data delivery process, which was itself paused due to a separate security issue). Where we’ve had control, our approach has been to confirm facts before communicating, rather than share things that might change or turn out to be inaccurate.

We’ve arranged complimentary credit monitoring and identity protection for one year through Instructure. You’ll receive details directly from Instructure, separately from this message. We’ll continue to strengthen our security practices as Braven grows, and we’ll keep being straightforward with our community if anything changes. If you have questions about this incident or your data, you can reach out to Braven CTO, Moon Lee — we’re glad to talk through it.

Thank you for your trust and patience through this process.

— The Braven Team