CSIDB logo
Incident

Wayzata Public Schools

Incident posture

Attack window
May 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-09 01:05

Linked entities

Victim
Wayzata Public Schools
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2026
Discovered
May 2026
Disclosed
May 2026
Resolved
Undetermined

Summary

Wayzata Public Schools was notified that a breach affecting the Canvas learning platform exposed names, email addresses, student ID numbers and internal messages for some of its students and staff, while confirming that its own networks were not compromised. Instructure, the platform’s parent company, stated that passwords, financial data and government identifiers were not accessed, and that it had contained the incident by revoking credentials, applying patches and increasing monitoring. The district notified families of the breach, activated its incident response team, is maintaining contact with Instructure and reviewing its security protocols.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 1, 2026, Instructure, the parent company of Canvas, notified Wayzata Public Schools that hackers had accessed certain systems within their environment. The breach was described as a vendor‑side incident, with Wayzata confirming that its internal networks and systems were not breached or compromised. Hackers claimed to have accessed information on approximately 275 million users and more than 9,000 schools using the Canvas platform. According to the district, the potentially exposed data included student and staff names, email addresses, student ID numbers, and internal messages sent within Canvas. Instructure officials stated there was no evidence that passwords, dates of birth, government identifiers, or financial information were accessed.

Wayzata Public Schools activated its Incident Response Team and began reviewing its own security protocols while maintaining close contact with Instructure. Instructure reported that the incident had been contained, privileged credentials had been revoked, security patches deployed, certain keys rotated, and monitoring increased across all platforms. The district noted that Instructure committed to notifying any impacted institutions if new information about the breach came to light. Families were advised by the district to watch for unsolicited emails or messages appearing to come from Canvas, especially those requesting personal information or password resets, and to monitor school accounts for any unusual activity.

Wayzata Public Schools indicated that it is not yet clear exactly how many students or staff members may have had their information accessed. The district also said it is unknown whether any Minnesota‑specific data was targeted in the breach. The investigation remains active and ongoing, with both the district and Instructure continuing to assess the scope and consequences. Throughout communications, Wayzata emphasized that the privacy and security of student data remains its highest priority.

Sources

Sources available to members: 1 source.

CSIDB