Wayzata Public Schools
Incident posture
Linked entities
- Victim
- Wayzata Public Schools
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Wayzata Public Schools was notified that a breach affecting the Canvas learning platform exposed names, email addresses, student ID numbers and internal messages for some of its students and staff, while confirming that its own networks were not compromised. Instructure, the platform’s parent company, stated that passwords, financial data and government identifiers were not accessed, and that it had contained the incident by revoking credentials, applying patches and increasing monitoring. The district notified families of the breach, activated its incident response team, is maintaining contact with Instructure and reviewing its security protocols.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On May 1, 2026, Instructure, the parent company of Canvas, notified Wayzata Public Schools that hackers had accessed certain systems within their environment. The breach was described as a vendor‑side incident, with Wayzata confirming that its internal networks and systems were not breached or compromised. Hackers claimed to have accessed information on approximately 275 million users and more than 9,000 schools using the Canvas platform. According to the district, the potentially exposed data included student and staff names, email addresses, student ID numbers, and internal messages sent within Canvas. Instructure officials stated there was no evidence that passwords, dates of birth, government identifiers, or financial information were accessed.
Wayzata Public Schools activated its Incident Response Team and began reviewing its own security protocols while maintaining close contact with Instructure. Instructure reported that the incident had been contained, privileged credentials had been revoked, security patches deployed, certain keys rotated, and monitoring increased across all platforms. The district noted that Instructure committed to notifying any impacted institutions if new information about the breach came to light. Families were advised by the district to watch for unsolicited emails or messages appearing to come from Canvas, especially those requesting personal information or password resets, and to monitor school accounts for any unusual activity.
Wayzata Public Schools indicated that it is not yet clear exactly how many students or staff members may have had their information accessed. The district also said it is unknown whether any Minnesota‑specific data was targeted in the breach. The investigation remains active and ongoing, with both the district and Instructure continuing to assess the scope and consequences. Throughout communications, Wayzata emphasized that the privacy and security of student data remains its highest priority.
Sources
Sources available to members: 1 source.