CSIDB logo
Incident

Education Queensland

Incident posture

Attack window
May 2026
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-16 01:40

Linked entities

Victim
Education Queensland
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
May 2026
Disclosed
May 2026
Resolved
Pending

Summary

Education Queensland said students and staff at state schools may have been affected by a breach of the global education systems vendor Instructure, which supplies the Canvas platform behind the QLearn learning management system used by over 1,200 schools, 570,000 students and 73,000 staff. The state’s education minister advised that a limited set of data fields—names, email addresses and school locations—were compromised, with no evidence that passwords, dates of birth or financial information were accessed. School principals are notifying families and teachers, other institutions are reviewing their exposure, and the National Cyber Security Coordinator is coordinating the response.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Queensland government announced that students and staff who have worked or studied at state schools since 2020 may have been involved in a breach affecting the global education systems vendor Instructure. QLearn, the digital learning management platform used by Queensland schools, is built on Instructure’s Canvas service. According to a vendor case study, QLearn serves 1,264 K‑12 schools, 572,160 students, and more than 73,000 teaching staff. Education Minister John‑Paul Langbroek stated that a limited number of data fields are believed to have been compromised. He advised that names, email addresses and school locations of affected individuals have been exposed in the international data breach. Langbroek also said there is no evidence that passwords, dates of birth or financial information were accessed.

The minister noted that school principals are in the process of contacting families and teachers to inform them of the breach. Earlier reports from iTnews indicated that other Australian institutions, including RMIT University, UTS, TasTAFE Tasmania and Western Sydney University, were urgently assessing their potential exposure to the same incident. TasTAFE reported that Instructure first notified them of the cyber incident on 2 May. TasTAFE added that, on the following day, the vendor provided further details indicating that a criminal third party was involved. Similar disclosures have been made by universities and schools worldwide regarding the Canvas breach.

Because of the broad potential impact, the National Cyber Security Coordinator, Lieutenant General Michelle McGuinness, has become involved in the response. McGuinness wrote on LinkedIn that her team is coordinating efforts to respond and to understand what Australian data may be affected. She stated that the assessment is in its early stages and that further updates will be shared as more information becomes available.

Sources

Sources available to members: 1 source.

CSIDB