# What we learned from the Canvas hack Page: https://stenobird.com/podcast/marketplace-tech-318132/what-we-learned-from-the-canvas-hack Text version: https://stenobird.com/podcast/marketplace-tech-318132/what-we-learned-from-the-canvas-hack.md Podcast: [Marketplace Tech](https://stenobird.com/podcast/marketplace-tech-318132) Published: 2026-05-20T10:00:00+00:00 Episode link: https://www.marketplace.org/episode/2026/05/20/what-we-learned-from-the-canvas-hack Audio file: https://pscrb.fm/rss/p/mgln.ai/e/5/dts.podtrac.com/redirect.mp3/play.publicradio.org/podcast/o/marketplace/tech_report/2026/05/20/tech_20260520_0520_MP_TECH_pod_128.mp3?awCollectionId=mkp-MKPtech&awEpisodeId=01KS0WZ3WYWFPX19G0EH85YWKM Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/marketplace-tech-318132/episodes/what-we-learned-from-the-canvas-hack Duration seconds: 389 ## Resource Earlier this month, a group called ShinyHunters took responsibility for a hack on the education platform Canvas, which is used for coursework at colleges. In a letter posted online , the group threatened to leak data it took from the platform, including billions of private messages between students and teachers. Canvas was also temporarily unavailable, disrupting students’ ability to do their work. Then, last week, Instructure , which makes Canvas, said it had reached a deal with the hackers , that the data had been returned and all copies destroyed. Marketplace’s Stephanie Hughes asked Rachel Tobac, CEO at Social Proof Security, what we know about the deal. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/marketplace-tech-318132/episodes/what-we-learned-from-the-canvas-hack/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/marketplace-tech-318132/what-we-learned-from-the-canvas-hack.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.