Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?
https://www.instructure.com/incident_update
It worries me they've only committed to making it available to their customers and not the public.
I don't know for sure, but I think it probably had to do with some kind of misconfiguration on an Salesforce Experience Cloud site. I have heard that ShinyHunters often exploits this type of service and that it is very easy for companies to forget to set the right permissions to data and they end up throwing a bunch of different data into Salesforce.
[0]: https://cyber.acmucsd.com/canvas (disclosure: I was involved with this org when I was a student)