RISI

← News

Updated 2026-05-08

ShinyHunters breaches Instructure Canvas, exposing data across 9,000 schools and demanding ransom by May 12

The criminal extortion group ShinyHunters claimed responsibility for an April 30 breach of Instructure, the company behind the Canvas learning management system used by roughly 9,000 educational institutions worldwide. Instructure confirmed the intrusion and acknowledged that names, email addresses, student ID numbers, and user messages were taken. The group followed the data theft with a defacement campaign against school login portals on May 7 and set a May 12 ransom deadline.

On April 30, 2026, Instructure — the company that operates Canvas, the learning management system used by approximately 9,000 educational institutions across North America, Europe, and Asia-Pacific — detected unauthorized access to its production systems. By May 1, the company confirmed criminal perpetrators and engaged forensic investigators. Instructure contained the intrusion by May 2, rotated application keys, increased monitoring, and required customers to re-authorize API access. The Canvas Data 2 platform was restored by May 3. The company disclosed the incident publicly around May 5 and confirmed that names, email addresses, student ID numbers, and user messages had been taken. Instructure stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.

ShinyHunters, a criminal extortion group with a documented record of large-scale credential and data theft including prior campaigns against Ticketmaster, AT&T, and Snowflake’s cloud-storage customers, claimed responsibility on May 3 by posting to a data-leak forum. The group alleged it had stolen 3.65 terabytes of data covering 275 million individuals across roughly 9,000 institutions, including universities such as Oxford, Cambridge, Harvard, Stanford, Columbia, Duke, Princeton, and Georgetown, as well as K-12 districts across multiple US states. It separately claimed to have accessed a Salesforce instance connected to Instructure. The gap between Instructure’s confirmed scope and ShinyHunters’ stated figure is substantial: Instructure confirmed that data was stolen and named specific data types, but has not confirmed the total volume. ShinyHunters’ prior campaigns have tended to inflate record counts, and no independent verification of the 275 million figure has been published as of this writing.

On May 7, ShinyHunters escalated by defacing the Canvas login pages of approximately 330 institutions. The group replaced login screens with an extortion notice warning that the stolen data would be published on May 12 unless affected institutions negotiated a settlement. The defacement was visible for approximately 30 minutes before Instructure’s response suppressed it. The same day, Instructure’s website was intermittently unreachable. The defacement campaign was described by a ShinyHunters representative as a response to Instructure patching the exploited vulnerability without engaging the group, a pattern the group has used in prior extortion operations. The specific vulnerability exploited in the April 30 intrusion has not been disclosed, and no CVE identifier has been assigned publicly. A ShinyHunters representative confirmed to TechCrunch that this constituted a second, separate breach of Instructure, implying a prior access that predates the April 30 detection.

Canvas’s installed base means the breach, even at a confirmed fraction of the claimed scale, represents one of the larger single-vendor education data exposures on record. The operational parallel for security teams is the vendor-concentration risk: a compromise at one SaaS provider propagated simultaneously to thousands of institutional customers who had no independent visibility into Instructure’s production environment and no path to individual containment. That is the same structural condition that made the 2024 Snowflake customer breach — also attributed to ShinyHunters — so wide in its reach. As of May 8, no law enforcement action against ShinyHunters specifically related to this incident has been announced publicly, and Instructure has not disclosed whether any ransom payment has been made or is under consideration.

Sources