Instructure Confirms Double Canvas Breach as ShinyHunters Sets Ransom Deadline
Ed-tech giant Instructure has acknowledged two separate security intrusions affecting its Canvas online learning platform within a two-week period. The attacks, attributed to the data-theft group ShinyHunters, exploited a vulnerability in the Free-for-Teacher system, leading to significant service disruptions during final exams. While Instructure restored full service by May 10, the hackers claim to have stolen 3.65 TB of data comprising approximately 275 million records from nearly 9,000 educational institutions globally, including prestigious universities like Harvard and Stanford. Compromised information includes usernames, email addresses, and course enrollment details, though core academic submissions and credentials remain secure. ShinyHunters has issued a final pay-or-leak deadline of May 12 for individual schools to negotiate, threatening to publish the dataset otherwise. In response, Instructure disabled Free-for-Teacher accounts, rotated credentials, and engaged CrowdStrike for forensic analysis. The company also notified the FBI and CISA. This incident marks Instructure's second major breach in under a year, following a previous Salesforce-related intrusion in late 2025, highlighting ongoing cybersecurity challenges in the educational technology sector.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection