Instructure Pays Ransom to ShinyHunters After Massive Canvas Data Breach
Edtech company Instructure paid a ransom to the ShinyHunters cybercrime group following two major data breaches of its Canvas learning platform. The attacks compromised 275 million records from nearly 9,000 educational institutions globally, exposing names, emails, and private messages. While Instructure secured digital proof of data destruction to prevent further extortion, the incident triggered service disruptions, class-action lawsuits, and a US Congressional investigation into the company’s cybersecurity failures and decision to negotiate with hackers.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
Canvas Hack: Ransom Payment Debate and Data Recovery After ShinyHunters Attack
US education technology firm Instructure, operator of the Canvas learning platform, reportedly paid a ransom to the hacking group ShinyHunters following a massive cyberattack that compromised the data of approximately 275 million students and staff worldwide. Although Instructure did not explicitly confirm a payment, it announced an agreement with the attackers, stating that the stolen data was returned and destroyed, verified by shred logs. Experts interpret this language as a strong indication that a ransom, potentially up to $10 million, was paid to prevent the leak of sensitive information including student IDs and messages. The attack caused significant disruptions, including week-long outages and defaced login pages, affecting thousands of educational institutions globally, particularly in Australia and the US. This incident highlights the ongoing dilemma faced by organizations regarding ransomware payments; while governments generally advise against paying to discourage criminal activity, many companies choose to pay to protect user privacy and mitigate further harm. The breach was facilitated by a vulnerability in Instructure's Free for Teacher software, raising concerns about cybersecurity protocols in the education sector.
The GuardianCongress Pressures Instructure Following Canvas Cyberattack and Ransom Agreement
The US House Committee on Homeland Security has demanded answers from educational technology vendor Instructure following a severe cyberattack on its Canvas learning management system. The committee sent a letter to CEO Steve Daly requesting a briefing by May 21, questioning the company's incident response capabilities after being breached twice in one week by the ShinyHunters cybercrime group. Lawmakers are particularly concerned about whether Instructure paid a ransom, following the company's statement that it reached an agreement with the attackers resulting in the return and destruction of stolen data. Although Instructure denied customer extortion, the removal of their listing from ShinyHunters' leak site suggests a payment was likely made. The initial breach exposed user identifying information, including names and student IDs, affecting over 9,000 educational institutions. The Senate Committee on Health, Education, Labor, and Pens also issued inquiries regarding data security improvements. This high-profile incident has disrupted grade reporting and other functions for thousands of schools, raising serious questions about the security obligations of edtech providers holding sensitive student data.
darkreadingCongress Pressures Instructure Following Canvas Cyberattacks by ShinyHunters
The US House Committee on Homeland Security has intensified scrutiny of educational technology vendor Instructure following repeated cyberattacks on its Canvas learning management system by the ShinyHunters criminal group. In a letter to CEO Steve Daly, the committee demanded a briefing by May 21, questioning the company's incident response capabilities after breaches occurred within days of each other in May 2026. The attacks disrupted services for thousands of schools and exposed user data, including names and student IDs. Concurrently, the Senate Committee on Health, Education, Labor, and Pensions launched its own investigation, focusing on whether Instructure paid a ransom. Although Instructure stated it reached an "agreement" resulting in the return and destruction of stolen data without customer extortion, it did not explicitly confirm a payment. However, the removal of Instructure from ShinyHunters' leak site suggests a ransom was likely paid. Lawmakers are also investigating potential links to a previous Salesforce environment breach, raising serious concerns about data security obligations to educational institutions.
darkreadingUS Congress Probes Instructure After Canvas Pays Ransom to ShinyHunters
The US House Homeland Security Committee has summoned Instructure CEO Steve Daly to testify regarding two recent cyberattacks on its Canvas educational platform. The breaches, executed by the extortion group ShinyHunters within a two-week period in late April and early May 2026, exploited XSS vulnerabilities to access administrative systems. The attackers stole approximately 3.6 TB of data affecting millions of students and staff across 8,800 institutions. Amidst final examinations, the second intrusion forced a temporary platform shutdown after hackers injected ransom demands into login portals. Instructure subsequently paid an undisclosed ransom to prevent data leakage, claiming receipt of digital confirmation that stolen files were destroyed. Committee Chairman Andrew Garbarino emphasized the national concern caused by disrupting a service used by over 30 million users. The investigation will scrutinize the circumstances of the intrusions, data volume, containment efforts, and coordination with federal agencies like CISA. This incident marks the second known security breach involving ShinyHunters and Instructure in less than a year, following a previous compromise of the company's Salesforce environment in September 2025.
www.theregister.com - ArticlesInstructure Reaches Deal with ShinyHunters to Prevent Data Release
Edtech giant Instructure, the creator of the Canvas learning management system, has announced a settlement with the hacking collective ShinyHunters following a significant data breach. The agreement, reached just before a May 12 ransom deadline, aims to prevent the public release of stolen user data and stop extortion attempts against individual customers. The breach, which occurred in two stages over recent weeks, compromised the personal information of approximately 275 million users across nearly 9,000 schools globally, including students, teachers, and staff. Affected data included usernames, email addresses, student IDs, and private messages. As part of the deal, ShinyHunters agreed to return the stolen data and provided digital confirmation of its destruction via shred logs. Instructure CEO Steve Daly acknowledged the inherent risks of negotiating with cybercriminals but emphasized the company's priority to protect its community. While financial details of the settlement were not disclosed, Instructure confirmed that the agreement covers all impacted customers. The company continues to work with forensic experts to harden its security infrastructure and review the extent of the data involvement, urging users not to engage directly with the hackers.
MashableCanvas Owner Instructure Pays Ransom to Hackers After Double Breach
Instructure, the educational technology company behind the widely used Canvas learning management system, has confirmed that it struck a deal with the cybercriminal group ShinyHunters following two significant data breaches of its platform. The company reportedly paid a ransom to secure the deletion of stolen sensitive information affecting approximately 275 million users globally. While Instructure received digital confirmation from the hackers that the exfiltrated data was destroyed, the company explicitly acknowledged that there is no absolute certainty that the attackers honored their word or deleted all copies of the compromised records. This incident highlights the growing dilemma faced by corporations when dealing with sophisticated ransomware gangs and the inherent risks of negotiating with cybercriminals. The breach underscores severe vulnerabilities in the education sector's digital infrastructure, raising concerns about the long-term privacy and security of student and institutional data. Despite the payment, the lack of guaranteed data destruction leaves millions of individuals potentially exposed to future identity theft or fraud, prompting further scrutiny of Instructure's cybersecurity protocols and crisis management strategies in the aftermath of these repeated security failures.
QuartzInstructure Pays Ransom to ShinyHunters to Recover Stolen Canvas Data
Instructure, the developer of the Canvas learning management system, reached a controversial agreement with the cyber extortion group ShinyHunters to prevent the leak of data stolen in a recent security breach. Although specific terms were not disclosed, the company strongly implied a ransom payment was made to secure the return and destruction of the compromised information. The breach, attributed to a vulnerability in Free-For-Teacher accounts, allegedly exposed 3.65 TB of data containing approximately 275 million records from over 8,800 educational institutions. Affected data includes student and staff names, email addresses, and internal communications. After ShinyHunters defaced login portals and began extorting individual schools, Instructure intervened to protect its community of 30 million users. The agreement ensures affected customers will not face direct extortion. However, cybersecurity experts warn that paying ransoms offers no guarantee that attackers have not copied or shared the data elsewhere. Instructure continues to work with forensic experts to analyze the incident and strengthen its security infrastructure while temporarily shutting down the vulnerable service.
Help Net SecurityCanvas Developer Instructure Admits Paying Hackers to Delete Stolen Data
Instructure, the developer of the online education platform Canvas, has admitted to reaching an agreement with the ShinyHunters hacker gang following a significant data breach. CEO Steve Daly disclosed that the company secured the return of stolen data and digital confirmation of its destruction, along with a guarantee that customers would not face extortion. Although Daly did not explicitly confirm a ransom payment, cybersecurity experts widely interpret the arrangement as such. The breach compromised sensitive information, including usernames, emails, and private messages, affecting millions of users across thousands of educational institutions. This decision has sparked controversy, with critics arguing it funds criminal activity, while Instructure maintains it was necessary to protect customers. Consequently, the company faces mounting class-action lawsuits demanding damages for the outage and data loss. Additionally, Instructure is under scrutiny from the US Congress, with House Homeland Security Committee Chairman Andrew Garbarino demanding a briefing. Garbarino criticized the company's incident response, citing failures to remediate vulnerabilities after initial intrusion detection. The situation highlights ongoing challenges in cybersecurity response and the ethical dilemmas surrounding ransom payments.
PCMag.com - Technology Product Reviews, News, Prices & TipsCanvas Operator Instructure Reaches Deal with Hackers to Delete Stolen Data
Instructure, the U.S.-based company operating the popular online learning platform Canvas, has reached an agreement with the hacking group ShinyHunters following a significant cyberattack. The breach impacted major Canadian universities, including the University of Toronto, University of British Columbia, and University of Alberta, causing service disruptions and security warnings for students and staff. ShinyHunters claimed responsibility for stealing data belonging to 275 million individuals from nearly 9,000 schools globally. Instructure confirmed that it received digital proof of data destruction, known as shred logs, from the unauthorized actors. The company stated that no customers would face extortion as a result of this incident and advised against individual engagement with the hackers. While Instructure did not disclose whether a ransom payment was made, the agreement covers all affected customers. The incident prompted several educational institutions to temporarily take their Canvas services offline as a precautionary measure while urging users to change passwords and avoid logging in until further notice.
global news canadaCanvas Data Breach Impacts Canadian Universities, Prompting Security Warnings
Major Canadian universities, including the University of Toronto, OCAD University, and the University of British Columbia, have issued warnings following a significant global data breach involving the learning management system Canvas. The incident, attributed to the cybercrime group ShinyHunters, was disclosed by Canvas parent company Instructure on May 1. The breach compromised user information such as names, email addresses, student ID numbers, and private messages, though passwords and financial data remain secure. Instructure temporarily suspended its Free-For-Teacher accounts to mitigate the threat, exploiting a vulnerability in that specific service. While Canvas is now fully operational, several institutions initially restricted access as a precaution. Affected universities are actively advising students and staff to enable multifactor authentication and remain vigilant against phishing attempts linked to the breach. Reports indicate the attack impacted approximately 15,000 institutions worldwide, stealing 3.65 terabytes of data comprising 275 million records. This event highlights ongoing cybersecurity challenges in the education sector, prompting immediate defensive measures and continuous monitoring by affected academic institutions across Canada and globally.
MobileSyrup