ShinyHunters Breaches Canvas, Disrupting Global Schools and Exposing Student Data
Instructure’s Canvas platform suffered a major cyberattack by the ShinyHunters group, disrupting final exams for millions of students across nearly 9,000 educational institutions globally. The breach exploited a vulnerability in free teacher accounts, exposing sensitive data like names, emails, and private messages for approximately 275 million users. While core credentials remained secure, the incident caused widespread academic chaos and triggered multiple class-action lawsuits. Instructure ultimately reached a controversial agreement with the hackers to retrieve and destroy the stolen data, highlighting critical vulnerabilities in educational technology infrastructure.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
Canvas Parent Company Instructure Strikes Deal with Hackers to Delete Stolen Student Data
Instructure, the parent company of the online learning platform Canvas, announced it reached an agreement with hackers to delete data stolen during a recent cyberattack. The breach caused significant disruption for students and faculty globally, leading to delayed final exams as users were locked out of the system. The hacking group ShinyHunters claimed responsibility, threatening to leak data affecting nearly 9,000 schools and 275 million individuals unless a ransom was paid. As part of the deal, Instructure received the stolen data back and obtained digital confirmation, known as shred logs, that remaining copies were destroyed. However, the company acknowledged there is no absolute certainty that all data was erased. The compromised information included student names, email addresses, ID numbers, and messages, though no financial or government identification data was exposed. Instructure did not disclose if a payment was made. The company is currently working with expert vendors to conduct forensic analysis and strengthen its security systems. This incident highlights the vulnerability of educational technology platforms and the difficult decisions organizations face when dealing with cybercriminals to protect user privacy.
The GuardianUniversity of Illinois Reschedules Finals After Canvas Reaches Deal with Hackers
The University of Illinois Urbana-Champaign rescheduled final exams from Friday to Sunday, Mother's Day, following a cyberattack on the Canvas learning platform. Instructure, Canvas's parent company, announced it reached an agreement with the hacking group ShinyHunters to delete stolen data and prevent its public release. The breach caused significant disruption, locking out students and faculty during critical exam periods. While Instructure received digital confirmation via shred logs that the data was destroyed, the company acknowledged there is no absolute certainty regarding complete erasure. The compromised data included student IDs, names, email addresses, and messages, though passwords and financial information were not affected. Provost John Coleman admitted the rescheduling was less than ideal due to religious observances and the holiday but deemed it the best available option. Instructure is currently conducting forensic analysis and strengthening system security. The incident highlights the vulnerability of educational infrastructure, as Canvas supports nearly 9,000 schools worldwide. ShinyHunters had previously threatened to leak data affecting 275 million individuals if ransom demands were not met, leading to negotiations that resulted in this settlement.
Chicago Sun-Times - AllCanvas Parent Company Instructure Strikes Deal with Hackers to Delete Stolen Data
Instructure, the parent company of the online learning platform Canvas, announced it reached an agreement with hackers to delete data stolen during a recent cyberattack. The breach, claimed by the hacking group ShinyHunters, threatened to expose personal information of approximately 275 million individuals across nearly 9,000 schools worldwide if a ransom was not paid. As part of the deal, Instructure received the stolen data back and obtained digital confirmation, known as shred logs, that remaining copies were destroyed. However, the company acknowledged that complete certainty of erasure is impossible when dealing with cybercriminals. The compromised data included student ID numbers, email addresses, names, and platform messages, though no passwords, financial details, or government IDs were exposed. The incident caused significant disruption for students and faculty, particularly those in the midst of final exams, as the system was temporarily taken offline. Instructure CEO Steve Daly apologized for inconsistent communication during the crisis. The company is currently working with expert vendors to conduct forensic analysis and strengthen its security systems to prevent future incidents.
Home - CBSNews.comInstructure Pays Ransom to ShinyHunters to Prevent Canvas Data Leak
Instructure, the American educational technology company behind the Canvas learning management system, has reached a controversial agreement with the ShinyHunters cybercrime group to prevent the public release of stolen data. Following a network breach that compromised approximately 3.65TB of information affecting nearly 9,000 educational institutions, Instructure opted to pay a ransom. The company stated that the agreement ensures the return of pilfered data, digital confirmation of its destruction, and protection against separate extortion attempts on customers. The attackers initially exploited a vulnerability in the Free-for-Teacher environment, stealing around 275 million records including usernames, emails, and enrollment details, though course content and credentials remained secure. A second wave of attacks in May 2026 defaced login portals at 330 institutions, prompting the negotiation. Instructure has since suspended Free-for-Teacher accounts, rotated internal keys, and enhanced security controls. Security experts warn that the exposed data could facilitate targeted phishing campaigns against students, staff, and parents, urging affected institutions to issue immediate advisories. Instructure continues to work with forensic vendors to analyze the breach and improve its cybersecurity posture.
The Hacker NewsCanvas Maker Instructure Strikes Deal with Hackers for Data Return
Instructure, the developer of the widely used Canvas learning platform, announced on May 11 that it reached an agreement with the ShinyHunters hacking group to return stolen data and destroy all copies. The cyberattack, which occurred in early May, compromised the personal information of over 275 million users across nearly 9,000 schools globally. Compromised data included names, email addresses, course details, and private messages between students and teachers. Following the breach detected on April 29 and May 7, Instructure temporarily shut down the platform to investigate. Although the company did not disclose the terms of the deal or whether a ransom was paid, it stated that customers would not face extortion. Instructure coordinated with the FBI and international law enforcement but proceeded with negotiations to ensure data destruction. ShinyHunters, known for previous high-profile attacks like the 2024 Ticketmaster breach, had threatened to leak billions of private messages if their demands were not met by May 12. This incident highlights significant cybersecurity vulnerabilities in educational technology infrastructure affecting millions of users worldwide.
The Straits Times World NewsCanvas Developer Instructure Reaches Agreement with Hackers Following Major Data Breach
Instructure, the US-based developer of the online learning platform Canvas, announced it has reached an agreement with the cybercriminal group ShinyHunters following a significant data breach. The attack targeted approximately 9,000 educational institutions globally, including schools and universities in Australia, the United States, and Canada, affecting millions of students. Stolen data included student ID numbers, email addresses, enrollment information, and platform messages, causing indefinite service shutdowns and disrupting academic activities. As part of the negotiated settlement, Instructure confirmed that the hackers returned the stolen data and provided digital confirmation of its destruction. The company stated that no customers would face extortion and advised individual institutions against engaging directly with the attackers. CEO Steve Daly apologized for the disruption and communication failures, attributing the breach to a vulnerability in support tickets for Free for Teacher accounts. While core learning data like course content and credentials remained secure, the incident highlights ongoing cybersecurity challenges in the education sector. Instructure has temporarily disabled the affected accounts while conducting a comprehensive cybersecurity review to prevent future incidents.
Just InCanvas Parent Company Reaches Agreement with Hackers and Issues Apology
Instructure, the technology company behind the widely used educational learning management system Canvas, has officially reached an agreement with the cybercriminals responsible for a recent data breach. Following extensive negotiations, the company announced that it has secured the return of stolen data and apologized to its users for the security incident. The breach had previously exposed sensitive information belonging to students, educators, and institutions globally, causing significant concern within the education sector. Instructure stated that the agreement was necessary to mitigate further harm and protect the privacy of affected individuals. The company has committed to enhancing its cybersecurity measures and working closely with law enforcement agencies to prevent future attacks. This resolution marks a critical step in addressing the fallout from one of the most significant cyberattacks on the education technology industry in recent years. Users are advised to monitor their accounts for any suspicious activity, although Instructure assures that no financial data was compromised during the incident.
VK: homepageCanvas Developer Instructure Apologizes After Major Data Breach by ShinyHunters
Instructure, the developer of the widely used educational platform Canvas, has issued a formal apology following a significant cyberattack that disrupted services and compromised user data. The breach was claimed by the hacking group ShinyHunters, which stated it stole approximately 6.65 terabytes of data linked to nearly 9,000 schools globally. Stolen information includes student names, email addresses, course enrollment details, and private messages between users. However, Instructure CEO Steve Daly confirmed that core learning data, such as course content, submissions, and login credentials, remained uncompromised. The attack exploited a vulnerability in the support ticket system within the app’s 'Free for Teacher' environment, which has since been disabled pending a full security review. The incident caused widespread disruption for students and faculty during the critical end-of-year academic period. Daly acknowledged the stress and communication failures experienced by users, promising more consistent updates moving forward. While the platform is now fully operational and deemed safe, the event highlights ongoing cybersecurity risks facing major educational technology providers.
The Straits Times World NewsMassive Canvas Hack Disrupts California Colleges Amid Critical Exam Period
A significant cyberattack on the educational platform Canvas severely impacted higher education in California, affecting over one million students during crucial midterm and final exam periods. The breach, attributed to the hacker group ShinyHunters, exploited a vulnerability in a free teacher tool, leading to widespread outages that blocked access to assignments, tests, and communication channels. Students at institutions like UC Riverside reported frustration due to limited professor communication and disrupted coursework. Instructure, the company behind Canvas, confirmed an agreement with the attackers to secure the return of stolen data, which included billions of messages, though core learning data and credentials were reportedly not compromised. While some campuses experienced brief shutdowns earlier in May, the major outage occurred on May 7, with services gradually restoring by May 9. The incident has sparked urgent discussions regarding cybersecurity vulnerabilities in edtech, institutional liability, and the need for backup communication plans in academia. This event highlights the heavy reliance of nearly 9,000 global educational institutions on digital platforms and the risks associated with centralized educational technology systems.
CalMattersShinyHunters Threatens Canvas Data Leak as Extortion Deadline Approaches
Instructure, the developer of the widely used educational platform Canvas, faces escalating pressure from the cybercriminal group ShinyHunters. The attackers, affiliated with The Com, claim to have stolen 3.65 terabytes of data comprising 275 million records across more than 8,800 school systems. After an initial May 6 deadline passed without ransom payment, the group intensified its campaign by injecting extortion messages into login pages of approximately 330 institutions and setting a new May 12 deadline for individual schools. The incident caused widespread outages, disrupting access for students and teachers nationwide. Instructure CEO Steve Daly apologized for inconsistent communication and confirmed that usernames, emails, and enrollment data were exposed, though course content and credentials remained secure. The breach has drawn significant attention from US lawmakers, with the House Homeland Security Committee requesting a briefing on Instructure’s incident response capabilities and remediation efforts. The Cybersecurity and Infrastructure Security Agency (CISA) is aware of the incident and offering voluntary support. This event marks one of the largest single exposures in the education sector, raising serious concerns about cybersecurity protocols in essential academic infrastructure.
CyberScoopCanvas Developer Instructure Apologizes After Major Data Breach
Instructure, the developer of the widely used educational platform Canvas, has issued a formal apology following a significant cyberattack that disrupted services and compromised student data. The breach, attributed to the hacking group ShinyHunters, involved the theft of approximately 6.65 terabytes of data linked to nearly 9,000 schools globally. Stolen information includes student names, email addresses, and private messages between users, though core learning materials and credentials remain secure. Steve Daly, CEO of Instructure, acknowledged the widespread disruption caused during the critical end-of-year academic period and admitted to failures in communication. The vulnerability was identified in the support ticket system of the app's 'Free for Teacher' environment, which has since been disabled pending a full security review. While the platform is now fully operational, the incident highlights ongoing cybersecurity risks in the education technology sector. Instructure has committed to providing more consistent updates to affected institutions and users as they continue to investigate the extent of the breach and strengthen their security protocols.
Latest NewsInstructure Confirms Double Canvas Breach as ShinyHunters Sets Data Leak Deadline
Ed-tech giant Instructure has acknowledged two separate security breaches affecting its Canvas online learning platform within a two-week period. The cybercrime group ShinyHunters claims to have stolen 3.65 TB of data, comprising approximately 275 million records from nearly 9,000 educational institutions worldwide, including prestigious universities like Harvard and Stanford. The attackers exploited a vulnerability in the Free-for-Teacher system, leading to service disruptions during critical final exam periods. ShinyHunters has set a final pay-or-leak deadline of May 12 for individual schools to negotiate, threatening to publish the full dataset otherwise. Instructure stated that core learning data such as course content and credentials were not compromised, though usernames, emails, and messages were accessed. The company has temporarily disabled Free-for-Teacher accounts, rotated internal keys, and engaged CrowdStrike for forensic analysis. Authorities, including the FBI and CISA, have been notified. This incident marks Instructure's second breach in less than a year, following a separate Salesforce-related intrusion in late 2025, which the company maintains is distinct from the current Canvas security event.
www.theregister.com - ArticlesInstructure Canvas Hack Update: Breach Linked to Teacher Accounts Disrupts Finals
The hacking collective ShinyHunters targeted Instructure's Canvas learning management system twice in recent weeks, causing significant disruptions during school finals. The initial breach on April 30 compromised data from 275 million users across nearly 9,000 schools, including usernames, email addresses, and private messages, though no passwords were stolen. A week later, the group launched a second attack by defacing school-specific login pages and threatening to release the stolen data unless a settlement was negotiated. Instructure identified the vulnerability in its Free-For-Teacher account environment and temporarily disabled these accounts to secure the platform. While the second incident did not result in further data theft, the repeated downtime severely impacted students and educators attempting to submit assignments and take exams. Google searches for Canvas-related issues spiked by 1,000 percent, reflecting widespread frustration. Institutions like Seton Hall University and Baylor University acknowledged the disruption, with some postponing final exams. Instructure emphasized that securing the entire platform took precedence over maintaining access to specific account types during the security review.
MashableCanvas Breach Exposes Student Data as ShinyHunters Claims Responsibility
The cybercrime gang ShinyHunters has claimed responsibility for a significant breach of Instructure’s Canvas platform, a widely used learning management system in higher education. The attack potentially impacts approximately 9,000 customers, including prestigious institutions like Harvard, Georgetown, and Cornell universities. Hackers allegedly accessed sensitive data such as names, email addresses, student IDs, and private messages, which they threaten to weaponize for fraud, identity theft, and extortion. Following the intrusion, follow-on attacks defaced school login pages during final exam season, causing widespread disruption. While Instructure has restored services and removed the threat actor from their leak portal, questions remain regarding ransom negotiations. The FBI is investigating the incident, warning victims against paying ransoms or responding to unsolicited contacts, noting that hackers often exaggerate their access. Experts highlight that universities are prime targets due to their vast data repositories and open networks. The primary long-term risk involves sophisticated phishing and social engineering scams rather than immediate financial theft. Consequently, the House Homeland Security Committee has launched an investigation into the matter, underscoring the growing vulnerability of educational technology providers to cybercriminal exploitation.
Nextgov/FCW - All ContentCanvas Developer Apologizes for Data Breach as Class-Action Lawsuits Mount
Instructure, the parent company of the educational platform Canvas, has issued an apology following a significant security breach that disrupted final exams at numerous universities. The attack, attributed to the hacking group ShinyHunters, exploited a vulnerability in the Free-for-Teacher support ticket system, potentially exposing data on tens of millions of students across nearly 9,000 schools. Compromised information includes usernames, email addresses, course details, and private messages. In response, Instructure temporarily suspended the free service and launched a dedicated incident update page. Despite restoring services and removing the attackers, the company faces immediate legal repercussions, with at least 18 class-action lawsuits filed in the US. Plaintiffs allege severe privacy violations, citing the exposure of sensitive educational records containing confidential communications about health, disability, and safety issues. ShinyHunters initially claimed to have stolen data on 275 million individuals to extort a ransom. CEO Steve Daly acknowledged communication failures and promised further forensic reports, while the company conducts a full security review to prevent future incidents involving social engineering tactics used by the hackers.
PCMag.com - Technology Product Reviews, News, Prices & TipsCanvas Hack Disrupts Finals Week, Exposing Student Data to ShinyHunters
A significant cyberattack on Canvas, a widely used educational platform, caused widespread disruptions during the critical finals week for students and educators. The breach, attributed to the notorious hacking group ShinyHunters, exploited vulnerabilities in Free-for-Teacher accounts, forcing Instructure, the parent company, to temporarily shut down the service. Hackers defaced login portals with ransom messages, claiming to have stolen data from millions of students, teachers, and staff across thousands of institutions. While Instructure assured users that passwords and financial details remained secure, the attackers accessed usernames, email addresses, student IDs, and internal messages, raising concerns about potential phishing attacks. This incident marks another confrontation between ShinyHunters and Instructure, following a previous breach in 2025. The outage forced many schools to postpone exams or adjust deadlines, highlighting the heavy reliance of educational institutions on digital platforms. Although reports suggest negotiations may be underway as the target was removed from the hackers' leak portal, the event serves as a urgent wake-up call for schools to strengthen cybersecurity measures and establish robust backup plans to protect sensitive student data and ensure operational continuity during future digital threats.
Digital TrendsCanvas Cyberattack Disrupts Access for Students at Harvard, Columbia, and Hundreds of Schools During Finals
Instructure, the company behind the widely used learning management system Canvas, confirmed a significant cybersecurity incident that disrupted access for students at major universities, including Harvard and Columbia, as well as hundreds of other educational institutions during their final exam periods. Steve Proud, Instructure's Chief Information Security Officer, stated in an incident log that the disruption was caused by a criminal threat actor. The attack not only hindered academic activities but also resulted in a data breach. Proud later revealed that the exposed information included sensitive personal data such as names, email addresses, student ID numbers, and private messages exchanged on the platform. This incident highlights the vulnerability of critical educational infrastructure to cyber threats, particularly during high-stakes academic periods. The outage caused widespread inconvenience and stress for students relying on the platform for submitting assignments and accessing course materials. The revelation of compromised personal data raises further concerns regarding privacy and security protocols within educational technology services. As investigations continue, affected institutions and students are left to manage the immediate academic disruptions while addressing the long-term implications of the data exposure.
TechSpotCanvas Cyberattack Disrupts Global Universities During Finals Week
A major cybersecurity incident targeted Canvas, a widely used online learning management platform operated by Instructure, causing widespread outages for tens of thousands of students during critical final exam periods. The hacking group ShinyHunters claimed responsibility, alleging the theft of over 275 million records, including names, email addresses, and student ID numbers. The group threatened to leak private messages unless a ransom was paid by May 12. In response, Instructure took the system offline to contain the breach, while numerous universities, such as Cal Poly and Queensland University of Technology, suspended access or granted assessment extensions to mitigate academic impact. Authorities, including National Cyber Security Coordinator Michelle McGuinness, warned institutions and users about heightened phishing risks and advised against engaging with the threat actors. The attack affected educational institutions across the United States, Australia, Ireland, and other regions, highlighting significant vulnerabilities in digital education infrastructure. Services have begun to restore, but the full extent of the data compromise remains under investigation.
groundShinyHunters Claims Canvas Breach Affects Nearly 9,000 Schools
The cybercriminal group ShinyHunters has claimed responsibility for a massive data breach affecting Canvas, the learning management system developed by Instructure. The attackers assert that they have exfiltrated several terabytes of data containing personal information of approximately 275 million users across nearly 9,000 educational institutions globally. Initially announcing the breach on May 1, the group set a deadline for ransom payments, threatening to leak the data if their demands were not met. They criticized Instructure for ignoring communication attempts and merely applying security patches instead of negotiating. Consequently, ShinyHunters extended the payment deadline to May 12, advising affected schools to use the Tox messaging protocol for settlement discussions. The list of impacted institutions includes prominent universities such as Harvard, MIT, Cambridge, and Columbia, alongside numerous school districts. While reports vary regarding the specific data compromised, sources indicate that names, email addresses, student ID numbers, and user communications were stolen. However, sensitive information such as passwords, dates of birth, and financial details reportedly remained secure. This incident highlights significant cybersecurity vulnerabilities in widely used educational technology platforms.
CyberScoopShinyHunters Claims Canvas Breach Affects Nearly 9,000 Schools
The cybercriminal group ShinyHunters has claimed responsibility for a massive data breach affecting Canvas, the learning management system developed by Instructure. The attackers assert that they have exfiltrated several terabytes of data containing personal information of approximately 275 million users across nearly 9,000 educational institutions globally. Initially announcing the breach on May 1, the group set a deadline for ransom payments, threatening to leak the data if their demands were not met. They criticized Instructure for ignoring communication attempts and merely applying security patches instead of negotiating. Consequently, ShinyHunters extended the payment deadline to May 12, advising affected schools to use the Tox messaging protocol for settlement discussions. The list of potentially compromised institutions includes prestigious universities such as Harvard, MIT, Cambridge, and Columbia. While reports vary regarding the specific data types involved, indications suggest that names, email addresses, student ID numbers, and user communications were exposed. However, sensitive financial information, passwords, and dates of birth reportedly remain secure. This incident highlights significant cybersecurity vulnerabilities in widely used educational technology platforms and poses severe privacy risks for students and staff worldwide.
CyberScoop