ShinyHunters Hacks Canvas LMS, Compromising Data of 275 Million Users
Instructure, the developer of the widely used Canvas Learning Management System (LMS), suffered a significant cybersecurity breach attributed to the extortion group ShinyHunters. The attack, which exploited a vulnerability in the platform's 'Free-For-Teacher' service, resulted in the theft of 3.65 terabytes of data affecting approximately 275 million students, teachers, and staff across 8,809 educational institutions globally. While Instructure stated that sensitive financial information and passwords were not compromised, personal details such as names, email addresses, and student IDs were exposed. ShinyHunters threatened to leak the data and defaced login pages of hundreds of institutions, causing widespread disruption to academic activities, including exam postponements at universities like Penn State and Idaho State. The incident highlights critical vulnerabilities in educational technology infrastructure and the risks of centralized data systems. Experts warn of potential follow-on phishing campaigns targeting affected communities. Despite Instructure's efforts to patch security flaws and revoke access tokens, the breach has sparked panic among users and raised serious concerns about data privacy and institutional resilience in the education sector.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection