Instructure, the company behind the Canvas learning management system, disclosed that a criminal threat actor breached its environment and stole user data from affected educational institutions. The company said the exposed information included names, email addresses, student ID numbers, course and enrollment details, and messages between users, while it found no evidence that passwords, dates of birth, government identifiers, financial information, course content, or student submissions were compromised. Reporting tied the intrusion to the ShinyHunters extortion group, which claimed far broader impact—up to 3.65 TB of data and roughly 275 million records across nearly 9,000 schools—though those figures were not independently verified. Instructure said the attackers exploited flaws in its Free-for-Teacher environment, brought in outside forensic experts, notified law enforcement, revoked privileged credentials and access tokens, rotated keys, patched systems, and required some customers to reauthorize API access.
The incident escalated when attackers allegedly reused the same access path to deface Canvas login portals with ransom messages, prompting Instructure to temporarily take Canvas offline and suspend Free-for-Teacher accounts while it contained the activity. The outage disrupted universities and schools across the U.S., Canada, Australia, Europe, and Asia during final exams, forcing some institutions to postpone tests, extend deadlines, or block access as a precaution. Instructure later said it reached an agreement with the threat actor under which the stolen data was returned and deletion was purportedly confirmed, but the company acknowledged there is no guarantee criminals actually destroyed their copies. The breach has since triggered warnings about follow-on phishing and impersonation campaigns, lawsuits, and scrutiny from the U.S. House Homeland Security Committee over how the same platform was compromised twice in quick succession.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Instructure CEO Steve Daly issued a follow-up statement apologizing for the disruption and for inconsistent communication during the incident. The company said it would review its response, continue institution-by-institution impact analysis, and create a security and resilience advisory board.
The FBI issued a Public Service Announcement warning that ShinyHunters may exaggerate or fabricate claims to pressure victims and advising students, staff, and institutions not to engage with extortionists directly. The bureau urged victims to report incidents and preserve evidence.
On May 13, lawmakers intensified scrutiny by pressing Instructure to testify about how the same hackers allegedly exploited the same vulnerability twice. They sought details on notification, data exposure, and coordination with CISA and other agencies.
The House Homeland Security Committee requested a briefing from Instructure about the two attacks, the scope of stolen data, remediation, and coordination with federal authorities. Reporting described the request as part of a congressional inquiry into the incident.
Instructure said it reached an agreement with the threat actor under which the stolen data was returned and the company received digital confirmation, or 'shred logs,' indicating deletion. The company said affected customers would not be separately extorted, while acknowledging such assurances cannot be guaranteed.
Instructure later confirmed that attackers exploited multiple cross-site scripting vulnerabilities in Canvas to hijack authenticated administrator sessions and modify login portals. The company said the issue affected the Free-for-Teacher environment.
Instructure said it notified the FBI, CISA, and international law enforcement as it investigated the attacks. Later reporting also noted federal scrutiny and coordination with authorities.
By late May 8, Instructure said Canvas had become available again for most users after the containment actions. Some institutions continued to restrict access or assess local impact even after restoration.
Instructure said its investigation found no evidence that new data was taken during the May 7 defacement incident. The company linked the disruption to the earlier breach and said the later activity was aimed at extortion pressure.
The May 7 attack caused widespread outages across universities and schools in multiple countries during finals and other end-of-term activities. Institutions postponed exams, extended deadlines, and warned users about phishing and suspicious messages.
Instructure temporarily took Canvas offline on May 7 to investigate and contain the renewed attack. The company also shut down or suspended Free-for-Teacher accounts as part of containment.
On May 7, attackers returned and altered pages shown to logged-in users, displaying extortion messages attributed to ShinyHunters. Reports said roughly 330 school login portals were defaced in this second wave.
By May 6, Instructure said Canvas was fully operational and that it was not seeing ongoing unauthorized activity. Later reporting contrasted this statement with the renewed attack that followed.
Instructure said it notified affected schools about the earlier data-theft incident. This outreach occurred before the later disruptive defacement wave.
Reporting said ShinyHunters provided or published a list of roughly 8,000 to 8,809 allegedly affected schools and organizations. Named institutions included major universities, though the victim list was not independently verified.
After confirming the breach, Instructure said it deployed patches, increased monitoring, and rotated application keys or access tokens. Customers were required to re-authorize API access as part of the response.
ShinyHunters claimed responsibility for the breach and added Instructure to its leak site, alleging impact to nearly 9,000 schools and hundreds of millions of individuals. Multiple reports noted those scale claims were not independently verified.
Instructure confirmed that the incident resulted in theft of user data, including names, email addresses, student ID numbers, and messages among users. The company said it had no evidence that passwords, dates of birth, government identifiers, or financial information were involved.
Beginning May 1, some Canvas services including Canvas Data 2 and Canvas Beta were placed under maintenance. Customers were warned that tools relying on API keys could experience issues.
Instructure disclosed that it had recently experienced a cybersecurity incident caused by a criminal threat actor and said it was investigating with outside forensic experts. The company said it was working to determine scope and minimize impact.
Instructure later said it discovered the initial 2026 breach on April 29 after attackers accessed part of its environment. Reporting tied the intrusion to the Free-for-Teacher area and said user data was stolen in this first attack.
Instructure published an update about a separate security incident involving a social engineering attack on its Salesforce environment. Later reporting linked claims about that 2025 incident to ShinyHunters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceinstructure.com
Open sourcespcollege.edu
Open sourcecommunity.instructure.com
Open sourceupguard.com
Open sourceupguard.com
Open sourceupguard.com
Open sourcebsk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.