EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-canvas-instructure-breach
034/430

File EL-0397HighResolvedData Breach / Ransomware / Extortion with Data Exfiltration

Canvas (Instructure) Data Breach

Also filed as ShinyHunters Canvas Hack · Instructure LMS Breach

A major cyberattack on Instructure's Canvas learning management system (LMS) involving data exfiltration and system defacement. The breach affected millions of students, teachers, and staff across thousands of educational institutions, exposing personal and communications data during a critical end-of-year period.

  • #education-data
  • #pii
  • #student-records
  • #private-messages
  • #ransomware
  • #extortion
  • #lms
Notoriety9/10
Event
25 Apr 2026
Disclosed
1 May 2026
Target
Instructure
Actor
ShinyHunters
Scale
275.0M people
Status
Resolved

01Summary

The breach, publicly surfaced in early May 2026, involved unauthorized access starting around April 25. ShinyHunters claimed responsibility, exfiltrating approximately 3.65 TB of data affecting ~275 million users across nearly 9,000 institutions. Exposed data included names, email addresses, student ID numbers, course/enrollment information, and private messages between users. Attackers exploited issues related to Free-For-Teacher accounts, leading to two incidents (initial access and a May 7 defacement/outage). Instructure paid a ransom; the group returned the data and confirmed its destruction.

02Background

Canvas is one of the world's most widely used LMS platforms, serving over 30 million active users at thousands of institutions. Its central role in education, including assignments, grading, and private communications, makes breaches particularly disruptive and privacy-sensitive.

03Key revelations

  1. 01Scale of interconnected educational data and communications exposed.
  2. 02Vulnerability of widely adopted SaaS education platforms.
  3. 03Successful ransom payment leading to data deletion confirmation.

04Technical analysis

Initial access leveraged vulnerabilities tied to Free-For-Teacher accounts. This enabled data exfiltration and later system changes for ransom note display. The second incident on May 7 caused widespread outages by defacing login pages. Instructure used monitoring and third-party forensics (including CrowdStrike) to contain and respond.

Attack vector
Exploitation of Free-For-Teacher account vulnerabilities
Attack method
Data exfiltration, system defacement, and extortion
Initial access
Account compromise / Vulnerability exploitation
Exfiltration
Bulk data extraction

Vulnerabilities exploited

  • Free-For-Teacher account vulnerabilities
  • Privilege escalation paths

05Threat actor

ShinyHunters is a prolific cybercriminal/extortion group known for targeting large datasets and high-profile organizations for financial gain.

Aliases

  • SH

Attribution sources

  • Ransomware.live
  • Instructure statements
  • Media reports

06Victims and impact

Additional victims

  • Thousands of universities, colleges, and K-12 school districts worldwide

Countries affected

  • United States
  • United Kingdom
  • Canada
  • Australia
  • New Zealand
  • Sweden
  • Netherlands
  • Hong Kong
  • Singapore

07Data exposed

Data types

  • PII
  • Student IDs
  • Email addresses
  • Private messages
  • Enrollment and course data

08Financial damage

Significant operational disruption during finals/exam periods; ransom payment reported (unconfirmed amount, rumors ~$10M); long-term costs for forensics, remediation, and potential lawsuits.

09Timeline

  1. 2026-04-25Initial unauthorized access.
  2. 2026-04-29Instructure detects intrusion and revokes access.
  3. 2026-05-01Incident disclosed.
  4. 2026-05-07Second attack; ransom notes displayed, outages begin.
  5. 2026-05-11Ransom agreement reached; data deleted.

10On the record

ShinyHunters has breached Instructure (again)...

ShinyHunters, Ransom note displayed on Canvas login pages

11Reaction and fallout

Public reaction

Widespread alarm over disruption during finals, privacy risks for students/teachers, and criticism of Instructure's initial communication.

Political impact

Increased scrutiny of education technology security; congressional investigations (e.g., House Homeland Security Committee).

12Legal

Class-action lawsuit filed; ongoing investigations.

Civil lawsuits

  • Class-action lawsuits related to data privacy and security failures

13Aftermath

Policy changes

  • Calls for stronger security standards in education SaaS platforms.

Security improvements

  • Temporary shutdown of Free-For-Teacher accounts
  • Enhanced monitoring (CrowdStrike Falcon)
  • Vulnerability remediation and environment hardening

14Significance and legacy

Significance

One of the largest education-sector breaches by scale, highlighting risks in cloud-based learning platforms and the impact on critical academic periods.

Legacy

Accelerated focus on securing educational data and communications; potential long-term shifts in vendor accountability and user trust in LMS platforms.

15Disclosure and media

Authentication
Ransom notes and samples shared by perpetrators

Publishing organisations

  • Ransomware.live
  • BleepingComputer
  • Major news outlets

16Field notes

  1. 01Attack timed to coincide with finals/exam periods at many institutions, maximizing disruption.
  2. 02ShinyHunters claimed access to 'several billions' of private messages.

17Resolution

Instructure reached an agreement with ShinyHunters. Data was returned and destroyed (with confirmation). Canvas restored to full operation with security enhancements.

18Sources

Wikipedia article ↗

Official documents

  • Instructure Incident Update page

References

  1. [1]Instructure official statements
  2. [2]Wikipedia entry
  3. [3]Media coverage (CNN, BBC, etc.)
Fact sheetEL-0397

Dates

Event
25 Apr 2026
Started
25 Apr 2026
Ended
12 May 2026
Duration
18 days
Discovered
29 Apr 2026
Disclosed
1 May 2026
Resolved
12 May 2026
Ongoing
No

Target

Organisation
Instructure, Inc.
Type
Technology Company
Sector
Education Technology
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through ransomware extortion and potential sale/leak of sensitive educational and personal data.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
275,000,000
Records
275,000,000
Volume
3.65 terabytes
Sensitivity
High
Published
No
Sold (dark web)
No

Money

Crypto
Likely (standard for ransomware/extortion)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.