Full Breakdown
Canvas Hack: Instructure Reaches Deal with ShinyHunters
5/12/2026, 9:58:39 PM
Breach and Deal
Instructure detected unauthorized access to Canvas on April 29, 2026. The hacking group ShinyHunters claimed to have stolen data for roughly 275 million users at about 9,000 schools. After a second intrusion on May 7 that displayed ransom messages, Instructure temporarily shut Canvas down and on May 12 announced an agreement with the “unauthorized actor” to return the data and receive digital “shred logs” confirming its destruction. The company said no customers would be extorted.
Background & Context
Canvas serves over 30 million active users across North America, Europe, Australia and Canada. The breach exploited a flaw in the Free-for-Teacher demo accounts, a vulnerability previously targeted in a September 2025 incident. ShinyHunters, active since 2020, has previously attacked Ticketmaster and other high-profile firms.
Data Impact
The breach involved approximately 275 million records—names, email addresses, student IDs, enrollment details and private messages. No passwords, Social-Security numbers or financial information were found. The group claimed to have taken about 3.5 TB of data.
Why It Matters
The outage struck during final-exam periods, forcing postponements at several universities and disrupting coursework for millions of students. Exposed personal details enable targeted phishing, raising immediate security concerns. The incident also reignites debate over whether paying ransoms legitimizes cyber extortion.
Official Responses
Instructure said the steps taken aim to give customers “additional peace of mind” and asserted that “no Instructure customers will be extorted as a result of this incident, publicly or otherwise.” The company is working with expert vendors to harden its environment. The FBI reiterated its advice against paying ransoms, warning that such payments “do not guarantee data deletion.” The House Homeland Security Committee has requested a briefing from CEO Steve Daly on the breach and coordination with CISA.
Criticism
Cliff Steinhauer of the National Cybersecurity Alliance warned that ransom payments “create a dangerous feedback loop” and noted that “history shows data is often retained, resold, or used in future extortion attempts.” Allison Nixon of Unit 221B advised against paying ShinyHunters, citing the group’s inconsistent follow-through. Luke Connolly of Emsisoft said ransom payments “encourage the criminals to continue to look for new victims.”
Verbatim Quotes
- “While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible.” — Instructure statement
- “the data is deleted, gone. The company and its customers will not further be targeted or contacted for payment by us.” — ShinyHunters representative
- “Paying a ransom in a case like this can create a dangerous feedback loop where attackers are effectively rewarded for successful breaches. Even if organizations believe they are ‘resolving’ the immediate crisis, it reinforces the economic incentive structure behind cyber extortion.” — Cliff Steinhauer
- “if you are contacted directly by anyone claiming to have your data, we recommend you not send payment or respond to their demands.” — FBI
What’s Next
Instructure will host a webinar on May 13 to present forensic findings and outline further system hardening. Congressional oversight and coordination with CISA remain pending, while schools continue to monitor for phishing attempts using the exposed data.
