Last Update: 08/02/2026 at 3:01 PM EST

ShinyHunters Breaches and Defaces Canvas

Coverage from BleepingComputer, TechCrunch, and others

Articles

27

Active Days

70

The Topic

ShinyHunters Breaches and Defaces Canvas topic image

ShinyHunters compromised Instructure’s Canvas platform, stealing user information and later using cross-site scripting vulnerabilities to alter login portals for hundreds of educational institutions. Instructure temporarily restricted Canvas services, rotated application keys, and investigated the incident while the U.S. House Homeland Security Committee sought testimony about the breach’s scope and response. Instructure says the stolen data was returned and destroyed, but the volume of allegedly affected records and the final impact on institutions remain unsettled.

First Article: 05/03/26

Latest Article: 07/11/26

Summary

  • ShinyHunters exploited vulnerabilities in Instructure’s Canvas environment to access user data and authenticated administrative sessions.
  • The attackers used the same weakness to modify login portals at approximately 330 educational institutions and display ransom demands.
  • Instructure reported exposure of names, email addresses, student ID numbers, and user messages, while saying it found no evidence of passwords, financial data, or government identifiers.
  • Canvas was temporarily taken offline, Free-for-Teacher accounts were restricted, and application keys were rotated before service restoration.
  • ShinyHunters claimed theft of hundreds of millions of records and more than 3.6 terabytes of data, but reported totals have not been independently verified.
  • Instructure says the stolen data was returned and destroyed; the company has not clearly disclosed whether a ransom was paid.
  • The House Homeland Security Committee requested testimony on containment, notification, data protection, and coordination with federal agencies.

History

07/27/2026

The main shift is that the breach is now framed less as a completed incident and more as an unresolved, potentially broader campaign: the House committee has formally sought testimony, and the extent of records affected remains unsettled. The current version also clarifies that the portal tampering used cross-site scripting to alter login pages at roughly 330 institutions.

07/25/2026

The story has sharpened from a broad Canvas breach and extortion case into a more specific two-stage attack that used XSS to hijack administrative sessions and deface school portals. It also now includes congressional scrutiny and a second education-tech target, widening the implications beyond Instructure alone.

Full History

Featured

Timeline: 70 Days

May 3May 17May 31Jun 7Jun 21Jul 5

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Lawrence Abrams05-12-2026
The U.S. House Homeland Security Committee asked Instructure CEO Steve Daly for testimony on ShinyHunters breaches of Canvas that exposed student data and disrupted schools.
BleepingComputer / Sergiu Gatlan06-15-2026
ShinyHunters claimed a March Salesforce-targeting attack on Infinite Campus, and Have I Been Pwned linked it to exposure of 137,100 school staff accounts.
TechCrunch / Lorenzo Franceschi-Bicchierai05-05-2026
Instructure confirmed a breach affecting student information after ShinyHunters claimed theft of names, personal emails, and teacher-student messages tied to Canvas.
Field Effect / Field Effect Security Intelligence Team05-06-2026
Instructure disclosed on May 3, 2026 a ShinyHunters-linked data leak exposing student identities and user messages at selected educational institutions.
Techzine Global / Erik van Klinken05-04-2026
Instructure confirmed a data breach affecting Canvas users, exposing student identifiers and messages after ShinyHunters claims of large-scale theft.
Hackread / Deeba Ahmed05-06-2026
ShinyHunters reportedly breached Instructure and Vimeo in 2026, exposing student and user records through vulnerability exploitation and Anodot token-based access.
Premier Christian News07-09-2026
Moody Bible Institute disclosed a cyberattack affecting over 2.3 million records, with leaked personal data reported via Have I Been Pwned.
HookPhish07-11-2026
Glendale Community College disclosed a reported June 15, 2026 ShinyHunters extortion incident in which alleged student records, including Social Security numbers, were published online.
shattered.io06-13-2026
ShinyHunters exploited two production vulnerabilities in Instructure Canvas during late April and May 2026, exfiltrating large volumes of student-related data and disrupting university course pages.
Have I Been Pwned07-11-2026
In June 2026, ShinyHunters allegedly published Glendale Community College student-enrollment data online after an extortion campaign, exposing email addresses and Social Security numbers.

⭐⭐⭐

BleepingComputer / Lawrence Abrams05-03-2026
Instructure disclosed a cybersecurity incident in Canvas after ShinyHunters claimed responsibility and posted an alleged data leak listing.
Mashable05-04-2026
ShinyHunters claimed a Canvas breach, and Instructure confirmed incident response steps after an April 30 disruption involving education platform user data.
CNET / Tyler Graham05-12-2026
Instructure said Canvas personal data stolen by ShinyHunters in an April 29 hack was deleted, with payment details unconfirmed and Free-For-Teacher access disabled during investigation.
SC Media07-06-2026
Moody Bible Institute reported a ShinyHunters-linked breach in 2.3 million records after unauthorized access and a public leak of sensitive PII.
TechEchelon / Sara Montes de Oca05-03-2026
Instructure confirmed Canvas user-identifying data exposure after a ShinyHunters-linked cyberattack, while ShinyHunters claims larger scope.
The Daily Pennsylvanian / Arti Jain, Luke Petersen, and Gabrielle Ostad05-07-2026
ShinyHunters disrupted University of Pennsylvania Canvas access on Thursday and threatened to leak data after a claimed Instructure breach, affecting multiple Canvas-using universities.
EdScoop05-07-2026
ShinyHunters extended Canvas breach extortion payments to May 12, claiming exposure of personal data for about 9,000 education institutions using Instructure.
Cybersecurity Insiders / Naveen Goud05-04-2026
ShinyHunters allegedly breached Instructure's Canvas system, and Instructure confirmed sensitive data access impacting thousands of schools.
Fox 5 Atlanta / Chris Williams05-07-2026
Instructure investigated Canvas outages and login disruptions after ShinyHunters claims of infiltration, with a reported data breach deadline for universities before May 12.
The CyberWire / N2K CyberWire staff05-08-2026
ShinyHunters defaced Instructure Canvas login portals for hundreds of schools and universities, and Instructure confirmed a breach involving user identifiers and messages.
LiveNOW from FOX05-07-2026
In the United States, ShinyHunters reportedly hacked Instructure's Canvas learning platform in early May, triggering outages and maintenance mode while Instructure withheld root-cause details.
Hjnews05-21-2026
Instructure reported unauthorized Canvas access beginning April 29, 2026, followed by ShinyHunters ransom activity and login defacement in early May 2026.
Mensjournal / Jessica McBride05-08-2026
ShinyHunters hacked Instructure's Canvas on May 7, set a May 12 student-data leak deadline, and caused school outages and login disablement across multiple U.S. states.
Almeida Law Group / Luke Coughlin06-17-2026
Moody Bible Institute faced an alleged June 2026 data leak after ShinyHunters claimed exfiltration of education, donor, and payroll records.