ShinyHunters Claims Canvas Data Breach
Coverage from ABC13 Houston, The Setonian, and others
Articles
3
Active Days
2
The Topic

A security incident at Instructure temporarily disrupted Canvas, a learning management platform used by schools and universities, during final examinations and other academic activities. ShinyHunters claimed responsibility and alleged access to data from hundreds of millions of users, while Instructure reported unauthorized access involving names, email addresses, student ID numbers, and Canvas messages but said it had found no evidence of exposure of passwords, government identifiers, dates of birth, or financial information. The incident matters because a centralized education platform outage affected coursework, exams, and communications across institutions, while the scope of any data compromise remains under investigation.
First Article: 05/07/26
Latest Article: 05/08/26
Summary
- Canvas access was disrupted for educational institutions during finals and other academic activities.
- Instructure linked the incident to unauthorized access involving an issue related to Canvas Free-For-Teacher accounts.
- ShinyHunters claimed access to data from more than 275 million people across nearly 9,000 schools, but those figures were not independently confirmed in the reporting.
- Instructure reported exposure of names, email addresses, student ID numbers, and Canvas messages.
- Instructure said there was no evidence that passwords, dates of birth, government identifiers, or financial information were exposed.
- Schools and universities used temporary access measures, investigations, and guidance on exams, assignments, deadlines, and phishing risks.
History
The main update is a sharper attribution and scale claim: ShinyHunters now explicitly claims responsibility and alleges access to data from hundreds of millions of users, while Instructure’s account remains limited to confirmed categories of exposed information. The story also broadens slightly from a pure outage report to include ongoing investigation and phishing-risk guidance.
The main update is a sharper, more specific account of the breach: Instructure now says the incident involved Free-For-Teacher accounts and exposed particular user data categories, while ruling out several sensitive fields. ShinyHunters’ ransom and scale claims are also more explicit, but remain unverified.
