Last Update: 08/02/2026 at 3:34 PM EST

ShinyHunters Breaches and Defaces Canvas

Coverage from BleepingComputer, TechCrunch, and others

Articles

27

Active Days

70

The Topic

ShinyHunters Breaches and Defaces Canvas topic image

ShinyHunters compromised Instructure’s Canvas platform, stealing user information and later using cross-site scripting vulnerabilities to alter login portals for hundreds of educational institutions. Instructure temporarily restricted Canvas services, rotated application keys, and investigated the incident while the U.S. House Homeland Security Committee sought testimony about the breach’s scope and response. Instructure says the stolen data was returned and destroyed, but the volume of allegedly affected records and the final impact on institutions remain unsettled.

First Article: 05/03/26

Latest Article: 07/11/26

History

07/27/20260 new articles

The main shift is that the breach is now framed less as a completed incident and more as an unresolved, potentially broader campaign: the House committee has formally sought testimony, and the extent of records affected remains unsettled. The current version also clarifies that the portal tampering used cross-site scripting to alter login pages at roughly 330 institutions.

07/25/20260 new articles

The story has sharpened from a broad Canvas breach and extortion case into a more specific two-stage attack that used XSS to hijack administrative sessions and deface school portals. It also now includes congressional scrutiny and a second education-tech target, widening the implications beyond Instructure alone.

  • XSS vulnerabilities reportedly enabled authenticated administrative session access.
  • About 330 institutions saw Canvas login portals altered with ransom messages.
  • Instructure said ShinyHunters returned the data and supplied shred logs.
  • House Homeland Security Committee is seeking testimony on the attacks.
  • Infinite Campus was also targeted in a related ShinyHunters campaign.
07/24/20264 new articles

The story has broadened from the core Instructure/Canvas breach into a wider education-sector extortion pattern, with later reporting confirming a separate Glendale Community College leak tied to the same playbook. The newer framing also emphasizes response actions and confirmed exposure of school records, not just disputed claims about Canvas scale.

  • Glendale Community College was later hit by a related extortion leak.
  • Reported response now includes token revocation and law-enforcement involvement.
  • Confirmed exposure includes school records and enrollment-related data.
  • The incident window now extends into July 2026.
06/20/2026Topic Formed

Instructure confirmed a breach affecting Canvas users after ShinyHunters claimed to steal large volumes of student, teacher, and staff data from the education platform. The incident expanded from data theft claims into portal defacements and ransom pressure, prompting investigation, patching, API key rotation, and temporary service disruption. Public reporting centers on exposed contact information and messages, while the full scale of the alleged theft remains disputed.