History
07/27/20260 new articles
The main shift is that the breach is now framed less as a completed incident and more as an unresolved, potentially broader campaign: the House committee has formally sought testimony, and the extent of records affected remains unsettled. The current version also clarifies that the portal tampering used cross-site scripting to alter login pages at roughly 330 institutions.
07/25/20260 new articles
The story has sharpened from a broad Canvas breach and extortion case into a more specific two-stage attack that used XSS to hijack administrative sessions and deface school portals. It also now includes congressional scrutiny and a second education-tech target, widening the implications beyond Instructure alone.
- XSS vulnerabilities reportedly enabled authenticated administrative session access.
- About 330 institutions saw Canvas login portals altered with ransom messages.
- Instructure said ShinyHunters returned the data and supplied shred logs.
- House Homeland Security Committee is seeking testimony on the attacks.
- Infinite Campus was also targeted in a related ShinyHunters campaign.
07/24/20264 new articles
The story has broadened from the core Instructure/Canvas breach into a wider education-sector extortion pattern, with later reporting confirming a separate Glendale Community College leak tied to the same playbook. The newer framing also emphasizes response actions and confirmed exposure of school records, not just disputed claims about Canvas scale.
- Glendale Community College was later hit by a related extortion leak.
- Reported response now includes token revocation and law-enforcement involvement.
- Confirmed exposure includes school records and enrollment-related data.
- The incident window now extends into July 2026.
06/20/2026Topic Formed
Instructure confirmed a breach affecting Canvas users after ShinyHunters claimed to steal large volumes of student, teacher, and staff data from the education platform. The incident expanded from data theft claims into portal defacements and ransom pressure, prompting investigation, patching, API key rotation, and temporary service disruption. Public reporting centers on exposed contact information and messages, while the full scale of the alleged theft remains disputed.