HomeSecurityInstructure announces data breach - ShinyHunters responsible

Instructure announces data breach – ShinyHunters responsible

Another high-profile cybersecurity incident has rocked the education technology, as Instructure, one of the world’s largest edtech companies, confirmed that it suffered a security breach that led to a leak of user data. The attack was claimed by the notorious cyber-extortion group ShinyHunters, which claims to have gained access to a huge amount of sensitive information.

Instructure 

The case takes on particular significance given Instructure's position in the global education market. The company is best known for Canvas, one of the most popular learning management systems internationally, which is used by schools, universities and educational organizations for course management, assignment submission, teacher-student communication and distance learning.

What Instructure

Instructure announced on Friday that it is facing a cybersecurity incident, noting that it is already collaborating with specialized digital security researchers and competent authorities to investigate the incident.

In a later update, the company confirmed that there had been an exposure of user personal data , clarifying that the evidence so far shows a leak of information such as names, email addresses, student ID numbers and private messages between users of the platform.

At the same time, Instructure emphasized that there is no indication that passwords, dates of birth, government identifiers or financial data, which partially limits the risk of further financial fraud or direct account abuse.

However, experts warn that even the leakage of communications and basic identification data can be a serious tool for targeted phishing and social engineering attacks.

Instructure announces data breach - ShinyHunters responsible

ShinyHunters' claims are worrying

The case took on greater proportions when the group ShinyHunters listed Instructure on its data leak website, publishing particularly disturbing allegations.

According to the group, the attack affected nearly 9,000 schools worldwide, with a total of 275 million user records exposed. The information allegedly includes students, teachers, administrators, and other users of the Canvas ecosystem.

Even more worrying is the alleged leak of billions of private messages between students and teachers, as well as the report of a possible breach of the company's presence on Salesforce.

If these allegations are confirmed, this would be one of the largest data breaches in the digital education space.

The educational community facing a new digital risk

The modern educational process is now heavily dependent on cloud-based platforms like Canvas. This means that an incident of this magnitude doesn’t just affect one technology company, but could have a ripple effect across thousands of institutions.

Universities and schools store academic data, private correspondence, grades, course attendance data, and access information.

The possibility of exposing this data raises legitimate concerns about the privacy of students and teachers, as well as compliance with regulatory frameworks such as GDPR in Europe and FERPA in the United States.

Immediate protective measures

Instructure announced that it has already proceeded with security updates, enhanced system monitoring, and renewal of application keys as a preventive measure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company's customers are invited to reauthorize API integrationsin order to be issued new access keys.

At the same time, cybersecurity experts recommend that affected institutions activate additional control mechanisms, check access logs, and proactively inform students and staff of possible suspicious communications.

Instructure announces data breach - ShinyHunters responsible

The big question that remains

Despite official announcements, there are still significant information gaps: it is not known exactly when the breach occurred, how long the attackers had access to the systems, and whether there was an attempt at extortion.

The incident serves as yet another reminder that the rapid digitization of education must be accompanied by equally strong investments in cybersecurity. Otherwise, the technology that facilitates learning may become one of the most vulnerable points in the modern education ecosystem.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS