HomeSecurityCanvas hack: Instructure paid ransom to ShinyHunters

Canvas hack: Instructure paid ransom to ShinyHunters

US educational technology company Instructure, the parent company of the Canvas, announced that it has reached an agreement with the cybercriminal ShinyHunters following an attack that resulted in the theft of 3.65TB of educational data from thousands of schools and universities. The company’s decision to pay a ransom has sparked a backlash in the cybersecurity industry, as it violates official recommendations from the FBI and CISA that discourage such payments.

ShinyHunters Instructure

According to a statement released by the Utah -based company , the settlement covers all affected customers and includes the return of stolen data and digital confirmation that it was destroyed on the hackers' systems. Instructure also stressed that none of its customers will be individually blackmailed as a result of the attack.

See also: Venmo changes privacy defaults for new users

The cyberattack began in late April 2026, when ShinyHunters infiltrated the network of Canvas, one of the world's most popular learning management platforms serving over 8,000 educational institutions and 30 million active users.

Attackers exploited an unspecified vulnerability related to support tickets in the Free-for-Teacher environment to gain initial access and extract approximately 275 million files .

The stolen data includes usernames, email addresses, course names, registration information and messages from educational institutions around the world. Instructure clarified that course content, assignments and credentials were not compromised. However, cybersecurity experts warn that the exposed data provides enough personal information to conduct attacks phishing against staff, students and parents. This information can be used to craft highly persuasive messages that mimic official communications from educational institutions.

Canvas hack: Instructure paid ransom to ShinyHunters

Escalation of the ShinyHunters attack and negotiations

Although the breach was initially thought to be contained, a second wave of unauthorized activity was detected on May 7, 2026. ShinyHunters escalated the attack by spoofing Canvas login pages with extortion messages to approximately 330 institutions . The messages stated that Instructure had until May 12, 2026 to negotiate. Otherwise, the hackers would proceed to leak the stolen data online.

See also: Hackers abuse Google Ads and Claude.ai chats for Mac attacks

The ShinyHunters group is known for its strategy of targeting vendors with large user bases, operating as a decentralized organization without a single leader, which makes it resistant to capture. In the past 12 months, the group has been linked to major breaches including ADT in April 2026. The hackers gained access through a single vishing call to an employee. The group has also been linked to an attack on cryptocurrency platform Nobitex and the Microsoft Partner Network.

Instructure 's decision to pay the ransom is a rare public admission of such a practice and has drawn heavy criticism from the cybersecurity community . The company said : " While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every measure to give customers additional peace of mind ."

However, experts like Kevin Beaumont warn that such payments encourage further attacks and fund criminal organizations.

Canvas hack: Instructure paid ransom to ShinyHunters

Impact on the educational sector and protective measures

The attack caused a global outage, affecting students at over 50 universities including UC Irvine , Georgetown , Penn and Duke . Instructure 's market capitalization fell by 12% after the attack, while recovery costs are estimated at over $50 million including costs for security updates, forensic analysis and alerts.

See also: 10 signs that your account has been hacked

In response to the incident, Instructure temporarily suspended Free-For-Teacher accounts and revoked privileged credentials and access tokens for the affected systems. The company also restricted token generation paths, refreshed internal encryption keys, and implemented additional security controls . It is also working with specialized vendors to investigate and improve its overall cybersecurity posture.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS