The recent cyberattack on Instructure’s Canvas, as the U.S. House of Representatives Homeland Security Committee has demanded an official briefing from the company on the scope of the breach and its impact. The incident has already been characterized as one of the most significant attacks to hit the educational technology space in recent years, with millions of students and educators directly affected.

The first breach was recorded on April 29 and, according to Instructure, was linked to misuse of tools that relied on API keys. Although the company said it had restored services by May 3, the situation worsened a few days later when the attackers returned and login portals school, causing a new wave of outages on May 7.
See also: Foxconn confirms ransomware attack on factories
ShinyHunters behind Canvas attack – Instructure
The cyberattack was claimed by the notorious ShinyHunters, which reportedly stole approximately 3.65 terabytes of data. The stolen files reportedly include personal information of up to 275 million students, teachers, and users from approximately 9,000 educational institutions worldwide.
This particular group has been linked in the past to major data breaches that affected companies such as Ticketmaster and AT&T, which reinforces the concerns of American authorities about the increasing aggression of organized cybercrime groups against critical digital infrastructure.
Canvas is considered one of the most widely used online learning internationally, serving over 30 million active users. For thousands of universities and schools, it is a key tool for exams, assignment submissions, storage of educational materials, and communication between students and teachers.
Agreement with hackers to delete data
In a move that has already sparked a backlash in the cybersecurity community, Instructure revealed that it had reached an agreement with the perpetrators to ensure the return and deletion of stolen data from the hackers’ servers. Although the company did not provide details on the nature of the agreement, many experts believe that it is a form of negotiation that likely includes financial compensation.
See also: RubyGems suspends account registrations due to attack

The company also announced that Free-For-Teacher accounts were the primary point of exploitation in both attacks. As a result, it has decided to temporarily disable the service until necessary security interventions.
This decision affects thousands of independent educators and small organizations who were using free access to the platform for distance learning and course management.
Concern about the educational technology sector
The Homeland Security Committee is now requesting full disclosure on how the breach occurred, what data was affected, and whether the company adequately cooperated with CISA and federal law enforcement.
In its official letter to Instructure, the Commission emphasizes that the incident does not only concern a private technology company, but touches on broader issues of national security and the protection of critical educational infrastructure. The cyberattack occurred at a particularly sensitive time, as millions of students in the US were in the process of final exams and completing semester assignments.
See also: TeamPCP breached Checkmarx's Jenkins AST Plugin
Authorities estimate that the May 7 disruption affected school districts and universities in at least 11 states, causing delays, exam cancellations and serious problems accessing educational services.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The new targets of cybercriminals
The Canvas case reveals that educational technology platforms are now becoming high-value targets for organized ransomware and data extortion. These systems collect vast amounts of personal data, academic records and login credentials, while often operating with limited cyber defense mechanisms compared to banking or government organizations.
Cybersecurity experts warn that education’s increasing reliance on cloud platforms is creating a new risk landscape, where a single breach can have a ripple effect across thousands of organizations simultaneously. For many edtech businesses, cybersecurity is no longer just a technical issue, but a critical factor in trust and sustainability.
