ShinyHunters breaches Canvas twice in a week holding 280 million education records hostage
On the night of May 7, students at universities across the world opened Canvas and found something other than their assignments. The login page had been replaced with a message from ShinyHunters: “rooting your systems since ’19 ;)”. Classes were paralyzed. Finals were disrupted. And the extortion group gave institutions until May 12 to negotiate a settlement.
This is the second time ShinyHunters hit Instructure in a single week.
The first breach came to light on May 1, when Instructure disclosed a “cybersecurity incident perpetrated by a criminal threat actor.” By May 3, ShinyHunters claimed it had stolen data on 275 million individuals and had access to “several billions of private messages.” They gave Instructure until May 6 to respond. The company did not pay. Instead, it patched the initial vulnerability and claimed the incident was contained.
It was not contained.
ShinyHunters came back on May 7 and defaced the Canvas login page directly. This time, they published a list of 8,809 affected institutions with record counts ranging from tens of thousands to several million per school. According to BleepingComputer, the group used Canvas data export features, including DAP queries, provisioning reports, and user APIs to harvest hundreds of gigabytes of user records, messages, and enrollment data.
The scope is staggering. CNN reports Columbia, Princeton, Harvard, and Georgetown were affected. School districts in at least a dozen US states reported impacts. ABC Australia confirmed universities, TAFE colleges, and state schools in Queensland and Tasmania were hit. The Herring reported 44 Dutch universities along with corporate Canvas clients including Anthropic, Apple, Cisco, and Amazon.
Instructure took Canvas offline entirely on Thursday, putting it in “maintenance mode.” By late Thursday night, the platform was restored for most users. But the damage was already done. Students lost access to course materials during finals week. Professors scrambled to distribute assignments through alternative channels. Multiple universities extended deadlines.
The compromised data includes names, email addresses, student ID numbers, locations of study, and private messages exchanged between users on the platform. Instructure claims no evidence of leaked passwords, dates of birth, government identifiers, or financial information. That claim is about to be tested. ShinyHunters has a well-documented history of selling stolen data on the dark web when ransom demands go unmet.
This is the same group behind the 2024 Ticketmaster breach and the Rockstar Games data leak. In 2024, the DOJ sentenced a member tied to the ShinyHunters name for posting stolen data from more than 60 companies on dark web forums. Mandiant reported earlier this year that the group uses sophisticated voice phishing and fake login pages to harvest employee credentials before extracting data from cloud platforms.
Instructure’s CISO Steve Proud said the company is “working quickly to understand the extent of the incident.” Australia’s national cyber security coordinator Michelle McGuinness is coordinating a response. Multiple universities have advised students not to log into Canvas until further notice and to be alert for phishing attempts.
The ransom deadline is May 12.
Sources: BleepingComputer, CNN, ABC Australia, Wikipedia, WIRED