Canvas Outage: ShinyHunters Threaten to Leak Data of 275 Million Students
Patch the Canvas login page to remove defacement and verify authentication flow.
Patch the Canvas login page to remove defacement and verify authentication flow.
Summary
On 7 May 2026, Instructure’s learning‑management system Canvas was hit by a large‑scale ransomware‑style attack carried out by the hacking group ShinyHunters. The attackers released a ransom note on the platform, claiming to have accessed the personal data of roughly 275 million students, teachers and staff across about 9 000 schools worldwide. The compromised information included names, email addresses, student ID numbers and private messages. ShinyHunters set a deadline of 12 May 2026, threatening to publish the data publicly if their demands were not met.
In response, Instructure immediately placed Canvas, Canvas Beta and Canvas Test into maintenance mode and deployed a series of security patches to mitigate the breach. The company’s status page confirmed that normal operation would resume once the patches were fully applied. The incident has sparked concerns about GDPR compliance and the overall security posture of educational platforms, as the data breach potentially violates privacy regulations in the European Union and other jurisdictions.
The breach was independently verified by Bleeping Computer, which listed the affected schools and the volume of data at risk. Schools and administrators have been urged to engage cyber‑advisory firms and negotiate settlements before the deadline to prevent the public release of the stolen data. The threat of a mass leak has prompted a broader conversation about the vulnerability of digital learning environments and the need for stronger safeguards against cyber‑extortion.
The incident underscores the growing risk that educational institutions face from sophisticated ransomware groups and highlights the importance of proactive security measures, timely patching, and clear incident‑response protocols to protect sensitive student and staff information.
Key changes
- Canvas login page defaced with ransom demand
- Instructure disabled Canvas and replaced login with maintenance message
- Stolen data includes names, emails, student IDs, and messages but no passwords or sensitive info
- Ransom deadline moved from May 6 to May 12
- ShinyHunters claimed to have stolen data from 275 million students/faculty across ~9,000 institutions
- This is the third ShinyHunters breach in eight months
- Instructure’s status page says incident contained but platform offline
- ShinyHunters previously breached ADT, Medtronic, and other high-profile targets