Briefing

Canvas Outage: ShinyHunters Threaten to Leak Data of 275 Million Students

security
by BrianKrebs ·

Patch the Canvas login page to remove defacement and verify authentication flow.

What to do now

Patch the Canvas login page to remove defacement and verify authentication flow.

Summary

On 7 May 2026, Instructure’s learning‑management system Canvas was hit by a large‑scale ransomware‑style attack carried out by the hacking group ShinyHunters. The attackers released a ransom note on the platform, claiming to have accessed the personal data of roughly 275 million students, teachers and staff across about 9 000 schools worldwide. The compromised information included names, email addresses, student ID numbers and private messages. ShinyHunters set a deadline of 12 May 2026, threatening to publish the data publicly if their demands were not met.

In response, Instructure immediately placed Canvas, Canvas Beta and Canvas Test into maintenance mode and deployed a series of security patches to mitigate the breach. The company’s status page confirmed that normal operation would resume once the patches were fully applied. The incident has sparked concerns about GDPR compliance and the overall security posture of educational platforms, as the data breach potentially violates privacy regulations in the European Union and other jurisdictions.

The breach was independently verified by Bleeping Computer, which listed the affected schools and the volume of data at risk. Schools and administrators have been urged to engage cyber‑advisory firms and negotiate settlements before the deadline to prevent the public release of the stolen data. The threat of a mass leak has prompted a broader conversation about the vulnerability of digital learning environments and the need for stronger safeguards against cyber‑extortion.

The incident underscores the growing risk that educational institutions face from sophisticated ransomware groups and highlights the importance of proactive security measures, timely patching, and clear incident‑response protocols to protect sensitive student and staff information.

Key changes

  • Canvas login page defaced with ransom demand
  • Instructure disabled Canvas and replaced login with maintenance message
  • Stolen data includes names, emails, student IDs, and messages but no passwords or sensitive info
  • Ransom deadline moved from May 6 to May 12
  • ShinyHunters claimed to have stolen data from 275 million students/faculty across ~9,000 institutions
  • This is the third ShinyHunters breach in eight months
  • Instructure’s status page says incident contained but platform offline
  • ShinyHunters previously breached ADT, Medtronic, and other high-profile targets

Affects

enterprise

Source angles · 4 perspectives

Krebs on Security
Independent angle

Canvas Breach Disrupts Schools & Colleges Nationwide

Open
Bleeping Computer
Independent angle

Canvas login portals hacked in mass ShinyHunters extortion campaign

Open
Bleeping Computer
Independent angle

Instructure confirms hackers used Canvas flaw to deface portals

Open
Hacker News (front page)
Independent angle

Canvas Outage: ShinyHunters Threaten to Leak Data of 275 Million Students

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting