✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Primary/Secondary Education
Breach intelligence, attack campaigns, and threat reports targeting the Primary/Secondary Education sector.
Explore Other Sectors
Primary/Secondary Education Threat Reports
Instructure's Canvas Platform Breached Twice by ShinyHunters in May 2026
In early May 2026, Instructure's Canvas learning management system suffered two significant cyberattacks by the ShinyHunters group. The initial breach on April 29 exposed sensitive data of approximately 275 million users across nearly 9,000 educational institutions, including names, email addresses, student ID numbers, and private messages. Despite Instructure's efforts to secure the system, ShinyHunters re-compromised Canvas on May 7, defacing login pages and issuing ransom demands. The attacks disrupted operations during critical exam periods, leading to delays and cancellations of final exams at numerous colleges and universities. In response, Instructure reached an agreement with the attackers, reportedly paying a ransom to secure the return and destruction of the stolen data, though the exact terms were not disclosed. This incident underscores the escalating threat of cyberattacks targeting educational institutions and the challenges in safeguarding sensitive student and staff information. ([techradar.com](https://www.techradar.com/pro/security/us-congress-calls-instructure-ceo-as-it-investigates-canvas-breach?utm_source=openai))
2 months ago
Kill Chain
Instructure Canvas Breach: A Wake-Up Call for Educational Cybersecurity
In May 2026, Instructure, the company behind the Canvas learning management system, suffered a significant data breach orchestrated by the hacking group ShinyHunters. The attackers exploited vulnerabilities to access and exfiltrate approximately 3.65 terabytes of data, affecting nearly 275 million individuals across 8,809 educational institutions worldwide. The compromised information included names, email addresses, student ID numbers, and private messages between students and staff. Following the initial breach, ShinyHunters escalated their attack by defacing Canvas login portals, disrupting access during critical academic periods and demanding a ransom to prevent the public release of the stolen data. This incident underscores the escalating threat posed by cybercriminal groups targeting educational institutions, highlighting the critical need for robust cybersecurity measures and incident response strategies. The breach also raises concerns about the effectiveness of paying ransoms, as Instructure's decision to negotiate with the attackers has sparked debate over best practices in handling such extortion attempts.
2 months ago
Kill Chain
Instructure's 2026 Data Breach: A Wake-Up Call for Educational Cybersecurity
In May 2026, Instructure, the company behind the Canvas learning management system, experienced a significant data breach orchestrated by the ShinyHunters extortion group. The attackers exploited vulnerabilities in the Free-for-Teacher environment, gaining access to over 3.6 terabytes of data, including usernames, email addresses, course names, enrollment information, and private messages from nearly 9,000 educational institutions worldwide. Following the initial breach, ShinyHunters defaced Canvas login portals, demanding a ransom to prevent the public release of the stolen data. Instructure reached an agreement with the attackers, who provided evidence of data destruction and assured that no extortion would occur against Instructure's customers. However, the FBI warns that paying ransoms does not guarantee that stolen data won't be sold or used in future attacks. This incident underscores the critical need for robust cybersecurity measures in educational platforms, especially as cybercriminal groups like ShinyHunters continue to target sensitive data for financial gain. Educational institutions must prioritize securing their digital infrastructures to protect against such threats.
2 months ago
Kill Chain
Instructure Canvas 2026 Cyberattacks: A Wake-Up Call for Educational Cybersecurity
In April and May 2026, Instructure's Canvas learning management system suffered two significant cyberattacks orchestrated by the ShinyHunters extortion group. The initial breach on April 29 led to the theft of personal information—including names, email addresses, student ID numbers, and user communications—from approximately 275 million individuals across nearly 9,000 educational institutions. Shortly after, on May 7, ShinyHunters executed a second attack, defacing Canvas login portals with ransom messages, disrupting access during critical final exams. Instructure responded by revoking compromised credentials, implementing security patches, and engaging forensic experts to investigate the incidents. ([apnews.com](https://apnews.com/article/3d55b9399ae87d49276f354e1c34c180?utm_source=openai)) These breaches underscore the escalating threats faced by educational institutions, particularly during pivotal academic periods. The incidents highlight the necessity for robust cybersecurity measures, proactive threat detection, and comprehensive incident response plans to safeguard sensitive student and staff data against increasingly sophisticated cybercriminal activities. ([apnews.com](https://apnews.com/article/209a51692f043a959459dbe37fb34e4b?utm_source=openai))
2 months ago
Kill Chain
Instructure's 2026 Data Breach: A Wake-Up Call for Educational Cybersecurity
In early May 2026, Instructure, the parent company of the Canvas learning management system, experienced a significant data breach executed by the cybercriminal group ShinyHunters. The attackers accessed 3.65 terabytes of data, affecting nearly 9,000 educational institutions and compromising personal information of approximately 275 million individuals, including names, email addresses, student ID numbers, and private messages. Although passwords and financial data were reportedly not compromised, the breach led to widespread disruptions, particularly during the critical final exam period. In response, Instructure reached an agreement with ShinyHunters to prevent the public release of the stolen data, receiving assurances of its destruction. The company has since implemented enhanced security measures and is conducting a comprehensive forensic analysis to prevent future incidents. ([apnews.com](https://apnews.com/article/3d55b9399ae87d49276f354e1c34c180?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational institutions. The breach highlights the critical need for robust cybersecurity frameworks, proactive threat detection, and comprehensive incident response plans to safeguard sensitive data and maintain operational continuity in the education sector.
2 months ago
Kill Chain
Instructure Canvas Data Breach: A Wake-Up Call for Educational Cybersecurity
In April 2026, Instructure, the company behind the Canvas learning management system, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers accessed personal information of approximately 275 million individuals across nearly 9,000 educational institutions, including names, email addresses, student ID numbers, and user communications. Although sensitive data such as passwords and financial information were reportedly not compromised, the breach led to widespread disruptions as Canvas was temporarily taken offline to mitigate further damage. ([instructure.com](https://www.instructure.com/incident_update?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting educational platforms. The breach highlights the critical need for robust cybersecurity measures and proactive incident response strategies within the education sector to safeguard sensitive user data and maintain operational continuity. ([malwarebytes.com](https://www.malwarebytes.com/blog/news/2026/05/shinyhunters-escalates-canvas-attacks-with-school-login-defacements?utm_source=openai))
2 months ago
Kill Chain
Instructure Canvas Breach 2026: A Wake-Up Call for Educational Cybersecurity
In April 2026, Instructure, the developer of the Canvas Learning Management System (LMS), experienced a significant data breach executed by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities in the Free-for-Teacher environment, leading to unauthorized access and the exfiltration of approximately 3.6 terabytes of data, affecting over 8,800 educational institutions and 275 million users. Compromised information included names, email addresses, student ID numbers, and private messages. Subsequently, in May 2026, ShinyHunters leveraged the same vulnerabilities to deface Canvas login portals, displaying ransom messages and demanding payment to prevent further data exposure. This incident underscores the critical need for robust security measures in educational platforms, especially as cybercriminals increasingly target the education sector. The exploitation of cross-site scripting (XSS) vulnerabilities highlights the importance of regular security assessments and prompt patching to mitigate such risks.
2 months ago
Kill Chain
ShinyHunters' 2026 Breach of Instructure's Canvas LMS: A Wake-Up Call for Educational Cybersecurity
In early May 2026, Instructure, the company behind the Canvas learning management system, suffered a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers accessed personal information of approximately 275 million individuals across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and billions of private messages exchanged between students and educators. Although Instructure reported that passwords and financial information were not affected, the breach led to widespread disruptions, including defaced login portals and service outages during critical academic periods. ([techradar.com](https://www.techradar.com/pro/security/canvas-school-login-portals-hacked-as-instructure-hack-apparently-gets-even-worse?utm_source=openai)) This incident underscores the escalating threat posed by cyber extortion groups targeting large-scale educational platforms. The breach highlights the vulnerabilities inherent in centralized educational systems and the potential for significant operational disruptions and data privacy concerns. Educational institutions must reassess their cybersecurity strategies to mitigate risks associated with third-party service providers and ensure the protection of sensitive user information. ([insidehighered.com](https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor?utm_source=openai))
2 months ago
Kill Chain
ShinyHunters Breach Canvas: 275 Million Users' Data Exposed
In early May 2026, the cybercriminal group ShinyHunters executed a data extortion attack on Instructure's Canvas learning management system, compromising personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. The breach exposed names, email addresses, student ID numbers, and private messages between students and faculty. The attackers defaced Canvas login pages with ransom demands, leading to widespread disruptions during critical academic periods, including final exams. ([apnews.com](https://apnews.com/article/446c240d5aeb1b1a1e3795fb92237563?utm_source=openai)) This incident underscores the escalating threat of cyberattacks targeting educational platforms, highlighting the urgent need for robust cybersecurity measures in the education sector. The timing of the attack, coinciding with final exams, emphasizes the potential for significant operational impact and the importance of proactive defense strategies against such threats.
2 months ago
Kill Chain
ShinyHunters' 2026 Canvas Data Breach: A Wake-Up Call for Educational Cybersecurity
In early May 2026, the cybercriminal group ShinyHunters executed a significant data breach targeting Instructure's Canvas learning management system. This attack compromised personal information—including names, email addresses, student ID numbers, and user communications—of approximately 275 million users across nearly 9,000 educational institutions worldwide. Notable universities such as MIT, Harvard, Oxford, and UC Berkeley were among those affected. The breach led to widespread disruptions, particularly as students were preparing for final exams. ([apnews.com](https://apnews.com/article/446c240d5aeb1b1a1e3795fb92237563?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups like ShinyHunters, who have a history of targeting educational platforms. The breach highlights the critical need for robust cybersecurity measures within educational institutions to protect sensitive data and maintain operational continuity. ([apnews.com](https://apnews.com/article/a0d7719689263e6b5f90d0e633391b5b?utm_source=openai))
2 months ago
Kill Chain
ShinyHunters' Exploitation of Instructure's Vulnerability Leads to Canvas Login Portal Defacements
In May 2026, the ShinyHunters extortion group exploited a vulnerability in Instructure's systems to deface Canvas login portals for approximately 330 educational institutions. The defacements displayed messages claiming responsibility for a prior breach and threatened to leak stolen data unless a ransom was paid by May 12, 2026. Instructure responded by taking Canvas offline to address the cyberattack. This incident underscores the escalating threat posed by cyber extortion groups targeting educational institutions. The breach highlights the critical need for robust cybersecurity measures and prompt incident response to protect sensitive student and staff data from unauthorized access and potential exploitation.
2 months ago
Kill Chain
Instructure Data Breach 2026: Lessons for Educational Institutions
In May 2026, Instructure, the company behind the Canvas learning management system, disclosed a significant data breach. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of 3.65 terabytes of data affecting approximately 275 million users across nearly 9,000 educational institutions. The compromised data includes names, email addresses, student ID numbers, and user communications. Instructure responded by revoking credentials, patching vulnerabilities, rotating keys, and enhancing monitoring. This incident underscores the critical need for educational institutions to assess and strengthen their third-party vendor security practices to protect sensitive student and staff information.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports