Executive Summary
In early May 2026, Instructure's Canvas learning management system (LMS) suffered two significant cyberattacks orchestrated by the ShinyHunters group. The initial breach on April 29 led to the exfiltration of personal data from approximately 275 million users across nearly 9,000 educational institutions. Compromised information included names, email addresses, student ID numbers, and private messages. Despite Instructure's remediation efforts, ShinyHunters executed a second attack on May 7, defacing Canvas login pages to pressure the company into paying a ransom. In response, Instructure reached an agreement with the attackers, resulting in the return and purported destruction of the stolen data. (techcrunch.com)
This incident underscores a growing trend where cybercriminals target educational technology vendors to exploit vulnerabilities and access vast amounts of sensitive data. The attacks on Instructure highlight the critical need for robust cybersecurity measures within the edtech sector to protect against such large-scale breaches.
Why This Matters Now
The recent breaches of Instructure's Canvas LMS by ShinyHunters highlight the escalating threat to educational technology platforms, emphasizing the urgent need for enhanced cybersecurity measures to protect sensitive student and staff data from large-scale cyberattacks.
Attack Path Analysis
The ShinyHunters group exploited a vulnerability in Instructure's Free-For-Teacher program to gain unauthorized access to the Canvas platform. They escalated privileges to access sensitive data of 275 million users. The attackers moved laterally within the system to exfiltrate personal information, including names, email addresses, and private messages. They established command and control by defacing login pages and issuing ransom demands. The exfiltrated data was used to extort Instructure, leading to a ransom payment. The impact included significant disruption to educational institutions and potential identity theft risks for users.
Kill Chain Progression
Initial Compromise
Description
Exploited a vulnerability in the Free-For-Teacher program to gain unauthorized access to Canvas.
Related CVEs
CVE-2026-35273
CVSS 9.8A critical remote code execution vulnerability in Oracle PeopleSoft's Environment Management component allows unauthenticated attackers to execute arbitrary code.
Affected Products:
Oracle PeopleSoft – 8.61, 8.62
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Compromise Software Dependencies and Development Tools
Compromise Hardware Supply Chain
Valid Accounts
Phishing
Command and Scripting Interpreter
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Supply Chain Security
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Supply chain attacks targeting EdTech platforms expose student data, research IP, and financial records across thousands of institutions simultaneously through vendor compromise.
Primary/Secondary Education
K-12 schools face concentrated risk from EdTech supply chain attacks affecting learning management systems, student records, and operational continuity during critical periods.
Computer Software/Engineering
EdTech software vendors become high-value targets enabling mass institutional compromise through single-point-of-failure attacks affecting hundreds of thousands of users.
Information Technology/IT
Educational IT infrastructure requires enhanced segmentation, encrypted traffic monitoring, and zero trust controls to prevent lateral movement in supply chain compromises.
Sources
- EdTech Attackers Shift From Schools to Their Software Suppliershttps://www.darkreading.com/cyberattacks-data-breaches/edtech-attackers-shift-schools-software-suppliersVerified
- Instructure strikes deal with hackers who breached it twicehttps://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/Verified
- Oracle warns of security bug that hackers abused to breach 100+ companieshttps://techcrunch.com/2026/06/11/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/Verified
- ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploithttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not have prevented the initial exploitation, it could have constrained the attacker's subsequent actions by limiting unauthorized access paths.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security could have constrained lateral movement by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control could have limited the attacker's ability to establish command and control by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement could have constrained data exfiltration by monitoring and controlling outbound traffic.
While Aviatrix CNSF may not have entirely prevented the impact, it could have reduced the scope of disruption by limiting the attacker's reach and data access.
Impact at a Glance
Affected Business Functions
- Learning Management System (LMS) Operations
- Student Information Systems
- Online Course Delivery
- Examination and Grading Systems
Estimated downtime: 7 days
Estimated loss: $5,000,000
Personal information of approximately 275 million individuals, including names, email addresses, student ID numbers, and private messages.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enhance Threat Detection & Anomaly Response to identify and respond to unauthorized access attempts.
- • Utilize Egress Security & Policy Enforcement to monitor and control data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of vulnerabilities.
- • Establish a robust Supply Chain Management program to assess and monitor the security posture of third-party vendors.



