Instructure, maker of the Canvas learning management system, disclosed a cyber attack in which data about students and staff was stolen. The extortion group ShinyHunters claimed responsibility, and later defaced Canvas login pages at many institutions during end-of-year exams.
What happened
- Instructure said names, email addresses, student ID numbers, and messages on the platform were taken, but not passwords, dates of birth, government IDs, or financial data.
- Nearly 9,000 schools and universities worldwide were reported to be affected, including in the US, Australia, and New Zealand. The hackers claimed data on 275 million people.
- On 7 May 2026, login pages were defaced with ransom messages, disrupting access during finals.
- On 11 May Instructure said it had reached an agreement with the attacker and received confirmation that the data had been destroyed, without disclosing the terms.
Why it mattered
The breach showed the concentration risk of shared education platforms and renewed debate about organisations negotiating with extortion groups.
Lessons for organisations
Review what data is held in SaaS platforms and whether it all needs to be there; data minimisation reduces the impact of any breach. Ask critical SaaS suppliers about their incident response and how they will communicate with you.
Sources: CBS News, TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.