Don’t do SECURITY. Do business SECURELY.
Threat intel

Hackers steal data from Canvas learning platform used by thousands of schools

ShinyHunters claims a breach of Instructure's Canvas platform, affecting nearly 9,000 schools and universities, then defaces login pages during exams.

Instructure, maker of the Canvas learning management system, disclosed a cyber attack in which data about students and staff was stolen. The extortion group ShinyHunters claimed responsibility, and later defaced Canvas login pages at many institutions during end-of-year exams.

What happened

  • Instructure said names, email addresses, student ID numbers, and messages on the platform were taken, but not passwords, dates of birth, government IDs, or financial data.
  • Nearly 9,000 schools and universities worldwide were reported to be affected, including in the US, Australia, and New Zealand. The hackers claimed data on 275 million people.
  • On 7 May 2026, login pages were defaced with ransom messages, disrupting access during finals.
  • On 11 May Instructure said it had reached an agreement with the attacker and received confirmation that the data had been destroyed, without disclosing the terms.

Why it mattered

The breach showed the concentration risk of shared education platforms and renewed debate about organisations negotiating with extortion groups.

Lessons for organisations

Review what data is held in SaaS platforms and whether it all needs to be there; data minimisation reduces the impact of any breach. Ask critical SaaS suppliers about their incident response and how they will communicate with you.

Sources: CBS News, TechCrunch

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights