ShinyHunters Claims Canvas Breach Affects 9,000 Schools, Demands Payment

ShinyHunters Claims Canvas Breach Affects 9,000 Schools, Demands Payment

ShinyHunters, a prolific criminal hacker and extortion group, claims to have breached Instructure’s Canvas learning management system, affecting nearly 9,000 educational institutions. CyberScoop reports the group exfiltrated several terabytes of data containing personal information from 275 million users. Initially setting a May 1 deadline for negotiations, ShinyHunters extended it to May 12 after Instructure reportedly failed to engage.

The group is now directly advising affected schools to seek security professionals and negotiate a “settlement” via the Tox messaging protocol. CyberScoop highlighted that the list of affected institutions includes numerous school districts and prominent universities such as Cambridge, Columbia, Cornell, Georgetown, Harvard, MIT, and UC Berkeley, among others. This incident marks what ShinyHunters claims is a repeat breach of Instructure’s systems.

This isn’t just a data dump; it’s a targeted extortion campaign against the institutions themselves. ShinyHunters’ direct outreach to schools, bypassing Instructure, signals a calculated move to maximize pressure and payouts. Their claim of Instructure’s inaction, whether true or not, is designed to erode trust and push schools to pay up.

What This Means For You

  • If your institution uses Canvas, assume your student and faculty data is compromised. Immediately assess your exposure based on the list ShinyHunters provided. Do not wait for Instructure to confirm; the attacker's calculus is to force your hand. Engage incident response, notify stakeholders, and prepare for potential data release, regardless of any negotiation attempts.

🛡️ Detection Rules

3 rules · 6 SIEM formats

3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

critical T1041 Exfiltration

ShinyHunters Canvas Data Exfiltration via Tox

Sigma YAML — free preview

Source: Shimi's Cyber World · License & reuse

✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Get rules for your SIEM →
Take action on this incident
📡 Monitor instructure.com Free · 1 watchlist slot · instant alerts on new breaches 🔍 Threat intel on Instructure All breaches, IOCs & vendor exposure

Related coverage on Instructure

GM Fined $12 Million in California Privacy Settlement Over Driver Data

GM has agreed to pay over $12 million in a privacy settlement with California officials, marking the largest fine issued under the California Consumer Privacy...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM /⚙ 2 Sigma

Kingdom Market Administrator Sentenced to 16 Years

Slovakian national Alan Bill, 33, has been sentenced to 16 years in prison after pleading guilty to conspiracy to distribute controlled substances. The Record by...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM /⚙ 3 Sigma

Virginia Man Convicted for Deleting 96 Government Databases

A Virginia man has been convicted on federal charges for deleting 96 government databases and illicitly accessing an individual’s email account through password theft. This...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM