Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

906+ Articles
122+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Instructure Confirms Data Breach, ShinyHunters Claims Attack
Instructure Confirms Data Breach, ShinyHunters Claims Attack
NEWS

Instructure Confirms Data Breach, ShinyHunters Claims Attack

Educational technology giant Instructure has confirmed that data was stolen in a cyberattack, with the prolific ShinyHunters extortion gang claiming responsibility for the breach against the company behind Canvas LMS.

Dylan H.

News Desk

May 3, 2026
3 min read

Educational technology giant Instructure — the company behind Canvas LMS, one of the most widely deployed learning management systems in higher education — has confirmed that a cyberattack resulted in the theft of customer data. The notorious ShinyHunters extortion gang has claimed responsibility for the intrusion.

What Happened

Instructure disclosed the security incident after ShinyHunters publicly claimed to have breached the company's systems and threatened to leak stolen data. The group, which has been linked to dozens of high-profile data theft operations against major organizations, alleged they had obtained sensitive records belonging to Instructure customers and users.

The company confirmed the breach was genuine and that unauthorized parties had accessed and exfiltrated data, though Instructure has not yet disclosed the full scope of affected records or the specific types of data compromised in the attack.

Who Is ShinyHunters?

ShinyHunters is a well-established cybercriminal extortion group responsible for a string of major data breaches over the past several years. The group typically infiltrates company systems, exfiltrates large datasets, and then threatens to publish or sell the stolen information unless a ransom is paid.

Notable previous ShinyHunters targets include:

  • Ticketmaster / Live Nation — 560 million customer records (2024)
  • Santander Bank — tens of millions of customer and employee records
  • AT&T — call and text records for nearly all customers
  • Snowflake — leveraged compromised credentials across dozens of downstream customers
  • Canada Goose, Panera Bread, Figure Technology, Telus Digital, and many others

The group's targeting of Instructure follows a pattern of attacking organizations that hold large volumes of personally identifiable information (PII).

Impact on Education Sector

Instructure's Canvas LMS is used by thousands of educational institutions worldwide, including universities, colleges, K-12 school districts, and corporate training programs. A breach of this scope carries significant implications:

  • Student and faculty PII potentially exposed, including names, email addresses, and institutional identifiers
  • Academic records and course data may have been accessed
  • Single sign-on (SSO) credentials used by millions of learners could be at risk depending on what systems were interconnected

Educational institutions using Canvas should assume their affiliated user data may have been included in the exfiltrated records until Instructure provides further clarification.

What Instructure Is Doing

Instructure stated it is actively investigating the incident with the assistance of external cybersecurity experts. The company indicated it is working to determine the full extent of the breach and will notify affected customers and individuals as required by applicable data protection laws.

No specific timeline for notifications has been confirmed publicly.

Recommendations for Affected Users

If you or your institution uses Instructure's Canvas LMS or related products, consider taking the following steps:

  1. Change your Canvas account password immediately, especially if it is reused elsewhere
  2. Enable multi-factor authentication (MFA) on your Canvas account and any linked accounts
  3. Watch for phishing attempts targeting your institutional email address
  4. Monitor for suspicious account activity across any services linked to the same credentials
  5. Notify your institution's IT security team so they can assess exposure and take protective action

Ongoing Investigation

The full scope of the breach — including how many records were compromised and which specific data types were accessed — is still being determined. CosmicBytez Labs will update this story as more details become available from Instructure's ongoing investigation.


This story was published based on reporting from BleepingComputer. The previous draft of this article was retracted after BleepingComputer determined initial details were partially based on an older incident; this version reflects Instructure's confirmed disclosure.

#Data Breach#ShinyHunters#Education#Canvas LMS#Cybercrime

Related Articles

ADT Confirms Data Breach After ShinyHunters Leak Threat

Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to publish stolen data unless a ransom is paid,...

5 min read

ShinyHunters Breach Infinite Campus — K-12 Platform Serving 11 Million Students

ShinyHunters claimed a breach of Infinite Campus on March 22, 2026, after gaining access through an employee's Salesforce account. The K-12 student...

7 min read

ShinyHunters Dumps Harvard and UPenn Data After Ransom

The ShinyHunters cybercriminal syndicate has published stolen data from Harvard University and the University of Pennsylvania after both institutions...

5 min read
Back to all News