Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

980+ Articles
124+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak
NEWS

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65 TB Canvas Leak

Educational technology company Instructure, parent of Canvas LMS, has reached an undisclosed 'agreement' with the ShinyHunters extortion group after a breach of its network threatened to expose 3.65 TB of student and institutional data from thousands of schools and universities.

Dylan H.

News Desk

May 12, 2026
4 min read

Instructure, the American educational technology company behind the widely used Canvas LMS, has confirmed it reached an "agreement" with the decentralized cybercrime extortion group ShinyHunters following a breach of its network that threatened to expose 3.65 terabytes of stolen data affecting thousands of educational institutions.

The development follows a high-profile week that saw Canvas login portals targeted in a mass extortion campaign, multiple universities forced to reschedule final exams, and widespread disruption to schools and colleges nationwide.

The Breach and Extortion Campaign

ShinyHunters — a prolific threat group known for large-scale data theft and extortion — breached Instructure's network and exfiltrated a substantial dataset before issuing demands. The stolen data reportedly includes:

  • Student and faculty personally identifiable information (PII)
  • Institutional data from thousands of enrolled schools and universities
  • Authentication credentials and session data
  • Course content and academic records

ShinyHunters threatened to publicly release the 3.65 TB dataset if Instructure did not comply with their demands. Instructure's update confirming an "agreement" stops short of disclosing whether a ransom was paid and for how much.

Instructure's Response

In a public update, Instructure stated that it had reached an "agreement" with the cybercrime group and that the threatened data leak had been halted. The company:

  • Did not confirm whether a ransom payment was made
  • Did not disclose the terms of the "agreement"
  • Acknowledged that a breach of its network had occurred
  • Indicated that the scope of affected data was still being investigated

The use of the term "agreement" — rather than a denial of payment — is widely interpreted in the security community as an implicit acknowledgment that some form of transaction or negotiation took place.

Scale of Impact

Canvas LMS is one of the most widely deployed learning management systems in the United States and internationally, used by:

  • Over 6,000 educational institutions worldwide
  • Tens of millions of students and faculty members
  • K-12 school districts, community colleges, and major research universities

The breach occurred ahead of end-of-semester exam periods, causing maximum disruption. Multiple universities were forced to delay or reschedule final examinations as login access was disrupted during the ShinyHunters extortion campaign.

ShinyHunters: Recurring Education Sector Threat

ShinyHunters is a decentralized cybercrime group with a history of high-profile data theft operations:

IncidentYearRecords
Infinite Campus extortion threat202611 million student records
Telus Digital breach2026Undisclosed
ADT data breach20265.5 million customers
Medtronic breach20269 million records claimed
Canvas/Instructure20263.65 TB

The group has increasingly targeted education and healthcare sectors in 2026, where sensitive PII and the critical nature of disrupted services create leverage for ransom demands.

Why Paying Ransoms Is Problematic

The security community has long cautioned against paying extortion demands, for several reasons:

  1. No guarantee of deletion — There is no enforceable mechanism to ensure stolen data is actually deleted after payment
  2. Funds criminal operations — Payments directly finance further criminal activity and infrastructure
  3. Encourages future attacks — Successful extortion signals that the sector will pay, attracting more attackers
  4. Regulatory exposure — Ransom payments may raise OFAC sanctions compliance concerns if the receiving group has designated members
  5. Data may already be shared — Copies may exist across multiple actors before payment is received

The FBI and CISA consistently advise against paying ransoms and recommend reporting to law enforcement instead.

Lessons for Educational Institutions

The Canvas breach reinforces the elevated threat profile facing education sector organizations:

  • Centralized LMS platforms are high-value targets — A single breach can affect thousands of downstream institutions
  • Third-party risk is underappreciated — Institutions relying on Canvas had no direct control over Instructure's security posture
  • Student data requires heightened protection — PII for minors carries additional regulatory and ethical obligations under FERPA and COPPA
  • Incident response plans must account for LMS outages — Exam schedules, grade submissions, and coursework depend on platform availability

Bottom Line: Instructure's "agreement" with ShinyHunters averted an immediate data dump, but does not resolve the underlying breach. Affected institutions should communicate proactively with students, prepare for potential secondary exposure of the stolen data, and review their own security posture for any credentials or tokens that transited Canvas.

References

  • The Hacker News — Instructure Reaches Ransom Agreement with ShinyHunters

Related Reading

  • Canvas Login Portals Hacked in Mass ShinyHunters Extortion Campaign
  • Multiple Universities Forced to Reschedule Final Exams After Canvas Cyber Incident
  • Canvas Breach Disrupts Schools and Colleges Nationwide
#Data Breach#ShinyHunters#Canvas#Education#Ransomware#Extortion#Instructure

Related Articles

Canvas Breach Disrupts Schools & Colleges Nationwide

A data extortion attack against Canvas LMS defaced login pages with a ransom demand, disrupting classes and coursework at school districts and universities across the United States.

4 min read

Canvas Login Portals Hacked in Mass ShinyHunters Extortion Campaign

ShinyHunters has struck education technology giant Instructure again, exploiting a fresh vulnerability to deface Canvas login portals across hundreds of colleges and universities in a sweeping new extortion campaign.

3 min read

Multiple Universities Forced to Reschedule Final Exams After Canvas Cyber Incident

Dozens of universities were forced to reschedule final examinations after a cybercriminal group displayed threatening messages through Canvas, the widely used Instructure learning management system, disrupting end-of-term academic activities across multiple institutions.

6 min read
Back to all News