Instructure Paid ShinyHunters for Canvas Data. The Ransom Bought a Promise, Not Proof. 275 Million Records Claimed Exposed.
ShinyHunters breached Canvas LMS through a free teacher account flaw. Instructure paid the ransom. Data was already copied. 275M student records exposed.

Instructure, the company behind Canvas, a learning management system (LMS) used by thousands of schools and universities worldwide, paid the extortion group ShinyHunters after the group breached its platform and exfiltrated records ShinyHunters claims cover 275 million students and staff. Instructure has not independently confirmed that count. The payment bought a promise from the attackers that the data was destroyed. It did not buy proof.
Instructure said the breach was contained on May 2, then said so again on May 6, 2026. ShinyHunters proved otherwise: on May 7, the group defaced Canvas login pages at roughly 330 institutions with a new ransom note and a May 12 deadline. Only after that show of force did Instructure negotiate. The company agreed to pay on May 11, one day before the deadline and five days after the defacement, not before it. Instructure says it received digital confirmation of data destruction, shred logs supplied by the same group that stole the data. No outside party has verified that claim, and by design no one can: once data leaves a network, a shred log from the thief is the only evidence a defender ever gets.
The root cause was a vulnerability in Canvas's Free-For-Teacher account program, the same weakness Instructure had already named as the cause of the initial intrusion the week before. ShinyHunters used it to gain initial access, then escalated to exfiltrate student records, staff information, and private messages exchanged through the platform. Instructure confirmed the exposed data included names, email addresses, student ID numbers, and user messages, and said passwords, birth dates, and financial data were not affected. The inclusion of private messages makes this breach particularly dangerous for individuals. Educational-platform messages often contain personal disclosures, disciplinary discussions, and communications between students and faculty that were never intended for public exposure.
The Ransom Payment Paradox
Instructure's decision illustrates the impossible position organizations face during active extortion. Refuse to negotiate, and the attackers have already shown they will deface the platform at hundreds of institutions to force the issue. Pay, and the only evidence the criminals kept their word is a message from the same group that broke in and stole the data in the first place.
The data left Instructure's network in late April, weeks before any ransom was on the table. Paying on May 11 could not undo that. It could only buy a claim, delivered by the people who profited from stealing the data, that their copies had been destroyed. Nothing about that claim is independently verifiable. The incentive runs entirely one way: the extortionist has every reason to say yes, whether or not it is true.
This pattern has repeated across ShinyHunters' campaigns. The group's operational model depends on volume: breach many organizations, often through the same class of vulnerability, and run the extortion clock on each one at the same time. Snowflake customers in 2024, a Salesforce-linked campaign in March 2026, Canvas in May 2026, and an Oracle PeopleSoft zero-day used against more than 100 organizations in June 2026 all follow variations of the same playbook. Every organization that pays becomes a data point in the pitch to the next victim.
What Actually Protects Student Data
The durable defense is not negotiation after the fact. It is rendering exfiltrated data useless before it leaves.
Encrypt sensitive records at rest with customer-managed keys. If student records and messages are encrypted with keys that the application does not store alongside the data, exfiltration produces ciphertext, not personally identifiable information (PII). The attacker gets data they cannot read.
Implement zero trust access controls for administrative functions. The Free-For-Teacher account vulnerability suggests that account provisioning pathways were not subject to the same security controls as paid accounts. Every account type, free or paid, must pass through the same FIDO2 authentication (a passwordless login standard) and authorization checks.
Monitor for anomalous data export patterns. A single account querying records at this scale should trigger alerts long before exfiltration completes. Data loss prevention controls and anomalous query volume detection are essential for platforms holding this much PII.
Do not pay ransoms expecting protection. The evidence is clear: payment does not verify data destruction, it funds criminal operations, and it incentivizes future attacks against the same organization and its peers.
Key Takeaways
- ShinyHunters breached Canvas LMS through a vulnerability in the Free-For-Teacher account program tied to Instructure's initial intrusion in late April; the group claims 275 million student and staff records were exfiltrated, a number Instructure has not independently confirmed
- Instructure declared the breach contained twice, on May 2 and May 6, before ShinyHunters defaced Canvas login pages at roughly 330 institutions on May 7 with a new ransom deadline
- Instructure agreed to pay on May 11, after the defacement, not before it; the company says it received shred-log confirmation of data destruction that no outside party has verified
- Stolen data includes student and staff records and private messages; Instructure says passwords, birth dates, and financial data were not affected
- This is part of ShinyHunters' pattern: Snowflake customers (2024), a Salesforce-linked campaign (March 2026), Canvas (May 2026), and an Oracle PeopleSoft zero-day used against 100+ organizations (June 2026)
- Encryption at rest with customer-managed keys is the only control that survives data exfiltration; a ransom payment buys an unverifiable promise, not protection
Deepak Gupta is the co-founder and CEO of GrackerAI. He previously founded a CIAM platform that scaled to serve over 1B+ users globally. He writes about AI, cybersecurity, and digital identity at guptadeepak.com.
More from Deepak Gupta
Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:
- About Deepak Gupta
Founder, cybersecurity architect, and writer at guptadeepak.com.
- My journey
From LoginRadius (2013, 1B+ users) to GrackerAI, in milestones.
- Publications & patents
Books, free e-books, a journal special issue, and five granted patents.
- Research Hub
Curated research, buyer's guides, vendor comparisons, and technical deep-dives.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.