ShinyHunters Breaches Canvas LMS Again, Threatens 9,000 Schools Data Leak

Original: Canvas online again as ShinyHunters threatens to leak schools data View original →

Read in other languages: 한국어日本語
Sciences May 8, 2026 By Insights AI (HN) 1 min read 2 views Source

The Second Strike

Instructure, the company behind Canvas LMS used by thousands of universities and schools worldwide, has suffered a second breach by ShinyHunters within a week. The group claims to have stolen data on 231 million people across approximately 9,000 schools globally and is threatening to publish the data on May 12 without a settlement payment.

How the Attack Unfolded

ShinyHunters defaced login pages at multiple schools Canvas portals by injecting HTML that replaced normal login screens with extortion messages. The stolen data allegedly includes student names, personal email addresses, and private messages between teachers and students. A first breach was disclosed on May 5; this second attack followed within two days.

Instructure Response

An Instructure spokesperson said the company discovered hackers had exploited an issue related to Free-For-Teacher accounts and temporarily shut those accounts down. Canvas has since been restored to full operation.

Context

ShinyHunters is a financially motivated cybercrime group with a long track record of high-profile breaches. The back-to-back attacks highlight a troubling pattern: education-sector platforms hold enormous quantities of sensitive student data while often lagging on security investment. The May 12 deadline approaches with the situation still unresolved.

Share: Long

Related Articles

Comments (0)

No comments yet. Be the first to comment!

Leave a Comment