:

INSTRUCTURE CONFIRMS DATA BREACH BY SHINYHUNTERS

AI DESK2 MIN READ
SUN, MAY 3, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Educational technology company Instructure has acknowledged a cyberattack in which the ShinyHunters extortion gang claims to have stolen user data. The breach affects the Canvas learning platform used by millions of students and educators worldwide.

Instructure, a major provider of learning management systems, disclosed the security incident after ShinyHunters publicly claimed responsibility for the attack. The threat actor group, known for targeting technology companies and attempting to extort payments by threatening to sell stolen data, confirmed they accessed Instructure's systems. The company confirmed that unauthorized access occurred but did not immediately disclose the full scope of compromised information. ShinyHunters' claims suggest the breach exposed customer data, though specific details about user records, credentials, or other sensitive information remain unclear. Instructure's Canvas platform serves educational institutions globally, hosting course materials, grades, and student information. The breach raises concerns about data security at organizations managing sensitive information for millions of users. The company stated it is investigating the incident and working with security professionals to understand what occurred. Instructure has not publicly detailed its response to ShinyHunters' extortion demands or timeline for notifying affected users. ShinyHunters has claimed credit for multiple high-profile breaches in recent years, typically stealing data and then attempting to sell it on dark web marketplaces or demanding ransom payments. Their claims in this case follow a pattern of publicly disclosing attacks to maximize pressure on targets. Instructure customers and users should monitor their accounts for suspicious activity and review security practices. The company is expected to provide more detailed incident information and remediation steps as its investigation progresses. This breach adds to a growing list of cyberattacks targeting educational technology providers, which handle extensive personal and academic data on vulnerable student populations.

■ SOURCES

Bleeping ComputerTechmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Artificial intelligence is becoming adept at finding and patching software vulnerabilities, potentially undermining governments' ability to deploy spyware and hacking tools. The development could spark renewed pressure for backdoors in encrypted devices.

JUST NOWAI Desk

New York Governor Kathy Hochul responded to 3D-printed gun creator Cody Wilson's new tool designed to circumvent state firearms laws, pledging to stay ahead of legal challenges to the state's restrictions.

1H AGOIndustry Desk

Chinese Fire Ant hackers have developed new techniques to turn Cisco IOS XR routers into covert surveillance platforms. Researchers discovered active GRE tunnel interfaces that left no trace in system configurations or commit histories.

1H AGOSecurity Desk

Berlin's city administration has confirmed that the Rhysida ransomware gang stole data and is attempting extortion after listing the city on their data leak site.

2H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.