Claim details
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.
Instructure confirmed two related Canvas intrusions through Free-for-Teacher accounts, exposing user, enrollment, course and message data and prompting a platform-wide outage on May 7, 2026. Main Canvas service returned, while Free-for-Teacher was discontinued after restricted retrieval windows ending July 29; as of August 10, customer-specific data delivery continued, message review remained pending and Kroll-supported user notifications were being organized.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Unauthorized modification or replacement of website content.
Threats to publish or sell stolen data without evidence of encryption.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
A specific application or software platform became unavailable or unusable.
Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Services continued but with longer processing, response, delivery, or completion times.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
DysruptionHub’s published report documented that Instructure took Canvas offline for institutions worldwide May 7, 2026, during a security incident that disrupted exams, coursework, grading and access to course materials. Instructure’s official incident hub confirms two related intrusions in which an unauthorized actor used Free-for-Teacher accounts, exploited privilege-escalation paths and accessed Canvas data.
DysruptionHub assesses with high confidence that the event was a successful data-theft and extortion intrusion with broad downstream operational consequences. Instructure identifies ShinyHunters as the actor in its customer FAQ, which explicitly acknowledges that the company paid the ransom. The public record does not establish file encryption, so the incident is confirmed data extortion rather than confirmed encrypting ransomware.
Canvas is a core learning-management platform for K-12 schools, colleges and universities. The May 7 maintenance shutdown made Canvas, Canvas Beta and Canvas Test unavailable during final exams and end-of-term grading. Institutions delayed exams, changed assignment and grading procedures and prepared to continue academic work without the platform.
The disruption outlasted the general Canvas outage for Free-for-Teacher users. Instructure permanently discontinued that product and offered restricted windows for educators to retrieve course content. Its final official window ran July 28-29, creating sustained downstream effects for educators and students who depended on Free-for-Teacher for courses, grades, assignments and instructional materials.
Instructure’s disclosures evolved from security notices and status updates to a detailed incident hub. The company says a malicious support ticket exploited a cross-site scripting vulnerability when opened by a customer-service representative, allowing the actor to obtain an authorization token and elevated access. It says the May 7 re-entry used a second unpatched XSS flaw and an OAuth flow; monitoring detected and disabled that activity in about 10 minutes, and no additional data was taken during the second intrusion.
The company says the involved data fields included usernames, email addresses, course names, enrollment information and messages, while core learning data such as course content, submissions, credentials, grades and disciplinary records had not been identified as involved. As of Aug. 10, Instructure said customer-specific data packets were still being delivered weekly. Unstructured DAP message data remained under forensic review, and customers could opt into Kroll-supported user notifications that may include 24 months of identity monitoring.
Instructure says it paid the ransom to reduce the risk of data distribution, received assurances and digital evidence that copies were deleted and was told customers would not be extorted further. Those statements document the company’s response and the actor’s assurances; they do not independently prove that no other copy exists. The ransom amount and full agreement terms remain undisclosed.
The incident remains active. Main Canvas service returned, Instructure says the known access paths were remediated and its status page showed Canvas services operating normally Aug. 10. Free-for-Teacher remained permanently discontinued, with the final incident-related access window ending July 29. That date remains the latest documented operational impact.
The continuing forensic review, customer data delivery and notification process are downstream breach-response work. They do not establish that Canvas service remained disrupted after July 29 or provide a later operational-impact date.
Confidence is high that unauthorized access, data exfiltration, page defacement, material service disruption and a ransom payment occurred because Instructure confirmed the attack path, affected data fields, remediation, payment and outage. Confidence is high that ShinyHunters was responsible because Instructure identifies the group and describes both related Canvas incidents as its activity.
No public evidence establishes file encryption. The ransomware-confidence field includes related data extortion, so the confirmed payment supports a confirmed value without implying an encrypting ransomware payload. The complete population of affected institutions and individuals, exact record counts and jurisdiction-specific notification scope remain unresolved.
The reviewed sources do not establish the complete initial-access sequence before the support ticket was opened, all exploited vulnerabilities, total dwell time, exact exfiltration volume, ransom amount, full agreement terms or independent proof that every copied data set was deleted. They also do not provide a definitive count of affected schools, users, messages, courses, enrollment records or legal notifications, or fully reconcile the first and second intrusion timelines.
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.
Instructure took Canvas offline for institutions worldwide during a cybersecurity incident, disrupting exams, coursework, grading, and access to course materials. Schools reported extortion messages appearing on Canvas pages and a ShinyHunters deadline threatening release of school data.
Instructure apologized for weeks of Free-for-Teacher disruption and offered a limited access window for educators to download course content. It described additional safeguards, system segregation, removed token-generation capabilities, and restricted functionality.
Instructure confirmed related April 29 and May 7 intrusions through Free-for-Teacher accounts and said known access paths were remediated. Main Canvas remained online, Free-for-Teacher was permanently discontinued, customer-specific data delivery continued and DAP message review remained pending.
Instructure said the involved data fields included usernames, email addresses, course names, enrollment information, and messages. It said core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved.
Instructure’s customer FAQ identifies ShinyHunters, confirms payment of the ransom and describes the support-ticket XSS and token-based access path. As reviewed Aug. 10, data packets were still being sent weekly, DAP message review remained pending, and Kroll-supported notifications could include 24 months of identity monitoring.
Signed-in members can report an error, update, or missing source.