Claim details
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.
Instructure confirmed two related Canvas intrusions that exposed user, enrollment, course and message data and prompted a platform-wide outage May 7, 2026. Canvas returned to normal service, and the final incident-related Free-for-Teacher retrieval window ended July 29; continuing data review and notifications are breach-response activities rather than an ongoing service disruption.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Unauthorized modification or replacement of website content.
Threats to publish or sell stolen data without evidence of encryption.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
A specific application or software platform became unavailable or unusable.
Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Services continued but with longer processing, response, delivery, or completion times.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
We reported that Instructure took Canvas offline for institutions worldwide May 7, 2026, during a security incident that disrupted exams, coursework, grading and access to course materials. Instructure’s official incident hub confirms two related intrusions in which an unauthorized actor used Free-for-Teacher accounts, exploited privilege-escalation paths and accessed Canvas data.
DysruptionHub assesses with high confidence that the event was a successful data-theft and extortion intrusion with broad downstream operational consequences. Instructure identifies ShinyHunters as the actor in its customer FAQ, which explicitly acknowledges that the company paid the ransom. The public record does not establish file encryption, so the incident is confirmed data extortion rather than confirmed encrypting ransomware.
Canvas is a core learning-management platform for K-12 schools, colleges and universities. The May 7 maintenance shutdown made Canvas, Canvas Beta and Canvas Test unavailable during final exams and end-of-term grading. Institutions delayed exams, changed assignment and grading procedures and prepared to continue academic work without the platform.
The disruption outlasted the general Canvas outage for Free-for-Teacher users. Instructure permanently discontinued that product and offered restricted windows for educators to retrieve course content. Its final official window ran July 28-29, creating sustained downstream effects for educators and students who depended on Free-for-Teacher for courses, grades, assignments and instructional materials.
Instructure’s disclosures evolved from security notices and status updates to a detailed incident hub. The company says a malicious support ticket exploited a cross-site scripting vulnerability when opened by a customer-service representative, allowing the actor to obtain an authorization token and elevated access. It says the May 7 re-entry used a second unpatched XSS flaw and an OAuth flow; monitoring detected and disabled that activity in about 10 minutes, and no additional data was taken during the second intrusion.
The company says the involved data fields included usernames, email addresses, course names, enrollment information and messages, while core learning data such as course content, submissions, credentials, grades and disciplinary records had not been identified as involved. Customer-specific data delivery and forensic review of unstructured DAP message data continued after service recovery, with Kroll-supported user notifications available to participating customers.
Instructure says it paid the ransom to reduce the risk of data distribution, received assurances and digital evidence that copies were deleted and was told customers would not be extorted further. Those statements document the company’s response and the actor’s assurances; they do not independently prove that no other copy exists. The ransom amount and full agreement terms remain undisclosed.
The operational disruption is resolved. Instructure says Canvas is fully back online, the known access paths were remediated and its external forensic partner found no evidence that the actor still had platform access. The Instructure status page showed Canvas and all other listed services operational August 16.
Free-for-Teacher remained permanently discontinued, and its final incident-related content-retrieval window ended July 29. Continuing forensic review, customer-specific data delivery and notification work are downstream breach-response activities; they do not establish continuing Canvas service disruption.
Confidence is high that unauthorized access, data exfiltration, page defacement, material service disruption and a ransom payment occurred because Instructure confirmed the attack path, affected data fields, remediation, payment and outage. Confidence is high that ShinyHunters was responsible because Instructure identifies the group and describes both related Canvas incidents as its activity.
No public evidence establishes file encryption. The ransomware-confidence field includes related data extortion, so the confirmed payment supports a confirmed value without implying an encrypting ransomware payload. The complete population of affected institutions and individuals, exact record counts and jurisdiction-specific notification scope remain unresolved.
The reviewed sources do not establish the complete initial-access sequence before the support ticket was opened, all exploited vulnerabilities, total dwell time, exact exfiltration volume, ransom amount, full agreement terms or independent proof that every copied data set was deleted. They also do not provide a definitive count of affected schools, users, messages, courses, enrollment records or legal notifications, or fully reconcile the first and second intrusion timelines.
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.

Instructure took Canvas offline for institutions worldwide during a cybersecurity incident, disrupting exams, coursework, grading, and access to course materials. Schools reported extortion messages appearing on Canvas pages and a ShinyHunters deadline threatening release of school data.
Instructure apologized for weeks of Free-for-Teacher disruption and offered a limited access window for educators to download course content. It described additional safeguards, system segregation, removed token-generation capabilities, and restricted functionality.
Instructure says Canvas is fully back online, the known access paths were remediated and its external forensic partner found no evidence that the actor still had platform access. Free-for-Teacher was permanently discontinued; continuing data delivery, DAP message review and notification support are post-incident response activities.
Instructure said the involved data fields included usernames, email addresses, course names, enrollment information, and messages. It said core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved.
Instructure’s customer FAQ identifies ShinyHunters, confirms payment of the ransom and describes the support-ticket XSS and token-based access path. As reviewed Aug. 10, data packets were still being sent weekly, DAP message review remained pending, and Kroll-supported notifications could include 24 months of identity monitoring.
Instructure’s official status page showed all systems operational August 16, including Canvas LMS, Canvas Catalog, Canvas Data 2, Canvas Mobile, support tools and listed regional infrastructure. The page showed no unresolved incident tied to the May Canvas intrusion.
Signed-in members can report an error, update, or missing source.