Claim details
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.
Instructure confirmed two related Canvas intrusions through Free-for-Teacher accounts, exposing user, enrollment, course and message data and prompting a platform-wide outage on May 7, 2026. Main Canvas service returned, while Free-for-Teacher was discontinued after restricted content-retrieval windows, the last officially scheduled for July 28–29. Instructure confirmed paying the ransom, while institution-specific data delivery, message review and optional user notifications continued.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Unauthorized modification or replacement of website content.
Threats to publish or sell stolen data without evidence of encryption.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.
A primary service, system, platform, or operational capability became entirely unavailable.
A specific application or software platform became unavailable or unusable.
Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Services continued but with longer processing, response, delivery, or completion times.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
DysruptionHub’s published report documented that Instructure took Canvas offline for institutions worldwide on May 7, 2026, during a cybersecurity incident that disrupted exams, coursework, grading, and access to course materials. Instructure’s official incident hub confirms two related intrusions in which an unauthorized actor used Free-for-Teacher accounts, exploited privilege-escalation paths, and accessed Canvas data.
DysruptionHub assesses with high confidence that the event was a successful data-theft and extortion intrusion with broad downstream operational consequences. Instructure identifies ShinyHunters as the actor in its customer FAQ, which now explicitly acknowledges that the company paid the ransom. The public record does not establish file encryption, so the incident is confirmed data extortion rather than confirmed encrypting ransomware.
Canvas is a core learning-management platform for K-12 schools, colleges, and universities. The May 7 maintenance shutdown made Canvas, Canvas Beta, and Canvas Test unavailable during final exams and end-of-term grading. Institutions delayed exams, changed assignment and grading procedures, and prepared to continue academic work without the platform.
The disruption outlasted the general Canvas outage for Free-for-Teacher users. Instructure permanently discontinued that product and offered restricted windows for educators to retrieve course content. Its final official window ran July 28–29, creating sustained downstream effects for educators and students who depended on Free-for-Teacher for courses, grades, assignments, and instructional materials. Instructure also said enhanced post-incident security controls could temporarily delay some customer-support responses.
Instructure’s disclosures evolved from security notices and status updates to a detailed incident hub. The company says a malicious support ticket exploited a cross-site-scripting vulnerability when opened by a customer-service representative, allowing the actor to obtain an authorization token and elevated access. It says the May 7 re-entry used a second unpatched XSS flaw and an OAuth flow; monitoring detected and disabled that activity in about 10 minutes, and no additional data was taken during the second intrusion.
The company says the involved data fields included usernames, email addresses, course names, enrollment information, and messages, while core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved. Instructure is delivering institution-specific data packets weekly. Unstructured message data remains under forensic review, with delivery targeted for late September, and customers may opt into Kroll-supported user notifications that can include identity monitoring.
Instructure says it paid the ransom to reduce the risk of data distribution, received assurances and digital evidence that copies were deleted, and was told customers would not be extorted further. Those statements document the company’s response and the actor’s assurances; they do not independently prove that no other copy exists. The ransom amount and full agreement terms remain undisclosed.
Confidence is high that unauthorized access, data exfiltration, page defacement, material service disruption, and a ransom payment occurred because Instructure confirmed the attack path, affected data fields, remediation, payment, and outage. Confidence is high that ShinyHunters was responsible because Instructure identifies the group and describes both recent Canvas incidents as its activity.
No public evidence establishes file encryption. The ransomware-confidence field includes related data extortion, so the confirmed payment supports a confirmed value there without implying an encrypting ransomware payload. The complete population of affected institutions and individuals, exact record counts, and jurisdiction-specific notification scope remain unresolved.
Main Canvas service returned and Instructure says the known attack paths were remediated. Free-for-Teacher remained unavailable except for restricted retrieval windows, with the final official window ending July 29. Because that incident-related access limitation was documented within six days of August 4, DysruptionHub assesses the operational incident as active under its status lifecycle. The continuing forensic review and notification process are downstream breach-response work and do not independently extend the operational-impact clock.
The reviewed sources do not establish the complete initial-access sequence before the support ticket was opened, all exploited vulnerabilities, total dwell time, exact exfiltration volume, ransom amount, full agreement terms, or independent proof that every copied data set was deleted. They also do not provide a definitive count of affected schools, users, messages, courses, enrollment records, or legal notifications, or fully reconcile the first and second intrusion timelines.
Instructure identified ShinyHunters as the actor behind the direct Canvas incidents; public extortion messages threatened release of school data.
Instructure took Canvas offline for institutions worldwide during a cybersecurity incident, disrupting exams, coursework, grading, and access to course materials. Schools reported extortion messages appearing on Canvas pages and a ShinyHunters deadline threatening release of school data.
Instructure confirmed related April 29 and May 7 intrusions through Free-for-Teacher accounts. It said a malicious support ticket exploited XSS to obtain an authorization token and elevated access; a second XSS path enabled page changes before monitoring stopped the activity in about 10 minutes. The company said Canvas returned to service, Free-for-Teacher was discontinued, and institution-specific data delivery and message review continued.
Instructure’s customer FAQ identifies ShinyHunters, explicitly acknowledges that the company paid the ransom, and says it received assurances and digital evidence that copied data was deleted. It describes the support-ticket XSS and token-based access path, says ransom content appeared on roughly 300 institutional pages, and outlines ongoing institution-specific data delivery, message review and optional Kroll notifications.
Instructure said the involved data fields included usernames, email addresses, course names, enrollment information, and messages. It said core learning data such as course content, submissions, credentials, grades, and disciplinary records had not been identified as involved.
Instructure apologized for weeks of Free-for-Teacher disruption and offered a limited access window for educators to download course content. It described additional safeguards, system segregation, removed token-generation capabilities, and restricted functionality.
Signed-in members can report an error, update, or missing source.