05/08/2026
On Tuesday, Instructure confirmed a security incident involving unauthorized access to student data, including names, email addresses, and messages exchanged between students and educators.
Shortly after, the company appeared to face another wave of disruption. A group associated with ShinyHunters reportedly defaced Canvas login pages for several schools, replacing them with a message demanding negotiations and threatening to release data on May 12 if no agreement is reached.❌
The altered pages temporarily affected access for some users, and parts of Instructure’s platform experienced instability, including maintenance notices and access errors.
ShinyHunters has previously claimed involvement in the earlier breach and said it obtained data from thousands of schools worldwide. The group is known for financially motivated attacks that combine data theft with public pressure tactics to force victims into paying.