ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)
ShinyHunters Mass Defacement of Canvas LMS (TL-2026-0482), also tracked as Canvas LMS Mass Defacement May 2026, is a high-severity data breach, first published 2026-05-08. It is attributed to ShinyHunters with high confidence, affects Instructure Canvas LMS, maps to 19 MITRE ATT&CK techniques (T1071, T1078, T1110), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0482
- Threat ID
- TL-2026-0482
- Also known as
- Canvas LMS Mass Defacement May 2026, Instructure Re-Breach Extortion, ShinyHunters Canvas Campaign, Operation Canvas Defacement
- Severity
- HIGH
- Status
- MONITORING
- Category
- DATA_BREACH
- First published
- 2026-05-08
- Last reviewed
- 2026-05-08
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education, higher-education, k-12, public-sector, government
- Target regions
- North America, United States, Canada, Europe, United Kingdom, Australia, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in ShinyHunters Mass Defacement of Canvas LMS
Malware and tooling: TOX P2P messenger
ShinyHunters extortion gang defaced Canvas LMS login portals at approximately 330 educational institutions on May 7, 2026, posting extortion messages tied to a prior breach claim of 280 million records from 8,809 schools. Defacements were visible for ~30 minutes before Instructure took Canvas offline. The actor set a May 12, 2026 ransom deadline and uses TOX as its sole communication channel.
How ShinyHunters Mass Defacement of Canvas LMS works
On May 7, 2026, the financially motivated extortion crew known as ShinyHunters executed a coordinated mass defacement of Canvas Learning Management System (LMS) login portals belonging to approximately 330 schools, colleges, and universities operated on Instructure's multi-tenant cloud infrastructure. Defacement banners replaced the standard Canvas login experience with an extortion message demanding payment by May 12, 2026, and listed a TOX messenger ID as the sole contact channel. The defacements remained visible for roughly thirty minutes before Instructure detected the activity and proactively removed Canvas service worldwide to contain the incident, causing global outages across higher education and K-12 customers in the middle of a school day.
The defacement campaign is the public escalation of an earlier intrusion that Instructure first disclosed on April 28, 2026, when the company filed a brief incident notice. Two days later, ShinyHunters publicly claimed theft of data covering 8,809 schools and approximately 280 million records, including user records, private messages, and enrollment data. On May 1, 2026, Instructure confirmed unauthorized access to a portion of its Canvas environment but disputed the volume of data the actor claimed. The actor states the data was extracted via legitimate Canvas data export features and supported APIs rather than via a custom exploit, indicating either valid credential abuse, OAuth/API token theft, or compromise of an integrator account with administrative scope across many tenants.
No CVE has been assigned and no specific vulnerability has been disclosed by Instructure as of May 8, 2026. Public reporting attributes initial access to ShinyHunters' established TTP set: voice phishing (vishing) of help desks and IT staff at SaaS vendors and their customers, device-code phishing against Microsoft Entra, OAuth consent abuse against Salesforce and Microsoft 365, and exploitation of trusted third-party integrations. The same TTP profile drove ShinyHunters' 2024 Snowflake-related campaigns and the 2025 Salesforce data-loader OAuth attacks impacting dozens of large enterprises. ShinyHunters has been operating in close collaboration with Scattered Spider (UNC3944) since at least mid-2024, with the merged tradecraft sometimes tracked as ''Sp1d3rHunters'' or ''Scattered LAPSUS$ Hunters.''
For defenders, the immediate concerns are (1) potential additional waves of defacement or destructive action against tenants who refuse extortion before the May 12 deadline, (2) downstream credential reuse — Canvas usernames are typically institutional email addresses and password reuse among students and staff is endemic, and (3) targeted phishing using stolen private messages and enrollment context to launch high-confidence social-engineering attacks. Education sector security teams should treat any Canvas-integrated SaaS (Google Workspace, Microsoft 365, Zoom, Turnitin, Respondus, Proctorio, library systems) as in scope for credential-stuffing and BEC follow-on activity.
MITRE ATT&CK techniques used in TL-2026-0482
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
Credential Access
T1110 Brute Force; T1528 Steal Application Access Token; T1556 Modify Authentication Process
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Impact
T1489 Service Stop; T1491 Defacement; T1657 Financial Theft
Discovery
T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard
Exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in ShinyHunters Mass Defacement of Canvas LMS
- Instructure — Canvas LMS
Vulnerable versions: Cloud / SaaS multi-tenant deployments — all customer instances accessible during 2026-04-28 to 2026-05-07 window - Instructure — Canvas Data Services / Caliper Analytics API
Vulnerable versions: Production API endpoints (data export, REST API v1)
Remediation for ShinyHunters Mass Defacement of Canvas LMS
Patches
- No patch available — vulnerability or compromise vector has not been disclosed by Instructure (as of 2026-05-08)
- Apply all Instructure-issued security advisories as they are released via the Canvas Community trust portal
Immediate actions
- If you are an Instructure Canvas customer: rotate all Canvas API keys, OAuth client secrets, and LTI integration credentials immediately
- Force password reset for all Canvas users with elevated roles (admin, account admin, sub-account admin, observer with cross-account scope)
- Disable or audit all Canvas data export jobs running outside known maintenance windows
- Revoke and reissue any Canvas-issued OAuth tokens for downstream SaaS integrations (Google Workspace, Microsoft 365, Zoom, Turnitin)
- Block known TOX traffic at the network perimeter for non-essential workstations
- Issue an immediate help-desk advisory: do NOT honor any Canvas password-reset or MFA-bypass calls without out-of-band verification (vishing defense)
- Subscribe to Instructure''s status page and incident communications channel for breach scope updates
Workarounds
- Restrict Canvas administrative console access to a small allowlist of corporate IPs / VPN egress only
- Disable the Canvas data-portability export feature for non-admin roles via account settings
- Disable LTI 1.1 (legacy) integrations and require LTI 1.3 with OAuth 2.0 client credentials only
- Temporarily suspend any third-party Canvas integrations that are not actively in use during the May 12 extortion deadline window
Longer-term hardening
- Implement phishing-resistant MFA (FIDO2 / hardware security keys) for all SSO providers fronting Canvas
- Disable Microsoft Entra device-code authentication flow except for explicitly approved device enrollment use cases
- Adopt least-privilege scopes for all OAuth applications integrating with Canvas, Salesforce, Microsoft 365
- Establish a SaaS Security Posture Management (SSPM) program covering Canvas, Salesforce, M365, Google Workspace
- Mandatory vishing-resistance training for help desks: scripted out-of-band callback, multi-factor identity proofing for any privileged action
- Implement Conditional Access policies blocking risky sign-ins, anonymous proxies, and impossible travel events
- Deploy a dedicated education-sector threat intelligence feed and tabletop the ShinyHunters / Scattered Spider playbook quarterly
- Negotiate Canvas tenant-level audit log streaming (LRS / Caliper Analytics) into your SIEM for native monitoring
Weaknesses (CWE) in ShinyHunters Mass Defacement of Canvas LMS
CWE-285, CWE-287, CWE-200, CWE-863, CWE-639
Timeline of ShinyHunters Mass Defacement of Canvas LMS
- ShinyHunters threat group first publicly identified following Tokopedia (91M records) and Microsoft GitHub repository data leaks
- ShinyHunters launches Snowflake-related campaign exfiltrating data from 165+ organizations including AT&T, Ticketmaster, and Santander, establishing template for SaaS-platform mass extortion
- ShinyHunters / Sp1d3rHunters launches Salesforce data-loader OAuth abuse campaign against dozens of Fortune 500 enterprises, refining vishing + OAuth-consent tradecraft
- Instructure publicly discloses cyber incident affecting Canvas LMS environment; investigation begins
- ShinyHunters publicly claims theft of approximately 280 million records covering 8,809 schools and universities from Instructure
- Instructure confirms data breach but disputes the volume of records claimed by ShinyHunters
- Instructure takes Canvas LMS offline globally to contain defacement and remediate; major outage during school-day hours across North America
- ShinyHunters defaces Canvas login portals at approximately 330 educational institutions with extortion messages and a TOX contact ID; defacements visible for ~30 minutes
- Threadlinqs Intelligence publishes TL-2026-0482 with full TTP profile, IOCs, MITRE mapping, and detection coverage
- ShinyHunters extortion deadline expires; risk of additional defacement waves, public data leak, or destructive follow-on activity
- As of 2026-05-29, this specific Canvas incident is contained: Instructure restored service May 8, permanently shut the Free-For-Teacher access vector, and on May 11 reached a ransom deal with confirmed data destruction, so the May 12 deadline lapsed without a leak. ShinyHunters itself remains fully active (Udemy, Figure campaigns; June 2025 arrests hit only affiliates), so the actor and vishing/OAuth tooling persist.
Sources cited for ShinyHunters Mass Defacement of Canvas LMS
- Canvas login portals hacked in mass ShinyHunters extortion campaign
- Instructure confirms data breach, ShinyHunters claims attack
- Instructure hacker claims data theft from 8,800 schools, universities
- Edu tech firm Instructure discloses cyber incident, probes impact
- MITRE ATT&CK — T1491.002 External Defacement
- MITRE ATT&CK — T1566.004 Spearphishing Voice
- MITRE ATT&CK — T1528 Steal Application Access Token
- CISA Advisory — Vishing and SSO Targeting by Financially Motivated Threat Actors
Threats related to ShinyHunters Mass Defacement of Canvas LMS
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
- NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII Theft
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program
- FIFA World Cup 2026 Broadcast API Broken Access Control (Missing Server-Side Authorization) Allowed Live TV Stream Takeover
Detection coverage for TL-2026-0482
As of 2026-05-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0482 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.