Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments

Ransomware Negotiation Tactics (TL-2026-1476), also tracked as Instructure Canvas Breach, is a high-severity ransomware operation, first published 2026-07-18 and last reviewed 2026-08-14. It is attributed to ShinyHunters with medium confidence, affects Instructure Canvas LMS (Free-For-Teacher tier / multi-tenant SaaS, maps to 26 MITRE ATT&CK techniques (T1078, T1098, T1102), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-1476

Threat ID
TL-2026-1476
Also known as
Instructure Canvas Breach, Pay or Leak Instructure, CWT Ragnar Locker Payment, UCSF NetWalker Payment
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-18
Last reviewed
2026-08-14
Attribution
ShinyHunters
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
education, higher education, government administration, travel, hospitality, health, technology, saas
Target regions
North America, Global
Detection rules
9
Indicators of compromise
22
Updates
2026-08-14

Malware and tooling in Ransomware Negotiation Tactics

Malware and tooling: Mailto, Ragnar Locker - S0481, EvilTokens, TruffleHog - S9009, Tycoon2FA, Venom

ShinyHunters (operating under the federated Scattered LAPSUS$ Hunters banner) breached Instructure's Canvas LMS via Free-For-Teacher account abuse in April-May 2026, exfiltrating an estimated 280 million student/staff records across ~8,800-9,000 institutions and extracting a data-destruction settlement under a public 'pay or leak' extortion deadline. The case is examined alongside two landmark 2020 ransom-payment precedents — CWT Global's $4.5M Ragnar Locker payment and UCSF's $1.14M NetWalker payment — to document negotiation TTPs, extortion economics, and decision points defenders and incident responders face during live ransomware/extortion negotiations.

How Ransomware Negotiation Tactics works

In late April 2026, the extortion group ShinyHunters — now operating as part of the federated 'Scattered LAPSUS$ Hunters' (SLH) collective alongside Scattered Spider and LAPSUS$ — compromised education-technology vendor Instructure's Canvas Learning Management System. Unauthorized activity was first detected on April 29, 2026, with Instructure issuing public confirmation on May 1. The attackers exploited a flaw related to Instructure's 'Free-For-Teacher' freemium onboarding tier: these low-friction accounts shared backend infrastructure and data stores with paid institutional tenants, logically isolated but running on common systems. ShinyHunters leveraged this to obtain unauthorized access to production Canvas data, and evidence of login-page defacements at affected institutions suggests the actor achieved write access beyond standard user permissions (tenant configuration, UI customization, or front-end templates), consistent with a multi-tenant isolation bypass or privilege escalation.

ShinyHunters claimed responsibility on May 3, 2026, launching a public 'pay or leak' extortion campaign with an initial May 7 deadline (later extended to May 12) after which the group threatened to publish all stolen data. Instructure took Canvas offline and shut down the Free-For-Teacher program on May 7, restoring service May 8. The group claimed roughly 3.65TB of data — names, email addresses, student ID numbers, and 'several billions' of private student-teacher messages — covering approximately 275-280 million individuals across just under 9,000 (8,000-8,800+) institutions; passwords, dates of birth, government IDs, and financial data were reportedly not exposed. This marked ShinyHunters' second attack on Instructure within eight months, following a September 2025 Salesforce-periphery social-engineering incident. The extortion campaign drew U.S. congressional attention: the House Committee on Homeland Security requested executive testimony from Instructure leadership by May 21, 2026. Instructure ultimately reached a negotiated settlement/agreement with ShinyHunters, which included a data-destruction ('shred logs') clause; the group removed leak-site warnings, though the claim of destruction is unverified and consistent with the FBI's long-standing position that payment carries no restoration or non-disclosure guarantee.

The Instructure breach fits a broader 2025-2026 ShinyHunters/SLH operating pattern built on three recurring technique clusters documented by third-party researchers: (1) vishing-driven Adversary-in-the-Middle (AiTM) phishing, where operators impersonate IT support over voice calls to drive victims to lookalike SSO domains that relay credentials and MFA codes in real time and capture resulting session tokens (used against SoundCloud ~30M records, Panera Bread ~14M records, Match Group 10M+ records, ADT 5.5M people, from August 2025); (2) vishing combined with OAuth device-code phishing, where malicious applications impersonating legitimate integrations (e.g., a fake Salesforce 'DataLoader') request broad OAuth scopes and abuse the device-authorization grant flow to bypass MFA/passkey protections entirely (37.5x increase in device-code phishing activity since the start of 2026; kits observed include EvilTokens, Venom, and Tycoon2FA; named victims include Coca-Cola, Cisco, Qantas, and LVMH, with 1.5B+ records claimed across 1,000+ organizations); and (3) OAuth supply-chain compromise of third-party integrators, where compromised vendor GitHub repositories and OAuth token stores (harvested via secret-scanning tools such as TruffleHog) yield tokens that grant downstream access to customer SaaS/data-warehouse environments (Salesloft/Drift 2025 compromising 1,000+ Salesforce orgs; Anodot/Glassbox April 2026 exposing Snowflake/BigQuery data for Rockstar Games 78.6M records, Vimeo 119K records, and Zara 197K records).

To contextualize modern extortion-only tactics against traditional encrypt-and-extort ransomware, this research also documents two historical ransom-payment case studies referenced in the source analysis. In July 2020, global travel-management firm CWT Global was hit by Ragnar Locker ransomware, which shut down more than 30,000 computers and exfiltrated roughly two terabytes of sensitive corporate data (financial reports, security documents, employee emails, and salary information). Ragnar Locker operators initially demanded $10 million; following negotiation — during which a CWT-side negotiator cited COVID-19 pandemic financial hardship — the demand was reduced to $4.5 million, paid as 414 Bitcoin on July 28, 2020. The attackers demonstrated credibility by sharing a password-protected press release previewing the planned data leak, and after payment provided cloud-storage credentials to the stolen files and removed the leak announcement; the negotiation chat log was later made public. Separately, in June 2020, the University of California San Francisco (UCSF) suffered a NetWalker ransomware attack that encrypted servers within the School of Medicine, opportunistically (not specifically targeted) impacting COVID-19-adjacent antibody research data that could not be restored from backup. NetWalker operators initially demanded $3 million; UCSF's counter-offer of $780,000 led to a negotiated settlement of 116.4 Bitcoin (~$1.14 million), paid within roughly a day of the counter-offer. UCSF stated patient care operations and medical records were not affected and that no evidence indicated patient data was accessed.

Across all three cases, negotiation tradecraft follows a consistent pattern documented by the source analysis: pre-contact preparation (assembling a cross-functional response team spanning security, legal, business continuity, and executive leadership; forensic scoping of encryption/exfiltration; monitoring leak sites and extortion channels for subsidiary/executive exposure), and post-contact tactics (centralizing communications to prevent unauthorized concessions, using legitimate business processes such as approval workflows to buy time, maintaining detailed communication logs for law enforcement, and demanding proof-of-decryption on randomly selected sample files before payment). The FBI continues to discourage ransom payment on the grounds that it provides no restoration guarantee, incentivizes repeat targeting, and funds further criminal enterprise activity — a position illustrated by ShinyHunters' unverified 'shred logs' claim in the Instructure case and by the repeat targeting pattern (Instructure hit twice in eight months; NetWalker and Ragnar Locker both went on to hit additional healthcare, government, and enterprise victims after these payments).

MITRE ATT&CK techniques used in TL-2026-1476

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

Privilege Escalation

T1078 Valid Accounts

Persistence

T1098 Account Manipulation; T1136 Create Account

Command and Control

T1102 Web Service

Credential Access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft

Discovery

T1526 Cloud Service Discovery

Collection

T1530 Data from Cloud Storage

lateral-movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in Ransomware Negotiation Tactics

  • Instructure — Canvas LMS (Free-For-Teacher tier / multi-tenant SaaS platform)
    Vulnerable versions: Free-For-Teacher onboarding tier, production Canvas platform as of April 2026
    Fixed in: Free-For-Teacher program suspended/rebuilt; service restored May 8, 2026
  • CWT Global (Carlson Wagonlit Travel) — Corporate IT network / endpoint systems
    Vulnerable versions: Network as of July 2020
  • University of California San Francisco (UCSF) — School of Medicine server infrastructure
    Vulnerable versions: Servers as of June 2020
  • Salesloft / Drift — OAuth-integrated Salesforce connector
    Vulnerable versions: OAuth token store as of 2025
  • Anodot / Glassbox — Snowflake / BigQuery-integrated analytics connectors
    Vulnerable versions: OAuth tokens as of April 2026

Remediation for Ransomware Negotiation Tactics

Patches

  • Instructure: Free-For-Teacher program required a redesign/shutdown (taken offline May 7, 2026; service restored May 8, 2026 after remediation) rather than a discrete CVE patch

Immediate actions

  • Disable or heavily restrict freemium/trial account onboarding tiers (e.g. Free-For-Teacher) that share backend infrastructure with paid institutional tenants until tenant isolation is verified
  • Force credential rotation and session token invalidation for all Canvas/Instructure institutional accounts following the breach window (April 29 - May 8, 2026)
  • Assemble a cross-functional ransomware/extortion negotiation team in advance (security, legal, business continuity, executive leadership, outside counsel) rather than ad hoc during an incident
  • Monitor known ShinyHunters/SLH leak sites and Telegram channels for organizational or subsidiary mentions

Workarounds

  • Temporarily suspend freemium self-service signup flows for SaaS platforms serving regulated/sensitive data (education, healthcare) until isolation is independently verified
  • Require out-of-band voice verification for any IT-support-initiated password/MFA reset request to counter vishing-driven AiTM and device-code phishing

Longer-term hardening

  • Implement hard tenant isolation (separate data stores/back-end systems, not just logical separation) between freemium and paid SaaS tiers
  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) and disable legacy OAuth device-code authorization flows where not operationally required
  • Establish vendor/third-party OAuth token and supply-chain risk monitoring given repeat SLH targeting of integrator platforms (Salesloft/Drift, Anodot/Glassbox pattern)
  • Maintain immutable, offline/air-gapped backups sufficient to avoid ransom payment as the only recovery path (as UCSF lacked for encrypted research data)
  • Pre-negotiate law-enforcement (FBI) engagement procedures and legal/OFAC sanctions-screening review before any ransom payment is authorized

Weaknesses (CWE) in Ransomware Negotiation Tactics

CWE-284, CWE-269, CWE-863

Timeline of Ransomware Negotiation Tactics

  • NetWalker ransomware encrypts servers within the UCSF School of Medicine, impacting COVID-19-adjacent research data with no viable backup restoration path.
  • UCSF pays NetWalker operators 116.4 Bitcoin (~$1.14 million) after negotiating down from a $3 million demand via a $780,000 counter-offer.
  • CWT Global pays Ragnar Locker operators 414 Bitcoin (~$4.5 million), reduced from an initial $10 million demand, after a 30,000+ computer shutdown and 2TB data exfiltration.
  • Scattered LAPSUS$ Hunters (SLH) emerges on Telegram as a federated alliance blending Scattered Spider, ShinyHunters, and LAPSUS$ branding and operations.
  • ShinyHunters conducts its first attack against Instructure via Salesforce-periphery social engineering (approximate date; precedes the April 2026 Canvas breach by roughly eight months).
  • Unauthorized activity is first detected in Instructure's production Canvas LMS environment.
  • Instructure publicly confirms unauthorized activity in Canvas LMS.
  • ShinyHunters publicly claims responsibility for the Instructure breach and launches a 'pay or leak' extortion campaign with an initial May 7 deadline.
  • Reporting details the breach scope: approximately 280 million records (275-280M individuals) across roughly 8,000-8,800+ (claimed just under 9,000) institutions; U.S. House Committee on Homeland Security requests executive testimony by May 21.
  • Instructure takes Canvas offline and shuts down the Free-For-Teacher program; original extortion deadline extended to May 12.
  • Canvas service is restored following remediation of the Free-For-Teacher exploitation vector.
  • Extended ShinyHunters extortion deadline for full data publication passes.
  • DarkOwl publishes an analysis of ransomware/extortion negotiation tactics anchored on the Instructure breach and the historical CWT Global and UCSF cases, reporting that Instructure reached a settlement with ShinyHunters including a data-destruction claim and removal of leak-site warnings.

Update history for TL-2026-1476

  • 2026-08-14 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 12 community-related indicator(s).

Sources cited for Ransomware Negotiation Tactics

Threats related to Ransomware Negotiation Tactics

Detection coverage for TL-2026-1476

As of 2026-08-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1476 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1476

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats