Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments
Ransomware Negotiation Tactics (TL-2026-1476), also tracked as Instructure Canvas Breach, is a high-severity ransomware operation, first published 2026-07-18 and last reviewed 2026-08-14. It is attributed to ShinyHunters with medium confidence, affects Instructure Canvas LMS (Free-For-Teacher tier / multi-tenant SaaS, maps to 26 MITRE ATT&CK techniques (T1078, T1098, T1102), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-1476
- Threat ID
- TL-2026-1476
- Also known as
- Instructure Canvas Breach, Pay or Leak Instructure, CWT Ragnar Locker Payment, UCSF NetWalker Payment
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-18
- Last reviewed
- 2026-08-14
- Attribution
- ShinyHunters
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- education, higher education, government administration, travel, hospitality, health, technology, saas
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 22
- Updates
- 2026-08-14
Malware and tooling in Ransomware Negotiation Tactics
Malware and tooling: Mailto, Ragnar Locker - S0481, EvilTokens, TruffleHog - S9009, Tycoon2FA, Venom
ShinyHunters (operating under the federated Scattered LAPSUS$ Hunters banner) breached Instructure's Canvas LMS via Free-For-Teacher account abuse in April-May 2026, exfiltrating an estimated 280 million student/staff records across ~8,800-9,000 institutions and extracting a data-destruction settlement under a public 'pay or leak' extortion deadline. The case is examined alongside two landmark 2020 ransom-payment precedents — CWT Global's $4.5M Ragnar Locker payment and UCSF's $1.14M NetWalker payment — to document negotiation TTPs, extortion economics, and decision points defenders and incident responders face during live ransomware/extortion negotiations.
How Ransomware Negotiation Tactics works
In late April 2026, the extortion group ShinyHunters — now operating as part of the federated 'Scattered LAPSUS$ Hunters' (SLH) collective alongside Scattered Spider and LAPSUS$ — compromised education-technology vendor Instructure's Canvas Learning Management System. Unauthorized activity was first detected on April 29, 2026, with Instructure issuing public confirmation on May 1. The attackers exploited a flaw related to Instructure's 'Free-For-Teacher' freemium onboarding tier: these low-friction accounts shared backend infrastructure and data stores with paid institutional tenants, logically isolated but running on common systems. ShinyHunters leveraged this to obtain unauthorized access to production Canvas data, and evidence of login-page defacements at affected institutions suggests the actor achieved write access beyond standard user permissions (tenant configuration, UI customization, or front-end templates), consistent with a multi-tenant isolation bypass or privilege escalation.
ShinyHunters claimed responsibility on May 3, 2026, launching a public 'pay or leak' extortion campaign with an initial May 7 deadline (later extended to May 12) after which the group threatened to publish all stolen data. Instructure took Canvas offline and shut down the Free-For-Teacher program on May 7, restoring service May 8. The group claimed roughly 3.65TB of data — names, email addresses, student ID numbers, and 'several billions' of private student-teacher messages — covering approximately 275-280 million individuals across just under 9,000 (8,000-8,800+) institutions; passwords, dates of birth, government IDs, and financial data were reportedly not exposed. This marked ShinyHunters' second attack on Instructure within eight months, following a September 2025 Salesforce-periphery social-engineering incident. The extortion campaign drew U.S. congressional attention: the House Committee on Homeland Security requested executive testimony from Instructure leadership by May 21, 2026. Instructure ultimately reached a negotiated settlement/agreement with ShinyHunters, which included a data-destruction ('shred logs') clause; the group removed leak-site warnings, though the claim of destruction is unverified and consistent with the FBI's long-standing position that payment carries no restoration or non-disclosure guarantee.
The Instructure breach fits a broader 2025-2026 ShinyHunters/SLH operating pattern built on three recurring technique clusters documented by third-party researchers: (1) vishing-driven Adversary-in-the-Middle (AiTM) phishing, where operators impersonate IT support over voice calls to drive victims to lookalike SSO domains that relay credentials and MFA codes in real time and capture resulting session tokens (used against SoundCloud ~30M records, Panera Bread ~14M records, Match Group 10M+ records, ADT 5.5M people, from August 2025); (2) vishing combined with OAuth device-code phishing, where malicious applications impersonating legitimate integrations (e.g., a fake Salesforce 'DataLoader') request broad OAuth scopes and abuse the device-authorization grant flow to bypass MFA/passkey protections entirely (37.5x increase in device-code phishing activity since the start of 2026; kits observed include EvilTokens, Venom, and Tycoon2FA; named victims include Coca-Cola, Cisco, Qantas, and LVMH, with 1.5B+ records claimed across 1,000+ organizations); and (3) OAuth supply-chain compromise of third-party integrators, where compromised vendor GitHub repositories and OAuth token stores (harvested via secret-scanning tools such as TruffleHog) yield tokens that grant downstream access to customer SaaS/data-warehouse environments (Salesloft/Drift 2025 compromising 1,000+ Salesforce orgs; Anodot/Glassbox April 2026 exposing Snowflake/BigQuery data for Rockstar Games 78.6M records, Vimeo 119K records, and Zara 197K records).
To contextualize modern extortion-only tactics against traditional encrypt-and-extort ransomware, this research also documents two historical ransom-payment case studies referenced in the source analysis. In July 2020, global travel-management firm CWT Global was hit by Ragnar Locker ransomware, which shut down more than 30,000 computers and exfiltrated roughly two terabytes of sensitive corporate data (financial reports, security documents, employee emails, and salary information). Ragnar Locker operators initially demanded $10 million; following negotiation — during which a CWT-side negotiator cited COVID-19 pandemic financial hardship — the demand was reduced to $4.5 million, paid as 414 Bitcoin on July 28, 2020. The attackers demonstrated credibility by sharing a password-protected press release previewing the planned data leak, and after payment provided cloud-storage credentials to the stolen files and removed the leak announcement; the negotiation chat log was later made public. Separately, in June 2020, the University of California San Francisco (UCSF) suffered a NetWalker ransomware attack that encrypted servers within the School of Medicine, opportunistically (not specifically targeted) impacting COVID-19-adjacent antibody research data that could not be restored from backup. NetWalker operators initially demanded $3 million; UCSF's counter-offer of $780,000 led to a negotiated settlement of 116.4 Bitcoin (~$1.14 million), paid within roughly a day of the counter-offer. UCSF stated patient care operations and medical records were not affected and that no evidence indicated patient data was accessed.
Across all three cases, negotiation tradecraft follows a consistent pattern documented by the source analysis: pre-contact preparation (assembling a cross-functional response team spanning security, legal, business continuity, and executive leadership; forensic scoping of encryption/exfiltration; monitoring leak sites and extortion channels for subsidiary/executive exposure), and post-contact tactics (centralizing communications to prevent unauthorized concessions, using legitimate business processes such as approval workflows to buy time, maintaining detailed communication logs for law enforcement, and demanding proof-of-decryption on randomly selected sample files before payment). The FBI continues to discourage ransom payment on the grounds that it provides no restoration guarantee, incentivizes repeat targeting, and funds further criminal enterprise activity — a position illustrated by ShinyHunters' unverified 'shred logs' claim in the Instructure case and by the repeat targeting pattern (Instructure hit twice in eight months; NetWalker and Ragnar Locker both went on to hit additional healthcare, government, and enterprise victims after these payments).
MITRE ATT&CK techniques used in TL-2026-1476
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
Privilege Escalation
Persistence
T1098 Account Manipulation; T1136 Create Account
Command and Control
Credential Access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft
Discovery
Collection
lateral-movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
Reconnaissance
T1598 Phishing for Information
stealth
Affected products and versions in Ransomware Negotiation Tactics
- Instructure — Canvas LMS (Free-For-Teacher tier / multi-tenant SaaS platform)
Vulnerable versions: Free-For-Teacher onboarding tier, production Canvas platform as of April 2026
Fixed in: Free-For-Teacher program suspended/rebuilt; service restored May 8, 2026 - CWT Global (Carlson Wagonlit Travel) — Corporate IT network / endpoint systems
Vulnerable versions: Network as of July 2020 - University of California San Francisco (UCSF) — School of Medicine server infrastructure
Vulnerable versions: Servers as of June 2020 - Salesloft / Drift — OAuth-integrated Salesforce connector
Vulnerable versions: OAuth token store as of 2025 - Anodot / Glassbox — Snowflake / BigQuery-integrated analytics connectors
Vulnerable versions: OAuth tokens as of April 2026
Remediation for Ransomware Negotiation Tactics
Patches
- Instructure: Free-For-Teacher program required a redesign/shutdown (taken offline May 7, 2026; service restored May 8, 2026 after remediation) rather than a discrete CVE patch
Immediate actions
- Disable or heavily restrict freemium/trial account onboarding tiers (e.g. Free-For-Teacher) that share backend infrastructure with paid institutional tenants until tenant isolation is verified
- Force credential rotation and session token invalidation for all Canvas/Instructure institutional accounts following the breach window (April 29 - May 8, 2026)
- Assemble a cross-functional ransomware/extortion negotiation team in advance (security, legal, business continuity, executive leadership, outside counsel) rather than ad hoc during an incident
- Monitor known ShinyHunters/SLH leak sites and Telegram channels for organizational or subsidiary mentions
Workarounds
- Temporarily suspend freemium self-service signup flows for SaaS platforms serving regulated/sensitive data (education, healthcare) until isolation is independently verified
- Require out-of-band voice verification for any IT-support-initiated password/MFA reset request to counter vishing-driven AiTM and device-code phishing
Longer-term hardening
- Implement hard tenant isolation (separate data stores/back-end systems, not just logical separation) between freemium and paid SaaS tiers
- Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) and disable legacy OAuth device-code authorization flows where not operationally required
- Establish vendor/third-party OAuth token and supply-chain risk monitoring given repeat SLH targeting of integrator platforms (Salesloft/Drift, Anodot/Glassbox pattern)
- Maintain immutable, offline/air-gapped backups sufficient to avoid ransom payment as the only recovery path (as UCSF lacked for encrypted research data)
- Pre-negotiate law-enforcement (FBI) engagement procedures and legal/OFAC sanctions-screening review before any ransom payment is authorized
Weaknesses (CWE) in Ransomware Negotiation Tactics
CWE-284, CWE-269, CWE-863
Timeline of Ransomware Negotiation Tactics
- NetWalker ransomware encrypts servers within the UCSF School of Medicine, impacting COVID-19-adjacent research data with no viable backup restoration path.
- UCSF pays NetWalker operators 116.4 Bitcoin (~$1.14 million) after negotiating down from a $3 million demand via a $780,000 counter-offer.
- CWT Global pays Ragnar Locker operators 414 Bitcoin (~$4.5 million), reduced from an initial $10 million demand, after a 30,000+ computer shutdown and 2TB data exfiltration.
- Scattered LAPSUS$ Hunters (SLH) emerges on Telegram as a federated alliance blending Scattered Spider, ShinyHunters, and LAPSUS$ branding and operations.
- ShinyHunters conducts its first attack against Instructure via Salesforce-periphery social engineering (approximate date; precedes the April 2026 Canvas breach by roughly eight months).
- Unauthorized activity is first detected in Instructure's production Canvas LMS environment.
- Instructure publicly confirms unauthorized activity in Canvas LMS.
- ShinyHunters publicly claims responsibility for the Instructure breach and launches a 'pay or leak' extortion campaign with an initial May 7 deadline.
- Reporting details the breach scope: approximately 280 million records (275-280M individuals) across roughly 8,000-8,800+ (claimed just under 9,000) institutions; U.S. House Committee on Homeland Security requests executive testimony by May 21.
- Instructure takes Canvas offline and shuts down the Free-For-Teacher program; original extortion deadline extended to May 12.
- Canvas service is restored following remediation of the Free-For-Teacher exploitation vector.
- Extended ShinyHunters extortion deadline for full data publication passes.
- DarkOwl publishes an analysis of ransomware/extortion negotiation tactics anchored on the Instructure breach and the historical CWT Global and UCSF cases, reporting that Instructure reached a settlement with ShinyHunters including a data-destruction claim and removal of leak-site warnings.
Update history for TL-2026-1476
- 2026-08-14 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 12 community-related indicator(s).
Sources cited for Ransomware Negotiation Tactics
- Ransomware Negotiation Tactics and Real-Life Examples
- ShinyHunters Claims 280 Million Canvas Records Lifted from Instructure
- How three techniques are behind ShinyHunters' 2026 campaigns
- Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
- "PAY OR LEAK": Hackers Target Big Higher Ed Vendor
- Trinity of Chaos: The LAPSUS$, ShinyHunters, and Scattered Spider Alliance Embarks on Global Cybercrime Spree
- University of California San Francisco Pays $1.14 Million Ransom to Resolve NetWalker Ransomware Attack
- UCSF Pays $1.14M to NetWalker Hackers After Ransomware Attack
- First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn't get the memo
- CWT Travel Agency Faces $4.5M Ransom in Cyberattack, Report
- ShinyHunters Claims Second Attack Against Instructure
Threats related to Ransomware Negotiation Tactics
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations
Detection coverage for TL-2026-1476
As of 2026-08-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1476 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1476
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.