Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments — Threadlinqs Intelligence
As of 2026-07-18, Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments is a high-severity ransomware threat attributed to ShinyHunters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1476 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: ShinyHunters · FINANCIAL
ShinyHunters (operating under the federated Scattered LAPSUS$ Hunters banner) breached Instructure's Canvas LMS via Free-For-Teacher account abuse in April-May 2026, exfiltrating an estimated 280
In late April 2026, the extortion group ShinyHunters — now operating as part of the federated 'Scattered LAPSUS$ Hunters' (SLH) collective alongside Scattered Spider and LAPSUS$ — compromised education-technology vendor Instructure's Canvas Learning Management System. Unauthorized activity was first detected on April 29, 2026, with Instructure issuing public confirmation on May 1. The attackers exploited a flaw related to Instructure's 'Free-For-Teacher' freemium onboarding tier: these low-friction accounts shared backend infrastructure and data stores with paid institutional tenants, logically isolated but running on common systems. ShinyHunters leveraged this to obtain unauthorized access to production Canvas data, and evidence of login-page defacements at affected institutions suggests the actor achieved write access beyond standard user permissions (tenant configuration, UI customization, or front-end templates), consistent with a multi-tenant isolation bypass or privilege escalation.
ShinyHunters claimed responsibility on May 3, 2026, launching a public 'pay or leak' extortion campaign with an initial May 7 deadline (later extended to May 12) after which the group threatened to publish all stolen data. Instructure took Canvas offline and shut down the Free-For-Teacher program on May 7, restoring service May 8. The group claimed roughly 3.65TB of data — names, email addresses, student ID numbers, and 'several billions' of private student-teacher messages — covering approximately 275-280 million individuals across just under 9,000 (8,000-8,800+) institutions; passwords, dates of birth, government IDs, and financial data were reportedly not exposed. This marked ShinyHunters' second attack on Instructure within eight months, following a September 2025 Salesforce-periphery social-engineering incident. The extortion campaign drew U.S. congressional attention: the House Committee on Homeland Security requested executive testimony from Instructure leadership by May 21, 2026. Instructure ultimately reached a negotiated settlement/agreement with ShinyHunters, which included a data-destruction ('shred logs') clause; the group removed leak-site warnings, though the claim of destruction is unverified and consistent with the FBI's long-standing position that payment carries no restoration or non-disclosure guarantee.
The Instructure breach fits a broader 2025-2026 ShinyHunters/SLH operating pattern built on three recurring technique clusters documented by third-party researchers: (1) vishing-driven Adversary-in-the-Middle (AiTM) phishing, where operators impersonate IT support over voice calls to drive victims to lookalike SSO domains that relay credentials and MFA codes in real time and capture resulting session tokens (used against SoundCloud ~30M records, Panera Bread ~14M records, Match Group 10M+ records, ADT 5.5M people, from August 2025); (2) vishing combined with OAuth device-code phishing, where malicious applications impersonating legitimate integrations (e.g., a fake Salesforce 'DataLoader') request broad OAuth scopes and abuse the device-authorization grant flow to bypass MFA/passkey protections entirely (37.5x increase in device-code phishing activity since the start of 2026; kits observed include EvilTokens, Venom, and Tycoon2FA; named victims include Coca-Cola, Cisco, Qantas, and LVMH, with 1.5B+ records claimed across 1,000+ organizations); and (3) OAuth supply-chain compromise of third-party integrators, where compromised vendor GitHub repositories and OAuth token stores (harvested via secret-scanning tools such as TruffleHog) yield tokens that grant downstream access to customer SaaS/data-warehouse environments (Salesloft/Drift 2025 compromising 1,000+ Salesforce orgs; Anodot/Glassbox April 2026 exposing Snowflake/BigQuery data for Rockstar Games 78.6M records, Vimeo 119K records, and Zara 197K records).
To contextualize modern extortion-only tactics against traditional encrypt-and-extort ransomware, this research
Weaknesses (CWE)
CWE-284, CWE-269, CWE-863
Target sectors: education, higher education, government administration, travel, hospitality, health, technology, saas
Target regions: North America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1598, T1583, T1588, T1585, T1566, T1078, T1199, T1195, T1098, T1136