Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted — Threadlinqs Intelligence
As of 2026-07-26, Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted is a critical-severity data breach threat attributed to ShinyHunters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1705 · Severity: CRITICAL · Status: ACTIVE · Category: DATA_BREACH
Attribution: ShinyHunters · FINANCIAL
ShinyHunters breached Instructure's Canvas LMS in April-May 2026 via a Salesforce/Salesloft-Drift OAuth-token foothold and a Free-For-Teacher account flaw, exfiltrating 3.65TB (~275 million records)
On April 25, 2026, the financially motivated extortion collective ShinyHunters gained unauthorized access to Instructure's Canvas learning-management-system backend by abusing a support-ticket-related weakness in Canvas's Free-For-Teacher (FFT) self-service onboarding tier — a deliberate design choice that let unverified users provision accounts on the same shared infrastructure as paying institutional customers. This Canvas-specific intrusion did not occur in isolation: multiple threat-intel writeups (Push Security, Reed Smith, Huntress) trace ShinyHunters' initial foothold into Instructure's environment back to a September 2025 Salesforce tenant compromise, itself downstream of the group's August 2025 Salesloft/Drift OAuth-token-theft campaign, in which attackers compromised Salesloft's GitHub environment, used TruffleHog to harvest secrets, stole Drift OAuth integration tokens, and used them to access roughly 760 downstream Salesforce customer tenants (~1.5 billion records claimed across that broader campaign).
From April 28, 2026, the attacker used a hijacked session to call Canvas APIs directly, pulling usernames, email addresses, course names, enrollment records, and private in-product messages between students, teachers, and administrators — but not passwords, government identifiers, financial data, or core learning content (course submissions/credentials). Instructure detected the intrusion on April 29, revoked access, and on April 30 revoked additional suspicious sessions and moved to remediate the underlying FFT weakness. The company publicly disclosed the incident May 1 and briefly declared it contained on May 6.
On May 3, ShinyHunters listed Instructure on its data leak site, claiming ~275 million individuals across ~8,800-9,000 schools and threatening publication. When the May 8 deadline passed without payment, the group escalated on May 7 with a second, technically distinct intrusion: a stored cross-site-scripting bypass in the Canvas discussion feature, in which malicious HTML/JavaScript was encoded as Unicode escape sequences inside a MathJax `\unicode` LaTeX construct. The pre-render sanitizer saw only a benign-looking math expression; MathJax's renderer then decoded the escapes and emitted executable content into the DOM, granting the attacker administrator-level access. This was used to deface Canvas login/theme pages with ransom notes at roughly 330 institutions and force Canvas offline during exam season, disrupting institutions across the US, UK, Canada, Australia, New Zealand, Sweden, the Netherlands, Hong Kong, and Singapore.
Instructure CEO Steve Daly issued a public apology May 8. On May 11, one day before the group's final leak deadline, Instructure confirmed it had reached an agreement with the attackers — unconfirmed reporting places the payment near $10 million — under which the stolen 3.65TB dataset was reportedly returned along with 'shred logs' claimed as digital proof of destruction; legal counsel has publicly noted such assurances from criminal actors are unenforceable and unverifiable. Instructure's remediation included engaging CrowdStrike as forensic incident-response partner, deploying CrowdStrike Falcon EDR across its environment, and permanently discontinuing the Free-For-Teacher service.
The incident triggered a U.S. House Homeland Security Committee inquiry (Chairman Andrew R. Garbarino, formal request May 11), a class-action lawsuit filed May 13 in the U.S. District Court for the Southern District of California, coordination by Australia's National Office of Cyber Security, and an FBI IC3 public advisory (May 15) warning students, staff, and parents of follow-on harassment, swatting threats, and spearphishing built from the leaked student IDs, names, and private message content. The Identity Theft Resource Center's H1 2026 Data Breach Report subsequently identified this single incident as responsible for 275 of the 471 million total breach notices issued in the first half of 2026
Target sectors: education, government administration, technology
Target regions: North America, Europe, Asia-Pacific, Oceania
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, CRITICAL, threat intelligence, cybersecurity, T1583.001, T1585, T1588.002, T1593.003, T1566.002, T1199, T1190, T1528, T1552.001, T1110.004