Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809 Institutions Extorted
Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 (TL-2026-1705), also tracked as Canvas Data Breach, is a critical-severity data breach, first published 2026-07-26. It is attributed to ShinyHunters with high confidence, affects Instructure Canvas LMS (Free-For-Teacher accounts), maps to 20 MITRE ATT&CK techniques (T1020, T1078.004, T1098.005), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-1705
- Threat ID
- TL-2026-1705
- Also known as
- Canvas Data Breach, 2026 Canvas Data Breach, Instructure Incident
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-07-26
- Last reviewed
- 2026-07-26
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education, government administration, technology
- Target regions
- North America, Europe, Asia-Pacific, Oceania
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
Malware and tooling: DataLoader (attacker-controlled OAuth app), EvilTokens, RapeFlake, RapeForce, ToogleBox Recall, TruffleHog - S9009, Tycoon2FA, Venom
ShinyHunters breached Instructure's Canvas LMS in April-May 2026 via a Salesforce/Salesloft-Drift OAuth-token foothold and a Free-For-Teacher account flaw, exfiltrating 3.65TB (~275 million records) from 8,809 institutions in 100+ countries, then defaced Canvas login pages at ~330 schools to force a reported ~$10M ransom payment. ITRC's H1 2026 report names it the largest education-sector breach on record, accounting for 275 of 471 million total H1 breach notices (58%).
How Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 works
On April 25, 2026, the financially motivated extortion collective ShinyHunters gained unauthorized access to Instructure's Canvas learning-management-system backend by abusing a support-ticket-related weakness in Canvas's Free-For-Teacher (FFT) self-service onboarding tier — a deliberate design choice that let unverified users provision accounts on the same shared infrastructure as paying institutional customers. This Canvas-specific intrusion did not occur in isolation: multiple threat-intel writeups (Push Security, Reed Smith, Huntress) trace ShinyHunters' initial foothold into Instructure's environment back to a September 2025 Salesforce tenant compromise, itself downstream of the group's August 2025 Salesloft/Drift OAuth-token-theft campaign, in which attackers compromised Salesloft's GitHub environment, used TruffleHog to harvest secrets, stole Drift OAuth integration tokens, and used them to access roughly 760 downstream Salesforce customer tenants (~1.5 billion records claimed across that broader campaign).
From April 28, 2026, the attacker used a hijacked session to call Canvas APIs directly, pulling usernames, email addresses, course names, enrollment records, and private in-product messages between students, teachers, and administrators — but not passwords, government identifiers, financial data, or core learning content (course submissions/credentials). Instructure detected the intrusion on April 29, revoked access, and on April 30 revoked additional suspicious sessions and moved to remediate the underlying FFT weakness. The company publicly disclosed the incident May 1 and briefly declared it contained on May 6.
On May 3, ShinyHunters listed Instructure on its data leak site, claiming ~275 million individuals across ~8,800-9,000 schools and threatening publication. When the May 8 deadline passed without payment, the group escalated on May 7 with a second, technically distinct intrusion: a stored cross-site-scripting bypass in the Canvas discussion feature, in which malicious HTML/JavaScript was encoded as Unicode escape sequences inside a MathJax `\unicode` LaTeX construct. The pre-render sanitizer saw only a benign-looking math expression; MathJax's renderer then decoded the escapes and emitted executable content into the DOM, granting the attacker administrator-level access. This was used to deface Canvas login/theme pages with ransom notes at roughly 330 institutions and force Canvas offline during exam season, disrupting institutions across the US, UK, Canada, Australia, New Zealand, Sweden, the Netherlands, Hong Kong, and Singapore.
Instructure CEO Steve Daly issued a public apology May 8. On May 11, one day before the group's final leak deadline, Instructure confirmed it had reached an agreement with the attackers — unconfirmed reporting places the payment near $10 million — under which the stolen 3.65TB dataset was reportedly returned along with 'shred logs' claimed as digital proof of destruction; legal counsel has publicly noted such assurances from criminal actors are unenforceable and unverifiable. Instructure's remediation included engaging CrowdStrike as forensic incident-response partner, deploying CrowdStrike Falcon EDR across its environment, and permanently discontinuing the Free-For-Teacher service.
The incident triggered a U.S. House Homeland Security Committee inquiry (Chairman Andrew R. Garbarino, formal request May 11), a class-action lawsuit filed May 13 in the U.S. District Court for the Southern District of California, coordination by Australia's National Office of Cyber Security, and an FBI IC3 public advisory (May 15) warning students, staff, and parents of follow-on harassment, swatting threats, and spearphishing built from the leaked student IDs, names, and private message content. The Identity Theft Resource Center's H1 2026 Data Breach Report subsequently identified this single incident as responsible for 275 of the 471 million total breach notices issued in the first half of 2026 (58%), across 1,029 tracked compromises — the largest education-sector data breach on record and the primary driver of the technology sector's outsized share of H1 2026 notice volume.
ShinyHunters (aliases 'shinycorp,' with individual personas 'Hollow,' 'Noct,' and 'Depressed' tied to prior arrests; tracked by Google under clusters UNC6240, UNC6395, UNC6040, UNC6661, and UNC6671) is a decentralized, financially motivated cybercrime collective active since 2019-2020 with no confirmed nation-state affiliation and members previously arrested in France and the United States. It operates a 'pay-or-leak' model without ransomware encryption, and its 2024-2026 campaign arc — Snowflake customer extortion (2024: Ticketmaster, AT&T, Santander), the Salesloft/Drift OAuth token-theft wave (2025), the Gainsight Salesforce app compromise (Nov 2025), Okta SSO vishing (Jan 2026), Salesforce Aura exploitation (Mar 2026), and the Instructure/Canvas breach (Apr-May 2026) — demonstrates a consistent progression from bulk consumer database theft toward compromising trusted third-party SaaS integrators to reach downstream victims at scale.
MITRE ATT&CK techniques used in TL-2026-1705
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Defense Evasion
Persistence
Credential Access
T1110.004 Credential Stuffing; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1556 Modify Authentication Process
Initial Access
T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.002 Spearphishing Link
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Impact
T1491.001 Internal Defacement; T1657 Financial Theft
lateral-movement
T1550.001 Application Access Token
Resource Development
T1583.001 Domains; T1585 Establish Accounts; T1588.002 Tool
Reconnaissance
Affected products and versions in Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
- Instructure — Canvas LMS (Free-For-Teacher accounts)
Vulnerable versions: Free-For-Teacher self-service tier (all instances prior to May 2026 discontinuation); Canvas discussion feature (MathJax rendering path, prior to May 7, 2026 patch)
Fixed in: Free-For-Teacher service permanently discontinued; Canvas discussion-feature MathJax sanitizer hardened post-May 7, 2026
Remediation for Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
Patches
- Instructure remediated the Free-For-Teacher support-ticket access weakness (April 30, 2026)
- Instructure patched the Canvas discussion-feature stored XSS / MathJax `\unicode` sanitizer bypass following the May 7, 2026 defacement incident
Immediate actions
- Rotate all Canvas-linked credentials, API keys, OAuth tokens, and SSO secrets for every affected institution
- Enforce phishing-resistant MFA (FIDO2/passkeys) on Canvas and upstream SSO/identity-provider accounts
- Alert students, faculty, and parents to expect targeted phishing/smishing/vishing referencing real student IDs, professor names, and leaked private-message content
- Block or flag logins from anonymized-IP infrastructure (Mullvad, Oxylabs, 9Proxy) at the conditional-access layer
- Audit and revoke unrecognized OAuth application authorizations and recently enrolled MFA devices across tenant SSO
Workarounds
- Free-For-Teacher self-service accounts are permanently discontinued by Instructure; institutions should confirm no shadow FFT accounts remain in use
- Restrict or monitor MathJax-rendered content in Canvas discussion posts pending confirmed sanitizer hardening
Longer-term hardening
- Permanently retire or tightly gate self-service onboarding tiers analogous to Free-For-Teacher that share infrastructure with paying institutional tenants
- Deploy EDR (e.g., CrowdStrike Falcon) with behavioral monitoring across LMS backend infrastructure
- Institute quarterly audits of OAuth application scopes and SaaS-to-SaaS integrations (Salesloft/Drift-style token trust chains)
- Adopt browser-layer detection for adversary-in-the-middle phishing pages and device-code-phishing OAuth flows
- Require ed-tech vendors to contractually commit to breach-notification SLAs and independent forensic transparency
Timeline of Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
- ShinyHunters compromises Salesloft's GitHub environment, uses TruffleHog to harvest secrets, and steals Drift OAuth integration tokens, beginning a downstream Salesforce data-theft wave affecting ~760 organizations.
- Instructure's Salesforce tenant is compromised via stolen Salesloft/Drift OAuth tokens, providing ShinyHunters an initial foothold that traces forward into the 2026 Canvas breach.
- ShinyHunters gains unauthorized access to Instructure's Canvas backend by exploiting a support-ticket-related weakness in the Free-For-Teacher account tier.
- Attacker begins using the hijacked session to call Canvas APIs directly, pulling usernames, emails, course/enrollment data, and private messages.
- Instructure detects the unauthorized access and revokes it.
- Instructure revokes additional suspicious access and addresses the underlying Free-For-Teacher vulnerability.
- Instructure publicly discloses the security incident via its status page.
- ShinyHunters claims responsibility, lists Instructure on its data leak site, and demands ransom, claiming ~275 million individuals across ~8,800-9,000 institutions affected.
- Instructure declares the incident resolved/contained.
- ShinyHunters exploits a separate stored XSS in the Canvas discussion feature (MathJax `\unicode` sanitizer bypass) to reach admin-level access and defaces Canvas login pages with ransom notes at ~330 institutions, taking Canvas offline during exam season.
- Instructure CEO Steve Daly issues a public apology as Canvas access issues persist.
- Instructure reaches an agreement with ShinyHunters (reported ~$10M payment); attackers reportedly return the stolen 3.65TB dataset with unverifiable 'shred logs' as destruction confirmation.
- A class-action lawsuit is filed in the U.S. District Court for the Southern District of California, and the U.S. House Homeland Security Committee formally opens an investigation into the incident.
- The FBI's Internet Crime Complaint Center issues a public advisory warning students, staff, and parents of ongoing harassment, swatting, and spearphishing risk from the leaked data.
- ITRC's H1 2026 Data Breach Report identifies the Instructure breach as generating 275 of 471 million total H1 2026 breach notices (58%), the largest education-sector breach on record.
Sources cited for Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
- Instructure Incident Driving 58 Percent of Breach Notices in 2026
- Instructure Incident Driving 58 Percent of Breach Notices in 2026 (DataBreaches.Net original)
- 2026 Canvas data breach
- Security Incident Update & FAQs
- Canvas/Instructure cyberattack – Key developments and action items for higher education institutions
- Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
- Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure
- ShinyHunters Escalates Canvas Extortion
- FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
- How three techniques are behind ShinyHunters' 2026 campaigns
- ShinyHunters Threat Actor Profile: TTPs, IoCs & Attacks
- Instructure Canvas Breach 2026: 275M Students Exposed (stored XSS analysis)
- ITRC: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year
Threats related to Instructure Canvas Breach (ShinyHunters) Drives 58% of H1
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts
Detection coverage for TL-2026-1705
As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1705 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.