Threat reportData BreachTL-2026-2124
ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program
ShinyHunters Breach of Instructure Canvas LMS via (TL-2026-2124), also tracked as 2026 Canvas Data Breach, is a high-severity data breach, first published 2026-05-08. It is attributed to ShinyHunters with high confidence, affects Instructure Canvas LMS - Free-For-Teacher accounts on shared, maps to 9 MITRE ATT&CK techniques (T1078.004, T1213, T1491.002), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 9MITRE ATT&CK
- Actors
- 1ShinyHunters
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-2124
- Threat ID
- TL-2026-2124
- Also known as
- 2026 Canvas Data Breach
- Severity
- HIGH
- Status
- MONITORING
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education
- Target regions
- North America, Europe, Oceania, Asia
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in ShinyHunters Breach of Instructure Canvas LMS via
Malware and tooling: scattered lapsus$ hunters
How ShinyHunters Breach of Instructure Canvas LMS via works
ShinyHunters exploited weak identity verification in Instructure Canvas's Free-For-Teacher (FFT) program, which lacked MFA and ran on shared production infrastructure with paid institutional tenants, to gain unauthorized access to Canvas data across ~9,000 schools. The actor exfiltrated names, emails, student ID numbers, course/enrollment data and private messages (3.65TB / ~275M records claimed), defaced login pages at ~330 institutions on May 7, 2026, and extorted Instructure to a May 12 deadline; Instructure paid an undisclosed ransom on May 11 in exchange for data return and destruction attestation.
On April 29, 2026, Instructure detected unauthorized activity on its Canvas Learning Management System production environment, later determined to have originated around April 25-30. The intrusion vector was Instructure's Free-For-Teacher (FFT) account program, a low-friction onboarding tier that let individual educators create Canvas tenants without institutional identity verification. Per the U.S. Department of Education's FSA alert, FFT accounts lacked multi-factor authentication protections. Critically, FFT tenants shared the same backend production infrastructure as paid institutional tenants, relying on logical rather than physical data isolation; once an attacker held valid FFT credentials, their access patterns to underlying systems were indistinguishable from a legitimate teacher piloting Canvas. Instructure has not technically confirmed the precise exploitation mechanism beyond attributing it to 'an issue related to Free-For-Teacher accounts.'
Instructure publicly disclosed the incident on May 1, 2026. On May 3, ShinyHunters claimed responsibility and posted an initial ransom note with a May 7 deadline, publishing a leak-listing page (hxxp://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt) and a Tor hidden-service leak site. On May 7, a second wave of activity — apparently leveraging write access obtained through the same FFT abuse — defaced the Canvas login pages of roughly 330 institutions with HTML-injected extortion messages, disrupting service during final exams and forcing Instructure to take Canvas offline. Service was restored May 8, and the FFT program was permanently discontinued. ShinyHunters claimed exfiltration of 3.65TB of data covering ~275-285 million user records across ~9,000 schools worldwide (Instructure has confirmed a narrower, unspecified scope). Confirmed compromised data types are limited to usernames, email addresses, student ID numbers, course/enrollment metadata, and private inter-user messages; Instructure states no evidence that passwords, birth dates, government identifiers, or financial data were exposed.
Named affected institutions include the University of Pennsylvania (~306,000 affiliates), Harvard, MIT, the University of Oxford, the University of North Carolina System, Rutgers, NC State, the University of California system, Arizona State University, multiple Missouri colleges, Charlotte-area K-12 districts, Texas and California school districts, and organizations in Australia, Canada, the EU (44 Dutch institutions), Hong Kong, Sweden, Singapore, and New Zealand.
On May 11, 2026, one day before the extended deadline, Instructure reached an agreement with ShinyHunters covering all impacted customers: the actor returned the stolen data, provided digital 'shred logs' attesting to its destruction, and agreed not to separately extort individual Canvas customers, in exchange for an undisclosed ransom payment (unconfirmed reporting suggests figures around $10 million). Instructure's remediation included revoking privileged credentials and API/access tokens, rotating internal keys, restricting token-creation pathways, and shutting down FFT permanently. The FBI subsequently issued a public warning that ShinyHunters historically follows breach extortion with direct harassment of individual victims (threatening calls/texts, swatting, and false claims of compromising material) and that stolen student IDs/messages could be weaponized for targeted spear-phishing. The House Homeland Security Committee opened a formal inquiry, requesting Instructure's CEO brief the committee by May 21 on breach scope, containment, and coordination with CISA/law enforcement. A class-action lawsuit was filed against Instructure on May 13, 2026 in the U.S. District Court for the Southern District of California, and law firms have flagged independent state-law and FERPA breach-notification obligations for affected institutions that are separate from Instructure's own settlement with the attacker.
This is the second Instructure breach attributed to ShinyHunters within roughly eight months — a September 2025 intrusion compromised Instructure's Salesforce-hosted business systems via social engineering but did not touch Canvas product data. ShinyHunters is one of three cybercrime collectives (alongside Scattered Spider and LAPSUS$) operating jointly as 'Scattered Lapsus$ Hunters,' an extortion-as-a-service alliance behind a wider 2025-2026 campaign of SaaS/CRM-focused breaches and public data-leak-site extortion.
MITRE ATT&CK techniques used in TL-2026-2124
Initial Access
T1078.004 Valid Accounts: Cloud Accounts
Collection
T1213 Data from Information Repositories
Impact
T1491.002 Defacement: External Defacement; T1565.001 Data Manipulation: Stored Data Manipulation; T1657 Financial Theft
Credential Access
T1528 Steal Application Access Token
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server
Discovery
Affected products and versions in ShinyHunters Breach of Instructure Canvas LMS via
- Instructure — Canvas LMS - Free-For-Teacher accounts on shared production infrastructure
Vulnerable versions: Free-For-Teacher program (all instances prior to shutdown)
Fixed in: Free-For-Teacher program permanently discontinued 2026-05-08
Remediation for ShinyHunters Breach of Instructure Canvas LMS via
Patches
- No CVE or vendor patch was issued; Instructure's remediation was to permanently discontinue the Free-For-Teacher program on May 8, 2026
Immediate actions
- Revoke and rotate all API credentials, privileged accounts, and OAuth/access tokens tied to Canvas integrations
- Disable or restrict any remaining free/unverified Canvas tenant creation (Free-For-Teacher and equivalents)
- Review Canvas login page branding/configuration for tampering and restore from clean backups where defacement is found
- Notify legal counsel and assess independent state data-breach-notification and FERPA obligations separate from Instructure's own response
- Implement litigation holds preserving all incident-related documents; notify cyber insurance carriers
Workarounds
- Treat any Canvas password-reset or security email as suspicious unless received through the official Canvas portal
- Train staff/students on FFT-breach-themed spear-phishing and harassment/swatting risk stemming from exposed student IDs and private messages
Longer-term hardening
- Enforce multi-factor authentication across all Canvas account tiers, including free/pilot accounts
- Architect strict tenant isolation (not merely logical separation) between low-verification and institutional SaaS tenants sharing backend infrastructure
- Audit and re-authorize third-party LTI tools, OAuth grants, and SAML integrations
- Establish 90+ day monitoring of dark-web/leak-site forums for re-exposure of previously 'destroyed' data
- Review vendor contracts for indemnification, breach notification, and incident-response coordination provisions
Weaknesses (CWE) in ShinyHunters Breach of Instructure Canvas LMS via
Timeline of ShinyHunters Breach of Instructure Canvas LMS via
- First ShinyHunters attack on Instructure: social engineering compromise of Instructure's Salesforce-hosted business systems; no Canvas product data accessed.
- Estimated start of unauthorized actor access to Canvas production systems via Free-For-Teacher accounts.
- Instructure detects unauthorized activity on Canvas and engages forensic investigators.
- Confirmed exposure window begins, running through May 7-8, 2026.
- Instructure publicly discloses the Canvas breach via its status page.
- ShinyHunters claims responsibility and posts an initial ransom note with a May 7 deadline.
- Second wave of activity: ShinyHunters defaces Canvas login pages with extortion messages at roughly 330 institutions, publishes a leak-listing page and Tor leak site, and extends the ransom deadline to May 12; Instructure takes Canvas offline.
- Canvas service restored; Instructure permanently discontinues the Free-For-Teacher program.
- House Homeland Security Committee formally requests Instructure's CEO brief the committee by May 21 on breach scope, containment, and law-enforcement coordination.
- Instructure reaches an agreement with ShinyHunters covering all impacted customers; the actor returns stolen data and provides 'shred logs' attesting to its destruction, in exchange for an undisclosed ransom payment.
- Extended ransom deadline passes; some residual Canvas access issues still reported.
- Class-action lawsuit filed against Instructure in the U.S. District Court for the Southern District of California.
- U.S. Department of Education (FSA Partners) issues an updated Technology Security Alert on the incident with school guidance.
Sources cited for ShinyHunters Breach of Instructure Canvas LMS via
- Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
- Hackers deface school login pages after claiming another Instructure hack
- Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
- 2026 Canvas data breach
- FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
- ShinyHunters Launches Second Major Attack on Instructure Canvas LMS via Free-For-Teacher Accounts
- ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program
- Technology Security Alert – Ongoing Cybersecurity Incident Involving the Canvas Learning Management System (Updated May 29, 2026)
- Canvas/Instructure cyberattack – Key developments and action items for higher education institutions
Detection coverage for TL-2026-2124
As of 2026-05-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2124 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2124
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.