ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program — Threadlinqs Intelligence
As of 2026-05-29, ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program is a high-severity data breach threat attributed to ShinyHunters, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-2124 · Severity: HIGH · Status: MONITORING · Category: DATA_BREACH
Attribution: ShinyHunters · FINANCIAL
ShinyHunters exploited weak identity verification in Instructure Canvas's Free-For-Teacher (FFT) program, which lacked MFA and ran on shared production infrastructure with paid institutional tenants,
On April 29, 2026, Instructure detected unauthorized activity on its Canvas Learning Management System production environment, later determined to have originated around April 25-30. The intrusion vector was Instructure's Free-For-Teacher (FFT) account program, a low-friction onboarding tier that let individual educators create Canvas tenants without institutional identity verification. Per the U.S. Department of Education's FSA alert, FFT accounts lacked multi-factor authentication protections. Critically, FFT tenants shared the same backend production infrastructure as paid institutional tenants, relying on logical rather than physical data isolation; once an attacker held valid FFT credentials, their access patterns to underlying systems were indistinguishable from a legitimate teacher piloting Canvas. Instructure has not technically confirmed the precise exploitation mechanism beyond attributing it to 'an issue related to Free-For-Teacher accounts.'
Instructure publicly disclosed the incident on May 1, 2026. On May 3, ShinyHunters claimed responsibility and posted an initial ransom note with a May 7 deadline, publishing a leak-listing page (hxxp://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt) and a Tor hidden-service leak site. On May 7, a second wave of activity — apparently leveraging write access obtained through the same FFT abuse — defaced the Canvas login pages of roughly 330 institutions with HTML-injected extortion messages, disrupting service during final exams and forcing Instructure to take Canvas offline. Service was restored May 8, and the FFT program was permanently discontinued. ShinyHunters claimed exfiltration of 3.65TB of data covering ~275-285 million user records across ~9,000 schools worldwide (Instructure has confirmed a narrower, unspecified scope). Confirmed compromised data types are limited to usernames, email addresses, student ID numbers, course/enrollment metadata, and private inter-user messages; Instructure states no evidence that passwords, birth dates, government identifiers, or financial data were exposed.
Named affected institutions include the University of Pennsylvania (~306,000 affiliates), Harvard, MIT, the University of Oxford, the University of North Carolina System, Rutgers, NC State, the University of California system, Arizona State University, multiple Missouri colleges, Charlotte-area K-12 districts, Texas and California school districts, and organizations in Australia, Canada, the EU (44 Dutch institutions), Hong Kong, Sweden, Singapore, and New Zealand.
On May 11, 2026, one day before the extended deadline, Instructure reached an agreement with ShinyHunters covering all impacted customers: the actor returned the stolen data, provided digital 'shred logs' attesting to its destruction, and agreed not to separately extort individual Canvas customers, in exchange for an undisclosed ransom payment (unconfirmed reporting suggests figures around $10 million). Instructure's remediation included revoking privileged credentials and API/access tokens, rotating internal keys, restricting token-creation pathways, and shutting down FFT permanently. The FBI subsequently issued a public warning that ShinyHunters historically follows breach extortion with direct harassment of individual victims (threatening calls/texts, swatting, and false claims of compromising material) and that stolen student IDs/messages could be weaponized for targeted spear-phishing. The House Homeland Security Committee opened a formal inquiry, requesting Instructure's CEO brief the committee by May 21 on breach scope, containment, and coordination with CISA/law enforcement. A class-action lawsuit was filed against Instructure on May 13, 2026 in the U.S. District Court for the Southern District of California, and law firms have flagged independent state-law and FERPA breach-notification obligations for affected institutions that are separate from Instructure's own settlement with the attacker.
Th
Weaknesses (CWE)
CWE-287, CWE-653
Target sectors: education
Target regions: North America, Europe, Oceania, Asia
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1583.003, T1078.004, T1528, T1619, T1213, T1567.002, T1491.002, T1565.001, T1657