# ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program

> ShinyHunters exploited weak identity verification in Instructure Canvas's Free-For-Teacher (FFT) program, which lacked MFA and ran on shared production infrastructure with paid institutional tenants, to gain unauthorized access to Canvas data across ~9,000 schools. The actor exfiltrated names, emails, student ID numbers, course/enrollment data and private messages (3.65TB / ~275M records claimed), defaced login pages at ~330 institutions on May 7, 2026, and extorted Instructure to a May 12 deadline; Instructure paid an undisclosed ransom on May 11 in exchange for data return and destruction attestation.

- **Published:** 2026-05-08T00:00:00Z
- **Last reviewed:** 2026-05-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2124
- **ID:** TL-2026-2124
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** MONITORING
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On April 29, 2026, Instructure detected unauthorized activity on its Canvas Learning Management System production environment, later determined to have originated around April 25-30. The intrusion vector was Instructure's Free-For-Teacher (FFT) account program, a low-friction onboarding tier that let individual educators create Canvas tenants without institutional identity verification. Per the U.S. Department of Education's FSA alert, FFT accounts lacked multi-factor authentication protections. Critically, FFT tenants shared the same backend production infrastructure as paid institutional tenants, relying on logical rather than physical data isolation; once an attacker held valid FFT credentials, their access patterns to underlying systems were indistinguishable from a legitimate teacher piloting Canvas. Instructure has not technically confirmed the precise exploitation mechanism beyond attributing it to 'an issue related to Free-For-Teacher accounts.'

Instructure publicly disclosed the incident on May 1, 2026. On May 3, ShinyHunters claimed responsibility and posted an initial ransom note with a May 7 deadline, publishing a leak-listing page (hxxp://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt) and a Tor hidden-service leak site. On May 7, a second wave of activity — apparently leveraging write access obtained through the same FFT abuse — defaced the Canvas login pages of roughly 330 institutions with HTML-injected extortion messages, disrupting service during final exams and forcing Instructure to take Canvas offline. Service was restored May 8, and the FFT program was permanently discontinued. ShinyHunters claimed exfiltration of 3.65TB of data covering ~275-285 million user records across ~9,000 schools worldwide (Instructure has confirmed a narrower, unspecified scope). Confirmed compromised data types are limited to usernames, email addresses, student ID numbers, course/enrollment metadata, and private inter-user messages; Instructure states no evidence that passwords, birth dates, government identifiers, or financial data were exposed.

Named affected institutions include the University of Pennsylvania (~306,000 affiliates), Harvard, MIT, the University of Oxford, the University of North Carolina System, Rutgers, NC State, the University of California system, Arizona State University, multiple Missouri colleges, Charlotte-area K-12 districts, Texas and California school districts, and organizations in Australia, Canada, the EU (44 Dutch institutions), Hong Kong, Sweden, Singapore, and New Zealand.

On May 11, 2026, one day before the extended deadline, Instructure reached an agreement with ShinyHunters covering all impacted customers: the actor returned the stolen data, provided digital 'shred logs' attesting to its destruction, and agreed not to separately extort individual Canvas customers, in exchange for an undisclosed ransom payment (unconfirmed reporting suggests figures around $10 million). Instructure's remediation included revoking privileged credentials and API/access tokens, rotating internal keys, restricting token-creation pathways, and shutting down FFT permanently. The FBI subsequently issued a public warning that ShinyHunters historically follows breach extortion with direct harassment of individual victims (threatening calls/texts, swatting, and false claims of compromising material) and that stolen student IDs/messages could be weaponized for targeted spear-phishing. The House Homeland Security Committee opened a formal inquiry, requesting Instructure's CEO brief the committee by May 21 on breach scope, containment, and coordination with CISA/law enforcement. A class-action lawsuit was filed against Instructure on May 13, 2026 in the U.S. District Court for the Southern District of California, and law firms have flagged independent state-law and FERPA breach-notification obligations for affected institutions that are separate from Instructure's own settlement with the attacker.

This is the second Instructure breach attributed to ShinyHunters within roughly eight months — a September 2025 intrusion compromised Instructure's Salesforce-hosted business systems via social engineering but did not touch Canvas product data. ShinyHunters is one of three cybercrime collectives (alongside Scattered Spider and LAPSUS$) operating jointly as 'Scattered Lapsus$ Hunters,' an extortion-as-a-service alliance behind a wider 2025-2026 campaign of SaaS/CRM-focused breaches and public data-leak-site extortion.

## MITRE ATT&CK

- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1078.004 Valid Accounts: Cloud Accounts
- T1528 Steal Application Access Token
- T1619 Cloud Storage Object Discovery
- T1213 Data from Information Repositories
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1491.002 Defacement: External Defacement
- T1565.001 Data Manipulation: Stored Data Manipulation
- T1657 Financial Theft

## Sources

- [Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS](https://www.bitdefender.com/en-us/blog/businessinsights/technical-advisory-shinyhunters-breach-instructure-canvas-lms)
- [Hackers deface school login pages after claiming another Instructure hack](https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/)
- [Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak](https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html)
- [2026 Canvas data breach](https://en.wikipedia.org/wiki/2026_Canvas_data_breach)
- [FBI warns students and staff that ShinyHunters may come knocking after Canvas breach](https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-shinyhunters-canvas-breach)
- [ShinyHunters Launches Second Major Attack on Instructure Canvas LMS via Free-For-Teacher Accounts](https://www.rescana.com/post/shinyhunters-launches-second-major-attack-on-instructure-canvas-lms-via-free-for-teacher-accounts-may-2026-breach-analys)
- [ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program](https://cybersecuritynews.com/shinyhunters-breaches-instructure-canvas-lms/)
- [Technology Security Alert – Ongoing Cybersecurity Incident Involving the Canvas Learning Management System (Updated May 29, 2026)](https://fsapartners.ed.gov/knowledge-center/library/electronic-announcements/2026-05-12/technology-security-alert-ongoing-cybersecurity-incident-involving-canvas-learning-management-system-updated-may-29-2026)
- [Canvas/Instructure cyberattack – Key developments and action items for higher education institutions](https://www.reedsmith.com/articles/canvasinstructure-cyberattack-key-developments-and-action-items-for-higher-education-institutions/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2124
