Instructure (Canvas SIS) breached by ShinyHunters

They are currently reporting a security incident: Instructure Status - Confirmed Security Incident

And I saw earlier today that Bleeping Computer published and then retracted a story about a vulnerability there: https://www.bleepingcomputer.com/news/security/story-retracted/

It looks like that incident is confirmed after all.

Am I crazy, or wasn’t there already one?

Yep, September 2025.

ShinyHunters has listed it.

I saved a sorted list of the schools impacted per ShinyHunters so you don’t have to deal with their CAPTCHA:

https://blog.gayint.org/intel/instructure.txt

4 Likes

Here’s the attached list without the spaces truncated. It is not filtered in any way.

canvas_list.txt (216.0 KB)

ShinyHunters still has access to Canvas infra. This message is being sent to schools via the platform.

1 Like

Canvas appears to be down for “maintenance.”

What’s Happening

Last Updated: 2026-05-08T18:06:25Z

On 2026-05-01T07:00:00Z, Instructure issued a statement about a breach of Canvas, their Student Information System (SIS) platform.

Threat actor ShinyHunters took credit.

Because Instructure didn’t respond, ShinyHunters dumped a list of schools impacted.

As of 2026-05-07T20:38:45Z, ShinyHunters used their access to Canvas infrastructure to send school instances a notification and warning.

Instructure promptly took Canvas offline. Instances now show “maintenace mode.”

A new incident page has been created for this event.

313 Team (yes, again) are claiming credit, but the list of impacted schools and ransom note were from ShinyHunters, so this may just be fishing for credit.

ShinyHunters have issued a “No comment” statement.

Looks like 313 team now claiming this? Or just piggybacking on ShinyHunters?

1 Like

Instructure has posted a new statement:

Looks like they paid.

Definitely paid.

Heard some reports of phishing emails targeting users. I wrote it off because honestly, it’s not real hard to figure out email addresses for college students en masse. It really really isn’t. And it’s even easier to figure out who uses Canvas. But then…

Based on this looks like they may have also been used to serve some sort of malware, possibly a JS token stealer? I’m not familiar enough with Instructure’s actual software beyond that Canvas is browser-based and the first account popped was Discord. Definitely something to look into. I haven’t seen an uptick in compromised Discord accounts so far today but I also haven’t been paying much attention.

We have internal confirmation of this. The data was already out the door when money changed hands.

Not surprised. I’ve now also seen a second definite Canvas user get their Discord account stolen and used to spam ‘investment opportunities.’ I’m not in touch with the account owner, but I know they used Canvas. They complain about it constantly. So it’s definitely looking like there was more than just exfil.