• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

ShinyHunters Breaches Canvas LMS in Second Instructure Security Incident in Eight Months

  • SOFX Staff Writer
  • May 7, 2026
(Mykola Borduzhak / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

Instructure, the Salt Lake City-based operator of the Canvas learning management system (LMS), confirmed a data breach exposing user personal information on May 1, with the extortion group ShinyHunters taking responsibility two days later.

📢⚠️ #ShinyHunters has claimed responsibility for major breaches affecting Instructure Canvas LMS and Vimeo, exposing millions of records through direct and supply chain attacks.

Read: https://t.co/kNFy02FfXu#CyberSecurity #DataBreach #CanvasLMS #Vimeo #Instructure

— Hackread.com (@HackRead) May 6, 2026


The company first reported a service disruption on April 30. Instructure said it patched affected systems, revoked compromised credentials, and rotated API keys “out of an abundance of caution.” The company engaged third-party forensics experts and law enforcement and said it believed the intrusion had been contained by May 2.

Confirmed compromised data includes users’ names, email addresses, student ID numbers, and private messages. Instructure said passwords, government identifiers, birth dates, and financial data were not affected.

On its dark web extortion site, ShinyHunters said the breach affected approximately 275 million users across nearly 9,000 institutions globally. As of May 5, the group revised the figure to 280 million records tied to 8,809 institutions.

A ShinyHunters member told TechCrunch the stolen data contains 231 million unique email addresses. Named institutions on the group’s published victim list include Harvard, Stanford, and Columbia universities, as well as Apple. These figures have not been independently verified.

ShinyHunters — the group that hacked @PennGSE last fall — tells me they acquired over 300,000 lines of data from Penn users in their recent Instructure breach.

The hackers claim the incident affected nearly 9,000 institutions, including all 8 Ivy Leagues.

More TK in @DailyPenn

— Jasmine Ni (@jasmineni_) May 6, 2026


ShinyHunters said the attack exploited a Salesforce Experience Cloud misconfiguration, the same method the group has used against hundreds of organizations since at least March 2026. Salesforce warned its customers in March about active exploitation of misconfigured Experience Cloud instances, with attackers using a modified version of AuraInspector, an open-source auditing tool developed by Mandiant.

This is Instructure’s second disclosed security incident in eight months. The company lists more than 8,000 institutions as customers worldwide.

ShinyHunters has separately announced breaches of Rockstar Games, Medtronic, Udemy, Zara, and 7-Eleven in 2026.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

by SOFX Staff Writer
July 15, 2026
2

A contractor-operated plant in Mesquite, Texas, built to produce 30,000 155mm projectile components per month, has not delivered a single...

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

by SOFX Staff Writer
July 15, 2026
1

A viral video shows a Russian soldier thrown from a YakB-12.7 rotary machine gun during a training exercise after the...

ADVERTISEMENT
ADVERTISEMENT
Home Global Operations

ShinyHunters Breaches Canvas LMS in Second Instructure Security Incident in Eight Months

  • SOFX Staff Writer
  • May 7, 2026
(Mykola Borduzhak / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

Instructure, the Salt Lake City-based operator of the Canvas learning management system (LMS), confirmed a data breach exposing user personal information on May 1, with the extortion group ShinyHunters taking responsibility two days later.

📢⚠️ #ShinyHunters has claimed responsibility for major breaches affecting Instructure Canvas LMS and Vimeo, exposing millions of records through direct and supply chain attacks.

Read: https://t.co/kNFy02FfXu#CyberSecurity #DataBreach #CanvasLMS #Vimeo #Instructure

— Hackread.com (@HackRead) May 6, 2026


The company first reported a service disruption on April 30. Instructure said it patched affected systems, revoked compromised credentials, and rotated API keys “out of an abundance of caution.” The company engaged third-party forensics experts and law enforcement and said it believed the intrusion had been contained by May 2.

Confirmed compromised data includes users’ names, email addresses, student ID numbers, and private messages. Instructure said passwords, government identifiers, birth dates, and financial data were not affected.

On its dark web extortion site, ShinyHunters said the breach affected approximately 275 million users across nearly 9,000 institutions globally. As of May 5, the group revised the figure to 280 million records tied to 8,809 institutions.

A ShinyHunters member told TechCrunch the stolen data contains 231 million unique email addresses. Named institutions on the group’s published victim list include Harvard, Stanford, and Columbia universities, as well as Apple. These figures have not been independently verified.

ShinyHunters — the group that hacked @PennGSE last fall — tells me they acquired over 300,000 lines of data from Penn users in their recent Instructure breach.

The hackers claim the incident affected nearly 9,000 institutions, including all 8 Ivy Leagues.

More TK in @DailyPenn

— Jasmine Ni (@jasmineni_) May 6, 2026


ShinyHunters said the attack exploited a Salesforce Experience Cloud misconfiguration, the same method the group has used against hundreds of organizations since at least March 2026. Salesforce warned its customers in March about active exploitation of misconfigured Experience Cloud instances, with attackers using a modified version of AuraInspector, an open-source auditing tool developed by Mandiant.

This is Instructure’s second disclosed security incident in eight months. The company lists more than 8,000 institutions as customers worldwide.

ShinyHunters has separately announced breaches of Rockstar Games, Medtronic, Udemy, Zara, and 7-Eleven in 2026.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

by SOFX Staff Writer
July 15, 2026
2

A contractor-operated plant in Mesquite, Texas, built to produce 30,000 155mm projectile components per month, has not delivered a single...

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

by SOFX Staff Writer
July 15, 2026
1

A viral video shows a Russian soldier thrown from a YakB-12.7 rotary machine gun during a training exercise after the...

Hegseth Orders Testosterone Screening for U.S. Troops

Hegseth Orders Testosterone Screening for U.S. Troops

by SOFX Staff Writer
July 16, 2026
6

War Secretary Pete Hegseth announced Wednesday that the U.S. military will begin annually screening service members aged 30 and older...

ADVERTISEMENT
ADVERTISEMENT
Next Post
DARPA Flies XRQ-73 Hybrid-Electric Stealth Drone in Push for Quiet ISR Over Contested Airspace

DARPA Flies XRQ-73 Hybrid-Electric Stealth Drone in Push for Quiet ISR Over Contested Airspace

China Sentences Ex-Defense Ministers to Death over Graft Charges

China Sentences Ex-Defense Ministers to Death over Graft Charges

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz