• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

ShinyHunters Breaches Canvas LMS in Second Instructure Security Incident in Eight Months

  • SOFX Staff Writer
  • May 7, 2026
(Mykola Borduzhak / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

Instructure, the Salt Lake City-based operator of the Canvas learning management system (LMS), confirmed a data breach exposing user personal information on May 1, with the extortion group ShinyHunters taking responsibility two days later.

📢⚠️ #ShinyHunters has claimed responsibility for major breaches affecting Instructure Canvas LMS and Vimeo, exposing millions of records through direct and supply chain attacks.

Read: https://t.co/kNFy02FfXu#CyberSecurity #DataBreach #CanvasLMS #Vimeo #Instructure

— Hackread.com (@HackRead) May 6, 2026


The company first reported a service disruption on April 30. Instructure said it patched affected systems, revoked compromised credentials, and rotated API keys “out of an abundance of caution.” The company engaged third-party forensics experts and law enforcement and said it believed the intrusion had been contained by May 2.

Confirmed compromised data includes users’ names, email addresses, student ID numbers, and private messages. Instructure said passwords, government identifiers, birth dates, and financial data were not affected.

On its dark web extortion site, ShinyHunters said the breach affected approximately 275 million users across nearly 9,000 institutions globally. As of May 5, the group revised the figure to 280 million records tied to 8,809 institutions.

A ShinyHunters member told TechCrunch the stolen data contains 231 million unique email addresses. Named institutions on the group’s published victim list include Harvard, Stanford, and Columbia universities, as well as Apple. These figures have not been independently verified.

ShinyHunters — the group that hacked @PennGSE last fall — tells me they acquired over 300,000 lines of data from Penn users in their recent Instructure breach.

The hackers claim the incident affected nearly 9,000 institutions, including all 8 Ivy Leagues.

More TK in @DailyPenn

— Jasmine Ni (@jasmineni_) May 6, 2026


ShinyHunters said the attack exploited a Salesforce Experience Cloud misconfiguration, the same method the group has used against hundreds of organizations since at least March 2026. Salesforce warned its customers in March about active exploitation of misconfigured Experience Cloud instances, with attackers using a modified version of AuraInspector, an open-source auditing tool developed by Mandiant.

This is Instructure’s second disclosed security incident in eight months. The company lists more than 8,000 institutions as customers worldwide.

ShinyHunters has separately announced breaches of Rockstar Games, Medtronic, Udemy, Zara, and 7-Eleven in 2026.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

In-Car Tech That Could Shut Down Engines to Be Mandatory in U.S. Cars by 2027 Amid Privacy Fears

In-Car Tech That Could Shut Down Engines to Be Mandatory in U.S. Cars by 2027 Amid Privacy Fears

by SOFX Staff Writer
May 4, 2026
2

New passenger vehicles sold in the United States would soon be required to include in-cabin monitoring systems that assess whether...

AI Coding Agent Wipes Startup’s Entire Database in Nine Seconds

AI Coding Agent Wipes Startup’s Entire Database in Nine Seconds

by SOFX Staff Writer
May 1, 2026
0

A Cursor coding agent running Anthropic's Claude Opus 4.6 deleted PocketOS's entire production database and all volume-level backups in a...

Air Force Special Warfare Tests Kinetic Drone Interceptor in Counter-UAS Exercise

Air Force Special Warfare Tests Kinetic Drone Interceptor in Counter-UAS Exercise

by SOFX Staff Writer
May 1, 2026
0

Air Force Special Warfare Airmen from the 48th Rescue Squadron, 7th Air Support Operations Squadron, and 316th Civil Engineer Squadron...

UK Releases Footage of RAF Crews Bracing for Iranian Missile Impact at Gulf Base

UK Releases Footage of RAF Crews Bracing for Iranian Missile Impact at Gulf Base

by SOFX Staff Writer
May 1, 2026
0

The UK Ministry of Defence released footage on Thursday showing RAF Regiment counter-uncrewed aerial systems (C-UAS) operators bracing at an...

ADVERTISEMENT
ADVERTISEMENT
Next Post
DARPA Flies XRQ-73 Hybrid-Electric Stealth Drone in Push for Quiet ISR Over Contested Airspace

DARPA Flies XRQ-73 Hybrid-Electric Stealth Drone in Push for Quiet ISR Over Contested Airspace

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz