ShinyHunters Hacks Instructure Knocking Canvas Offline Across 9,000 Schools Globally

Hacking group ShinyHunters has claimed responsibility for a breach of Instructure, the parent company of the Canvas learning management system, taking the platform offline for thousands of institutions globally and threatening to release data unless affected universities make contact before May 12.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
University student facing a browser error screen on a laptop representing the ShinyHunters breach of Instructure Canvas affecting over 9,000 educational institutions globally

University student facing a browser error screen on a laptop representing the ShinyHunters breach of Instructure Canvas affecting over 9,000 educational institutions globally

The Canvas learning management system, used by schools, colleges, and universities worldwide to manage grades, course materials, and student communications, was taken offline on Thursday after hacking group ShinyHunters claimed responsibility for a breach of its parent company, Instructure.

Multiple student newspapers across the United States, including The Harvard Crimson, The Daily Pennsylvanian at the University of Pennsylvania, and Duke University's The Chronicle, reported that students were unable to access Canvas beginning Thursday afternoon. ShinyHunters claimed that Harvard was among thousands of institutions affected by the breach, and posted a list of allegedly compromised schools directly on the Canvas platform itself.

As of late Thursday, Instructure confirmed on its status page that Canvas and related services had been placed in maintenance mode while the company investigated login difficulties. The company stated it anticipated restoring services but did not confirm the nature or extent of any data breach.

What ShinyHunters Claimed and What the Data Shows

ShinyHunters used the compromised Canvas platform to post messages directly to affected universities, stating that any institution wishing to prevent its data from being released publicly should contact the group before 12 May 2026. The Daily Pennsylvanian reported this message was posted on Penn's Canvas page as early as last week, indicating the breach and the extortion campaign were underway before the platform-wide disruption became visible to users.

Duke University's student newspaper confirmed the institution was among those affected, describing the breach as hitting over 9,000 schools. Student newspapers from UCLA, the University of Nebraska, and other institutions reported that their universities had also been impacted.

The scale of the claimed breach, if confirmed, would make this one of the most significant attacks on educational technology infrastructure on record.

ShinyHunters: A Documented High-Volume Threat Actor

ShinyHunters is not a new or unknown group. The threat actor has a documented history of targeting large platforms and exfiltrating significant volumes of data. In April 2026, the group claimed to have stolen nearly 80 million business records from Rockstar Games, the maker of Grand Theft Auto. Their operational pattern consistently involves large-scale data theft followed by extortion, with public posting of victim lists used as leverage.

The group's willingness to use the compromised Canvas interface itself as a communication channel for extortion demands is consistent with their approach of maximising visibility and pressure on victims. By posting directly to affected universities' Canvas pages, they simultaneously demonstrated access and ensured that the widest possible audience, including students and faculty, became aware of the breach.

Why This Matters for Enterprise and Government Organisations

While this incident directly affects educational institutions, the implications extend well beyond the higher education sector. Canvas is deployed across a wide range of organisations globally, including corporate training platforms, government learning and development systems, and professional certification bodies.

For enterprise security leaders, the Instructure breach illustrates a recurring and critical risk in the SaaS supply chain. When a platform provider is compromised, every organisation relying on that provider becomes a downstream victim regardless of the strength of their own internal security controls. This is the same pattern seen in the PyTorch Lightning supply chain attack targeting AI development pipelines and in the broader trend of threat actors targeting software and platform providers to achieve maximum reach from a single intrusion.

Third-party and SaaS platform risk management is not a theoretical exercise. It is an active and immediate threat vector that requires organisations to maintain visibility into the security posture of every platform they depend on, not only their own infrastructure.

What Affected Organisations Should Do Now

Security and IT teams at any institution or organisation running Canvas should take the following steps immediately:

  • Monitor Instructure's official status page for updates on the scope of the breach and any indicators of compromise.
  • Audit user accounts associated with Canvas for any signs of unauthorised access or credential exposure.
  • Treat any credentials used to access Canvas as potentially compromised and enforce password resets for all associated accounts.
  • Review any sensitive data stored within Canvas including student records, assessment materials, and personal identifiers, and assess the regulatory notification obligations that may apply.
  • Contact Instructure directly to request confirmation of whether your institution or organisation is among those affected.

The May 12 deadline set by ShinyHunters creates urgency. Organisations that have not yet received communication from Instructure about their exposure status should not wait for outreach and should proactively contact the company for clarity.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

SaaS and Supply Chain SecurityData Breach 2026Threat Actor IntelligenceThird Party Risk ManagementGCC Compliance and Breach NotificationIdentity Security and Credential Risk