logo

ShinyHunters Breaches Instructure Canvas LMS via Free Teacher Accounts

ID: 50502bd2-8993-55c5-a43a-7528a1f4219c

STIX ID: report--50502bd2-8993-55c5-a43a-7528a1f4219c

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Varshini

...
...

In May 2026 ShinyHunters breached Instructure's Canvas LMS by exploiting the Free‑For‑Teacher account program, accessing user names, institutional email addresses, student identification numbers, and private messages; the actors published affected institutions and initiated a public extortion campaign with a mid‑May ransom deadline. The report highlights multi‑tenant architectural failures that allowed lateral access between free and paid tenants, notes a prior late‑2025 compromise of Instructure’s Salesforce systems, and includes defanged IOCs (public listing URL and an onion leak site).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.