logo

Instructure confirms hackers used Canvas flaw to deface portals

ID: 3e568974-55f5-5ccd-9cf2-670f7b299987

STIX ID: report--3e568974-55f5-5ccd-9cf2-670f7b299987

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ionut Ilascu

...
...

Instructure's Canvas LMS was breached via multiple cross-site scripting (XSS) vulnerabilities that allowed attackers (ShinyHunters) to hijack authenticated admin sessions, exfiltrate data (reported ~3.6 TB / 275M records), and later deface login portals with an extortion demand; Free-for-Teacher instances were temporarily shut down while the company revoked access and engaged forensic help.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.