logo

Instructure reaches 'agreement' with ShinyHunters to stop data leak

ID: 6debbaf6-3670-58e9-abd3-413fe32f1959

STIX ID: report--6debbaf6-3670-58e9-abd3-413fe32f1959

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Sergiu Gatlan

...
...

Instructure's Canvas LMS was breached by the ShinyHunters extortion group, which exploited multiple cross-site scripting (XSS) vulnerabilities in the Free-for-Teacher environment to inject JavaScript, obtain authenticated admin sessions, steal roughly 3.6 TB of data, deface login portals, and issue extortion demands; Instructure reports an agreement with the actor and temporary shutdown of affected free accounts while investigating and remediating the flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.