Canvas login portals hacked in mass ShinyHunters extortion campaign
ID: aa77cbff-c0d5-593d-91a5-ee1b85c6cc61
STIX ID: report--aa77cbff-c0d5-593d-91a5-ee1b85c6cc61
Feed Name: Bleeping Computer
Threat Score
ShinyHunters reportedly exploited a vulnerability in Instructure's Canvas platform to deface login portals at approximately 330 colleges and universities with an extortion message threatening to leak stolen student and staff data (allegedly 280 million records) unless paid by May 12, 2026; Instructure confirmed data theft and temporarily took Canvas offline while investigating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
