logo

Stolen Canvas data was “returned” after hacker agreement, Instructure says

ID: 0f8d62d0-1822-55c1-bf80-e269f4eaaf72

STIX ID: report--0f8d62d0-1822-55c1-bf80-e269f4eaaf72

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

...
...

The article covers a data breach of Instructure/Canvas claimed by the extortion group ShinyHunters, noting Instructure reportedly paid the actor and that the stolen data was "returned" and logs "shredded." Exposed items include usernames, emails, course names, enrollment details, and private messages — data sufficient to enable targeted phishing and social engineering; the vendor states no passwords, DOBs, government IDs, or financial data were involved. Recommended actions for affected users include resetting Canvas passwords, enabling MFA, monitoring financial/credit activity, and remaining vigilant for personalized phishing attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.