Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

ShinyHunters Hit Instructure + Downs Canvas Learning Management System

By Linn Foster Freedman on May 14, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule.

According to Dataminr, ShinyHunters “claimed to have stolen 3.654TB of data affecting about 275 million individuals and 9,000 institutions worldwide.” The stolen data included names, email addresses, student ID numbers and messages, but not passwords, government IDs, birth dates, or financial data. The company admitted that the threat actors obtained access on April 29, 2026. After remediation and revoking the threat actors’ access, it identified additional unauthorized activity on May 7, 2026. The incident caused Instructure to take Canvas offline, affecting its 8,800 customers during exam season.

This is a repeated attack by ShinyHunters against Instructure. Not only did it maintain persistence in April and May, but ShinyHunters also attacked Instructure by  in September 2025, in a social engineering attack that provided the threat actors with access to its Salesforce instance.

Instructure confirmed on May 11, 2026, that it has “reached an agreement with the unauthorized actor involved in this incident” and had “received digital confirmation of data destruction (shred logs)” and that “no Instructure customers will be extorted as a result of this incident, publicly or otherwise.” The Cybersecurity & Infrastructure Security Agency issued an alert on the incident, and Congress started an inquiry. In addition, the Federal Trade Commission (FTC) warns consumers to be cautious about texts or emails pretending to be from Canvas “to trick you into giving them your information,” and providing tips about responding to any messages related to the Canvas hack. Importantly, the FTC advises to alert children to be cautious about texts and emails. It’s a good reminder to discuss with your children how threat actors launch social engineering campaigns using the data stolen from an incident such as this one.

Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Linn Foster FreedmanEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo