Instructure Paid the Ransom. ShinyHunters Leaked the Data Anyway. 275 Million Students Exposed. – Security Boulevard

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityboulevard.com

Threat Risk: High
Victim: Instructure (Canvas LMS)
Incident: A massive data breach and subsequent leak after a failed ransom negotiation.
Impact: Exposure of records and private messages for approximately 275 million students and staff.
Attacker: ShinyHunters
Analysis: ShinyHunters exploited a flaw in the Canvas Free-For-Teacher account program to exfiltrate massive amounts of PII and private communications. Despite a ransom payment aimed at securing the data, the attackers leaked the records anyway. This incident underscores the futility of paying extortionists once data has already been exfiltrated.
Recommendations: Encrypt sensitive PII at rest using customer-managed keys to render exfiltrated data useless; Conduct rigorous security audits of all account provisioning and onboarding pathways; Implement zero-trust access controls for all administrative and privileged functions
Source: Security Boulevard

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *