Instructure Confirms Breach, ShinyHunters Claims 275M Users
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Instructure confirmed that a cyberattack exposed user personal information including names, email addresses, student ID numbers, and messages between users, while stating it found no evidence that passwords, dates of birth, government identifiers, or financial information were involved
- Instructure deployed patches, increased monitoring, and rotated application keys as a precaution, requiring customers to re-authorize API access so new application keys can be issued
- ShinyHunters listed Instructure on its data leak site and claimed 275 million individuals' data across nearly 9,000 schools, plus "several billions" of private messages among students and teachers
- ShinyHunters alleged the stolen dataset spans almost 15,000 institutions across North America, Europe, and Asia-Pacific, totaling over 240 million records of students, teachers, and staff
- ShinyHunters said the data was stolen via a vulnerability in Instructure's own systems that has since been patched, and claimed the company's Salesforce instance was also breached
- BleepingComputer noted it could not independently verify ShinyHunters' claims and that Instructure had not answered questions about when the breach occurred or whether extortion demands were made
Why it matters: For the thousands of schools and universities running on Canvas, the confirmed exposure of names, emails, student IDs, and private messages creates immediate phishing and identity-fraud risk for hundreds of millions of students, teachers, and staff. ShinyHunters' claim of 275 million individuals and billions of messages across 15,000 institutions—if accurate—would rank among the largest education-sector breaches on record, and Instructure's silence on timeline and extortion status leaves affected institutions with limited information to act on.



