Instructure shuts Canvas after ShinyHunters ransomware

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Instructure disabled its Canvas platform after a defacement by cybercrime group ShinyHunters, which displayed a ransom demand threatening to leak data of 275 million students and faculty across ~9,000 institutions.
- ShinyHunters claimed to have stolen identifying information (names, email addresses, student IDs) and private messages, but Instructure found no evidence of passwords, birth dates, or financial data being compromised.
- The ransom deadline was initially set for May 6 and later extended to May 12, while the attack coincided with final exam periods, disrupting coursework nationwide.
- Instructure announced that the breach was contained and that Canvas was fully operational on May 6, but a second defacement forced the platform offline again on May 7, replacing the login page with a maintenance notice.
- ShinyHunters urged affected schools to negotiate ransom payments directly to avoid data publication, despite Instructure’s refusal to pay.
Why it matters: Students and faculty lose access to assignments and exam portals, while schools scramble to replace the platform; Instructure faces reputational damage and potential legal liability, and ShinyHunters stands to profit from ransom payments.


