Instructure Reaches Ransom Agreement With ShinyHunters After Largest Education Data Breach in History
Instructure on May 11 announced it reached an agreement with ShinyHunters following the group's exfiltration of 3.65TB of Canvas data covering roughly 275 million records at approximately 9,000 institutions via a vulnerability in the Free-for-Teacher support ticket environment. A second intrusion on May 7 had defaced login portals at roughly 330 institutions and set a May 12 pay-or-leak deadline, according to The Register. Instructure said the agreement covers all affected customers, that it received digital confirmation of data destruction, and that customers would not be separately extorted; the company did not disclose the monetary value of the settlement. ShinyHunters confirmed the resolution on May 13 via its dark web leak site, stating "the matter has been resolved" and "the data is nonexistent," per Cyber Daily.
ShinyHunters' staged escalation from initial exfiltration to portal defacement and a hard pay-or-leak deadline demonstrated that layered pressure can compel negotiation from a major EdTech vendor even after remediation steps are taken. The settlement establishes a publicly documented threshold: operational disruption across thousands of institutions is sufficient to force a vendor of Instructure's scale to pay. The 275 million records covering enrollments, private messages, and email addresses retain full phishing utility regardless of destruction claims, because Instructure cannot verify deletion and the group's decentralized structure provides no guarantee that individual members did not retain copies outside the settlement terms. ShinyHunters' concurrent intrusions at Penn, Princeton, and Harvard point to coordinated sector targeting rather than opportunistic selection, and the confirmed payment now functions as proof of concept that large LMS providers will negotiate under sufficient pressure. Support-tier environments with privileged access to production data represent a systemic and underdefended attack surface across the education technology sector.