ShinyHunters Breach Canvas LMS Affecting 9000 Schools and 275 Million Users
On May 7,
ShinyHunters' pivot from pressuring Instructure to soliciting individual schools directly fractures the standard vendor-breach dynamic, creating hundreds of independent negotiating fronts Instructure cannot coordinate. Defaced login pages at three institutions, directly observed by TechCrunch, function as proof-of-access, reinforcing the extortion threat's credibility. Instructure's failure to fully remediate after the initial April breach suggests the group retained persistent access, a vulnerability individual schools now face without vendor intermediation. Selective disclosures or partial settlement with at least some schools before the stated May 12 deadline is likely. The deadline may instead function as leverage theater if a private channel with Instructure is already open, with the stated 231-million-individual victim count, unverified, serving primarily as a negotiating multiplier.
4 sources
- Canvas hack strands university students during finals week -
CNN - Instructure confirms data breach, ShinyHunters claims attack -
BleepingComputer - Developing: ShinyHunters Hacks Instructure Again; Canvas Down -
DataBreaches.Net - Hackers deface school login pages after claiming another Instructure hack -
TechCrunch