Ransomware victim disclosure
← All victimsEntire list of affected schools by Instructure breach
Claimed by shinyhunters · listed 16 days ago
Status timeline
- Listed
May 5, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileInstructure is a US-based education technology company best known for Canvas, a widely-used Learning Management System (LMS) deployed by thousands of K-12 schools, colleges, and universities globally. The platform serves tens of millions of students and educators. The victim in this post is characterised not as Instructure itself but as the aggregate list of educational institutions whose data was allegedly obtained via a breach of Instructure's Canvas LMS platform.
- Industry
- Education Technology (LMS / Learning Management Systems)
Attack summary
Severity: critical — The breach involves a major LMS platform used by thousands of educational institutions, implying large-scale exfiltration of student PII (names, emails, academic records, potentially minors' data). Data has already been partially published (affected-schools list) with a credible threat of full release, affecting regulated data categories (FERPA-covered student records) at significant scale.ShinyHunters claims to have exfiltrated data from Instructure's Canvas LMS affecting an undisclosed number of schools, and is threatening to publish all data unless affected institutions or Instructure negotiate a settlement by 6–7 May 2026; Instructure is stated to have not engaged with the group. A downloadable list of affected schools has already been published as proof of access.
Data the group says was taken
AI dossier — extracted from the leak post- List of affected schools/institutions
- Student data (implied, unspecified)
- Institutional data from Canvas LMS (implied)
The group's post references roughly 1 proof file.
What the group claims
The download button below is a list of affected schools by the Instructure Canvas LMS data breach. If any of the schools in the file are interested in preventing the release of their data please consult with a cyber advisory firm and contact us privately at TOX to negociate a settlement. You have till the end of the day by 7 May 2026 before everything is leaked and there will be no chance at a negociation for anyone. Instructure has not even bothered speaking to us to understand the situation or to even negociate with us to prevent the release of this data. Our demand was not even as high as you might think it is. The Company seemingly does not care about all the students affected and the institutions impacted by this data breach. They still have by 6 May 2026 to come speak with us. There is no better option but to come to an agreement with us. Not paying will only worsen the situation rather than resolving it. | Updated: 5 May 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 16 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
