ShinyHunters Targets Education DataShinyHunters Targets Education DataCoverage from HookPhish, Have I Been Pwned, and others
00/00/0000
DailyWeekly
ShinyHunters-linked intrusions exposed education-sector data at Instructure’s Canvas platform and Moody Bible Institute.
Instructure said names, email addresses, student IDs, messages, and enrollment-related information were accessed, while it reported no evidence that passwords, financial data, or government identifiers were compromised; Moody disclosures described exposure ranging from email addresses to Social Security and driver’s-license information for a smaller confirmed group. The incidents also involved extortion, Canvas portal defacement, vulnerability remediation, and disputed claims about the total volume of affected records.
Looking Back
107 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
May 3
May 21
Jun 8
Jun 26
Jul 11
Jul 29
Aug 16
History
09/12/2026
The current version largely confirms the previous account without materially changing the story’s scope or urgency. It adds a specific remediation consequence: customers had to reauthorize the Instructure API after application-key rotation.
09/06/2026
The story has broadened beyond Instructure and Canvas to include a separate Moody Bible Institute campaign involving millions of exposed email addresses and thousands of people with highly sensitive regulated identifiers. This materially raises the potential harm and reframes the activity as a recurring education-sector extortion pattern.
Glendale Community College disclosed a reported June 15, 2026 ShinyHunters extortion incident in which alleged student records, including Social Security numbers, were published online.
7/11/2026 • Data Breaches & Exposure Events • General
In June 2026, ShinyHunters allegedly published Glendale Community College student-enrollment data online after an extortion campaign, exposing email addresses and Social Security numbers.
7/11/2026 • Data Breaches & Exposure Events • General
ShinyHunters exploited two production vulnerabilities in Instructure Canvas during late April and May 2026, exfiltrating large volumes of student-related data and disrupting university course pages.
6/13/2026 • Data Breaches & Exposure Events • General
ShinyHunters reportedly breached Instructure and Vimeo in 2026, exposing student and user records through vulnerability exploitation and Anodot token-based access.
5/6/2026 • Data Breaches & Exposure Events • General
Field Effect / Field Effect Security Intelligence Team66
Instructure disclosed on May 3, 2026 a ShinyHunters-linked data leak exposing student identities and user messages at selected educational institutions.
5/6/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a March Salesforce-targeting attack on Infinite Campus, and Have I Been Pwned linked it to exposure of 137,100 school staff accounts.
6/15/2026 • Data Breaches & Exposure Events • General
The U.S. House Homeland Security Committee asked Instructure CEO Steve Daly for testimony on ShinyHunters breaches of Canvas that exposed student data and disrupted schools.
5/12/2026 • Data Breaches & Exposure Events • General
Instructure confirmed a breach affecting student information after ShinyHunters claimed theft of names, personal emails, and teacher-student messages tied to Canvas.
5/5/2026 • Data Breaches & Exposure Events • General
Moody Bible Institute confirmed in June 2026 that ShinyHunters-linked attackers published personal information on more than 2.3 million people through underground forums and leak sites after an extortion campaign.
8/17/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a June 2026 cyberattack on Moody Bible Institute in Chicago that exposed personal data, including records affecting 8,955 Washington residents.
7/30/2026 • Data Breaches & Exposure Events • General
ShinyHunters disrupted Instructure Canvas access at the University of Pennsylvania and other universities on May 7, 2026, after claiming a vendor breach and threatening data release.
5/7/2026 • Data Breaches & Exposure Events • General
Instructure said a May 13 webinar would share details after ShinyHunters stole data and attempted extortion against Canvas, with the stolen data later returned and destroyed.
5/12/2026 • Data Breaches & Exposure Events • General
Instructure disclosed that XSS vulnerabilities enabled ShinyHunters to modify Canvas login portals, steal data, and extort ransom after the breach began April 29.
5/11/2026 • Cybersecurity (Privacy-Relevant) • General
Instructure reported unauthorized Canvas access beginning April 29, 2026, followed by ShinyHunters ransom activity and login defacement in early May 2026.
5/21/2026 • Data Breaches & Exposure Events • General
ShinyHunters defaced Instructure Canvas login portals for hundreds of schools and universities, and Instructure confirmed a breach involving user identifiers and messages.
5/8/2026 • Data Breaches & Exposure Events • General
ShinyHunters hacked Instructure's Canvas on May 7, set a May 12 student-data leak deadline, and caused school outages and login disablement across multiple U.S. states.
5/8/2026 • Data Breaches & Exposure Events • General
In the United States, ShinyHunters reportedly hacked Instructure's Canvas learning platform in early May, triggering outages and maintenance mode while Instructure withheld root-cause details.
5/7/2026 • Data Breaches & Exposure Events • General
The Daily Pennsylvanian / Arti Jain, Luke Petersen, and Gabrielle Ostad54
ShinyHunters disrupted University of Pennsylvania Canvas access on Thursday and threatened to leak data after a claimed Instructure breach, affecting multiple Canvas-using universities.
5/7/2026 • Data Breaches & Exposure Events • General
Instructure investigated Canvas outages and login disruptions after ShinyHunters claims of infiltration, with a reported data breach deadline for universities before May 12.
5/7/2026 • Data Breaches & Exposure Events • General
ShinyHunters extended Canvas breach extortion payments to May 12, claiming exposure of personal data for about 9,000 education institutions using Instructure.
5/7/2026 • Data Breaches & Exposure Events • General
Instructure said Canvas personal data stolen by ShinyHunters in an April 29 hack was deleted, with payment details unconfirmed and Free-For-Teacher access disabled during investigation.
5/12/2026 • Data Breaches & Exposure Events • General
ShinyHunters claimed a Canvas breach, and Instructure confirmed incident response steps after an April 30 disruption involving education platform user data.
5/4/2026 • Data Breaches & Exposure Events • General