Last Update: 09/18/2026 at 10:00 PM EST

ShinyHunters Targets Education Data

Coverage from HookPhish, Have I Been Pwned, and others

ShinyHunters Targets Education Data topic image

ShinyHunters-linked intrusions exposed education-sector data at Instructure’s Canvas platform and Moody Bible Institute.

Instructure said names, email addresses, student IDs, messages, and enrollment-related information were accessed, while it reported no evidence that passwords, financial data, or government identifiers were compromised; Moody disclosures described exposure ranging from email addresses to Social Security and driver’s-license information for a smaller confirmed group. The incidents also involved extortion, Canvas portal defacement, vulnerability remediation, and disputed claims about the total volume of affected records.

Looking Back
107 Day Timeline
May 3May 24Jun 14Jul 5Jul 26Aug 16
History
09/12/2026

The current version largely confirms the previous account without materially changing the story’s scope or urgency. It adds a specific remediation consequence: customers had to reauthorize the Instructure API after application-key rotation.

09/06/2026

The story has broadened beyond Instructure and Canvas to include a separate Moody Bible Institute campaign involving millions of exposed email addresses and thousands of people with highly sensitive regulated identifiers. This materially raises the potential harm and reframes the activity as a recurring education-sector extortion pattern.

All Articles30 articles
Important16 articles · CI Score 60 and above
HookPhish
Glendale Community College disclosed a reported June 15, 2026 ShinyHunters extortion incident in which alleged student records, including Social Security numbers, were published online.
7/11/2026 • Data Breaches & Exposure Events • General
Have I Been Pwned
In June 2026, ShinyHunters allegedly published Glendale Community College student-enrollment data online after an extortion campaign, exposing email addresses and Social Security numbers.
7/11/2026 • Data Breaches & Exposure Events • General
Premier Christian News
Moody Bible Institute disclosed a cyberattack affecting over 2.3 million records, with leaked personal data reported via Have I Been Pwned.
7/9/2026 • Data Breaches & Exposure Events • General
shattered.io
ShinyHunters exploited two production vulnerabilities in Instructure Canvas during late April and May 2026, exfiltrating large volumes of student-related data and disrupting university course pages.
6/13/2026 • Data Breaches & Exposure Events • General
Hackread / Deeba Ahmed
ShinyHunters reportedly breached Instructure and Vimeo in 2026, exposing student and user records through vulnerability exploitation and Anodot token-based access.
5/6/2026 • Data Breaches & Exposure Events • General
Field Effect / Field Effect Security Intelligence Team
Instructure disclosed on May 3, 2026 a ShinyHunters-linked data leak exposing student identities and user messages at selected educational institutions.
5/6/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Sergiu Gatlan
ShinyHunters claimed a March Salesforce-targeting attack on Infinite Campus, and Have I Been Pwned linked it to exposure of 137,100 school staff accounts.
6/15/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Lawrence Abrams
The U.S. House Homeland Security Committee asked Instructure CEO Steve Daly for testimony on ShinyHunters breaches of Canvas that exposed student data and disrupted schools.
5/12/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Lawrence Abrams
ShinyHunters defaced Instructure Canvas login portals in attacks on about 330 colleges and universities, demanding ransom or student data leakage.
5/7/2026 • Data Breaches & Exposure Events • General
TechCrunch / Lorenzo Franceschi-Bicchierai
Instructure confirmed a breach affecting student information after ShinyHunters claimed theft of names, personal emails, and teacher-student messages tied to Canvas.
5/5/2026 • Data Breaches & Exposure Events • General
Techzine Global / Erik van Klinken
Instructure confirmed a data breach affecting Canvas users, exposing student identifiers and messages after ShinyHunters claims of large-scale theft.
5/4/2026 • Data Breaches & Exposure Events • General
Simply Secure Group
Moody Bible Institute confirmed in June 2026 that ShinyHunters-linked attackers published personal information on more than 2.3 million people through underground forums and leak sites after an extortion campaign.
8/17/2026 • Data Breaches & Exposure Events • General
Emery Reddy
ShinyHunters claimed a June 2026 cyberattack on Moody Bible Institute in Chicago that exposed personal data, including records affecting 8,955 Washington residents.
7/30/2026 • Data Breaches & Exposure Events • General
Almeida Law Group / Luke Coughlin
Moody Bible Institute faced an alleged June 2026 data leak after ShinyHunters claimed exfiltration of education, donor, and payroll records.
6/17/2026 • Data Breaches & Exposure Events • General
The Daily Pennsylvanian / Luke Petersen
ShinyHunters disrupted Instructure Canvas access at the University of Pennsylvania and other universities on May 7, 2026, after claiming a vendor breach and threatening data release.
5/7/2026 • Data Breaches & Exposure Events • General
Cybersecurity Insiders / Naveen Goud
ShinyHunters allegedly breached Instructure's Canvas system, and Instructure confirmed sensitive data access impacting thousands of schools.
5/4/2026 • Data Breaches & Exposure Events • General
Interesting14 articles · CI Score 45–59
BleepingComputer / Sergiu Gatlan
Instructure said a May 13 webinar would share details after ShinyHunters stole data and attempted extortion against Canvas, with the stolen data later returned and destroyed.
5/12/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Ionut Ilascu
Instructure disclosed that XSS vulnerabilities enabled ShinyHunters to modify Canvas login portals, steal data, and extort ransom after the breach began April 29.
5/11/2026 • Cybersecurity (Privacy-Relevant) • General
SC Media
Moody Bible Institute reported a ShinyHunters-linked breach in 2.3 million records after unauthorized access and a public leak of sensitive PII.
7/6/2026 • Data Breaches & Exposure Events • General
Hjnews
Instructure reported unauthorized Canvas access beginning April 29, 2026, followed by ShinyHunters ransom activity and login defacement in early May 2026.
5/21/2026 • Data Breaches & Exposure Events • General
The CyberWire / N2K CyberWire staff
ShinyHunters defaced Instructure Canvas login portals for hundreds of schools and universities, and Instructure confirmed a breach involving user identifiers and messages.
5/8/2026 • Data Breaches & Exposure Events • General
Mensjournal / Jessica McBride
ShinyHunters hacked Instructure's Canvas on May 7, set a May 12 student-data leak deadline, and caused school outages and login disablement across multiple U.S. states.
5/8/2026 • Data Breaches & Exposure Events • General
LiveNOW from FOX
In the United States, ShinyHunters reportedly hacked Instructure's Canvas learning platform in early May, triggering outages and maintenance mode while Instructure withheld root-cause details.
5/7/2026 • Data Breaches & Exposure Events • General
The Daily Pennsylvanian / Arti Jain, Luke Petersen, and Gabrielle Ostad
ShinyHunters disrupted University of Pennsylvania Canvas access on Thursday and threatened to leak data after a claimed Instructure breach, affecting multiple Canvas-using universities.
5/7/2026 • Data Breaches & Exposure Events • General
Fox 5 Atlanta / Chris Williams
Instructure investigated Canvas outages and login disruptions after ShinyHunters claims of infiltration, with a reported data breach deadline for universities before May 12.
5/7/2026 • Data Breaches & Exposure Events • General
EdScoop
ShinyHunters extended Canvas breach extortion payments to May 12, claiming exposure of personal data for about 9,000 education institutions using Instructure.
5/7/2026 • Data Breaches & Exposure Events • General
TechEchelon / Sara Montes de Oca
Instructure confirmed Canvas user-identifying data exposure after a ShinyHunters-linked cyberattack, while ShinyHunters claims larger scope.
5/3/2026 • Data Breaches & Exposure Events • General
CNET / Tyler Graham
Instructure said Canvas personal data stolen by ShinyHunters in an April 29 hack was deleted, with payment details unconfirmed and Free-For-Teacher access disabled during investigation.
5/12/2026 • Data Breaches & Exposure Events • General
Mashable
ShinyHunters claimed a Canvas breach, and Instructure confirmed incident response steps after an April 30 disruption involving education platform user data.
5/4/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Lawrence Abrams
Instructure disclosed a cybersecurity incident in Canvas after ShinyHunters claimed responsibility and posted an alleged data leak listing.
5/3/2026 • Data Breaches & Exposure Events • General