Last Update: 09/18/2026 at 10:33 PM EST

ShinyHunters Targets Education Data

Coverage from HookPhish, Have I Been Pwned, and others

ShinyHunters Targets Education Data topic image

ShinyHunters-linked intrusions exposed education-sector data at Instructure’s Canvas platform and Moody Bible Institute.

Instructure said names, email addresses, student IDs, messages, and enrollment-related information were accessed, while it reported no evidence that passwords, financial data, or government identifiers were compromised; Moody disclosures described exposure ranging from email addresses to Social Security and driver’s-license information for a smaller confirmed group. The incidents also involved extortion, Canvas portal defacement, vulnerability remediation, and disputed claims about the total volume of affected records.

History
09/12/20260 new articles

The current version largely confirms the previous account without materially changing the story’s scope or urgency. It adds a specific remediation consequence: customers had to reauthorize the Instructure API after application-key rotation.

09/06/20263 new articles

The story has broadened beyond Instructure and Canvas to include a separate Moody Bible Institute campaign involving millions of exposed email addresses and thousands of people with highly sensitive regulated identifiers. This materially raises the potential harm and reframes the activity as a recurring education-sector extortion pattern.

  • Moody Bible Institute became a newly identified ShinyHunters-linked victim.
  • Approximately 2.3 million Moody-related email addresses were reportedly exposed.
  • Filings identified regulated identifiers for 8,955 residents, including Social Security numbers and state IDs.
  • The broader campaign is characterized as recurring education-sector extortion with threatened or actual data publication.
07/27/20260 new articles

The main shift is that the breach is now framed less as a completed incident and more as an unresolved, potentially broader campaign: the House committee has formally sought testimony, and the extent of records affected remains unsettled. The current version also clarifies that the portal tampering used cross-site scripting to alter login pages at roughly 330 institutions.

07/25/20260 new articles

The story has sharpened from a broad Canvas breach and extortion case into a more specific two-stage attack that used XSS to hijack administrative sessions and deface school portals. It also now includes congressional scrutiny and a second education-tech target, widening the implications beyond Instructure alone.

  • XSS vulnerabilities reportedly enabled authenticated administrative session access.
  • About 330 institutions saw Canvas login portals altered with ransom messages.
  • Instructure said ShinyHunters returned the data and supplied shred logs.
  • House Homeland Security Committee is seeking testimony on the attacks.
  • Infinite Campus was also targeted in a related ShinyHunters campaign.
07/24/20264 new articles

The story has broadened from the core Instructure/Canvas breach into a wider education-sector extortion pattern, with later reporting confirming a separate Glendale Community College leak tied to the same playbook. The newer framing also emphasizes response actions and confirmed exposure of school records, not just disputed claims about Canvas scale.

  • Glendale Community College was later hit by a related extortion leak.
  • Reported response now includes token revocation and law-enforcement involvement.
  • Confirmed exposure includes school records and enrollment-related data.
  • The incident window now extends into July 2026.
06/29/20260 new articles

The current version largely confirms the previous account without adding a material development. It more explicitly emphasizes the unresolved scale of the alleged theft and the absence of evidence involving passwords, government IDs, or financial data.

06/20/2026Topic Formed

Instructure confirmed a breach affecting Canvas users after ShinyHunters claimed to steal large volumes of student, teacher, and staff data from the education platform. The incident expanded from data theft claims into portal defacements and ransom pressure, prompting investigation, patching, API key rotation, and temporary service disruption. Public reporting centers on exposed contact information and messages, while the full scale of the alleged theft remains disputed.