⚠️ Canvas Data Wasn't Deleted, Analysts Warn — Phishing Wave Expected for Months
On this page
Security researchers universally doubt Instructure's claim that stolen Canvas student data was destroyed, warning of targeted phishing campaigns that could last a year or more.
When Instructure "reached an agreement" with the ShinyHunters extortion crew this week, the education giant told nearly 9,000 affected schools and universities that the stolen data had been digitally shredded. The company said it received "digital confirmation of data destruction (shred logs)" and that no customers would be extorted.
Not a single cybersecurity expert who spoke with The Register believes that's true.
Analysts: "They're Criminals and Scumbags"
"Do I believe they deleted the data? No. They're criminals and scumbags," Allan Liska, a threat intelligence analyst at Recorded Future, told the publication. Liska, widely known as the Ransomware Sommelier, points to what security researcher Max Smeets calls the "Ransomware Trust Paradox": ransomware groups have to at least appear to delete data after a payout, or no future victim would pay. But that doesn't mean the data is actually gone.
Cynthia Kaiser, SVP at the Halcyon Ransomware Research Center and a former two-decade FBI veteran, put it even more bluntly. "'We destroyed the data' is a standard line from extortion groups once a payment is made or negotiations conclude, but time after time it has proven untrue," Kaiser said. She noted that ShinyHunters has a documented history of recycling, reselling, and re-leveraging stolen data across campaigns — data they claimed was contained from earlier intrusions has resurfaced on criminal forums months and years later.
What the Experts Expect Next
Kaiser's warning is specific and practical: "Halcyon expects targeted phishing waves against staff, students, and parents over the next six to 12 months using leaked names, email addresses, and Canvas chat context to make the lures convincing."
This means the 275 million individuals whose data was stolen from Canvas should expect highly targeted phishing emails that appear to come from their school or university. Because the attackers have chat message content from Canvas, these phishing lures could reference real conversations, class schedules, or assignment details to trick recipients into clicking malicious links or revealing additional passwords.
How Much Did Instructure Pay?
Instructure never directly said it paid a ransom. The company said it "reached an agreement" with ShinyHunters — phrasing cybersecurity analysts universally interpret as a ransom payment. Doug Thompson, chief education architect at cybersecurity firm Tanium, estimates the amount sits somewhere between $5 million and $30 million.
We may never know the exact figure. But we do know what happened next: ShinyHunters removed Instructure from its dark-web leak site and stopped publishing stolen data samples. That pattern — a victim pays, data disappears from the leak site — is standard in ransomware negotiations. It does not mean the attackers erased their only copies.
History Repeats: PowerSchool Paid and Got Hit Again
This isn't the first time an education technology company has paid a ransom and found the stolen data resurface later. In December 2024, PowerSchool suffered a breach affecting tens of millions of students. The company reportedly paid about $2.85 million in bitcoin in exchange for a video supposedly showing the attackers destroying the data.
But about five months later, in May 2025, PowerSchool's school district customers received individual extortion threats — from either the same ransomware crew or someone connected to them.
This pattern is well-documented across the industry. CrowdStrike surveyed 1,100 global security leaders last year and found that of the 78% who experienced a ransomware attack, 83% of those that paid ransoms were attacked again. Plus, 93% lost data regardless of payment.
Chainalysis found that the percentage of ransomware victims who pay dropped to an all-time low of 28% in 2025 — despite attacks hitting record highs. The industry is moving away from paying, but the education sector remains an outlier.
Why Education Keeps Getting Hit
The education sector is uniquely vulnerable. Doug Thompson explains: "The FBI says don't pay. But the operational reality at 3 a.m. during finals week or enrollment season can push institutions toward a very different calculation."
Four major vendors — PowerSchool, Infinite Campus, Canvas, and Blackboard — hold records on something close to every American student, according to Thompson. Three of the four have been breached at a multi-million-record scale in the last 18 months.
"The economics are good," Thompson said. "Instructure paid. PowerSchool paid last year. Every other ed-tech vendor's board just had a conversation about what their number would be. The pattern is established."
Infinite Campus was also targeted by ShinyHunters earlier this year as part of a broader wave of Salesforce-related intrusions.
The Com Connection
ShinyHunters is associated with "The Com" — a loosely knit group of primarily English-speaking hackers, SIM swappers, and extortionists who have been known to blackmail minors into carrying out real-world criminal acts, including shootings and stabbings. Liska noted that "protecting children's data is absolutely a critical factor in these types of decisions, especially when the attacks originate from one of the groups associated with The Com."
A representative of ShinyHunters denied any association with The Com, calling it "baseless allegations and industry propaganda." But security researchers say the group's tactics — including school-by-school extortion and direct harassment — align with The Com's known playbook.
What Students, Parents, and Educators Should Do Now
Whether or not ShinyHunters deleted its copy of the data, here's what you need to do to protect yourself — especially over the next 6-12 months:
1. Change Your Canvas Password Immediately
Even though Instructure says passwords weren't part of the breach, a different set of stolen credentials could have been compromised in the attack. Use a strong, unique password that you don't reuse anywhere else. Our password generator can create a 20+ character random string in one click.
2. Enable Multi-Factor Authentication (MFA)
Most school portals support MFA. Turn it on. This is the single most effective thing you can do to stop a phisher from accessing your account, even if they have your password. For more details, see our complete MFA guide.
3. Watch for Targeted Phishing Emails
Expect emails that appear to come from your school with context from Canvas chats. Be skeptical of any email that asks you to click a link, download a file, or enter your credentials — even if it references a real conversation. Always navigate to your school portal directly by typing the URL into your browser.
4. Use Unique Passwords for Every Account
If you reuse passwords across your school account, email, banking, and social media, one breach cascades into total account takeover. Use a password manager like Bitwarden or 1Password to generate and store unique passwords for every site.
5. Monitor for Account Takeover
Check your school account login history for unfamiliar locations or devices. Enable notifications for new logins if your school portal supports them. If you see something suspicious, report it to your school's IT department immediately.
6. Freeze Your Child's Credit
If your child's personal information — name, birth date, student ID — was exposed, consider placing a credit freeze with the three major credit bureaus (Experian, Equifax, TransUnion). Student data is particularly valuable to identity thieves because fraudulent activity can go undetected for years.
Read the Full Canvas Breach Coverage
This is the third post in our ongoing coverage of the Canvas breach. See our earlier articles for the full timeline:
- Canvas Breach: 275M Students Exposed – Password Safety Guide (11 May 2026)
- Congress Investigates Canvas Breach as Instructure Pays Ransom to ShinyHunters (13 May 2026)
FAQs
Did ShinyHunters actually delete the Canvas student data?
Cybersecurity analysts universally doubt it. Former FBI analysts and threat intelligence researchers point to the group's documented history of recycling stolen data across multiple campaigns. "We destroyed the data" is a standard line from ransomware groups after payment — it has repeatedly proven untrue.
What data was stolen from Canvas?
The stolen data includes names, email addresses, student ID numbers, and internal chat messages among users. Instructure says passwords, dates of birth, government identifiers, and financial information were not compromised in this breach.
How many people are affected by the Canvas breach?
ShinyHunters claims to have stolen data on 275 million students, teachers, and staff across nearly 9,000 educational institutions, including universities and K-12 schools.
When will the phishing attacks start?
Halcyon's Cynthia Kaiser expects targeted phishing waves within the next 6-12 months. Attackers will use leaked names, email addresses, and Canvas chat context to craft convincing lures that appear to come from schools or universities.
Should I change my Canvas password?
Yes. Even though passwords weren't part of the stolen data, a different set of account credentials could have been exposed. Use a strong, unique password not used on any other service, and enable multi-factor authentication immediately.
Did Instructure pay the ransom?
Instructure said it "reached an agreement" with ShinyHunters, which cybersecurity analysts interpret as a ransom payment. Tanium's Doug Thompson estimates the amount at $5-30 million. ShinyHunters subsequently removed Instructure from its dark-web leak site.
Can ShinyHunters still use the Canvas data for extortion?
Yes. Even after a so-called data destruction agreement, attackers can retain copies. The PowerSchool precedent is instructive: that company paid $2.85 million in December 2024, but school districts received individual extortion threats five months later in May 2025.
What other education platforms have been breached?
PowerSchool (December 2024, tens of millions of students), Infinite Campus (2025, ShinyHunters claimed a breach), and Blackboard have all suffered significant attacks in the last 18 months. Three of the four major education software vendors holding records on nearly every American student have now been breached.
Should parents be concerned about their children's data?
Yes. Student data — especially of minors — is highly valuable to identity thieves because fraudulent activity can go undetected for years. Consider placing a credit freeze with major credit bureaus, monitor for suspicious activity, and talk to your child's school about their data protection measures.
Will paying the ransom guarantee data safety?
No. CrowdStrike's research shows 93% of organizations that paid a ransom still lost data, and 83% were attacked again. Paying does not guarantee the attackers deleted their copies, and it funds future criminal operations.