⚠️ Congress Investigates Canvas Breach as Instructure Pays Ransom to ShinyHunters
On this page
The US Congress has summoned Instructure CEO Steve Daly to Capitol Hill after the education technology giant confirmed it paid a ransom to the ShinyHunters cybercrime group behind the Canvas breach that exposed data on 275 million students and faculty across 8,800 educational institutions. The House Homeland Security Committee sent a formal letter on Monday demanding a briefing, and new details have emerged about how the attackers pulled off the breach — and how much they got away with before the company opened its wallet.
In our analysis of the breach timeline, the ransom payment, and the Congressional investigation, one thing is clear: this story is far from over. Here’s what we know now that we didn’t know a week ago.
Congress Demands Answers from Instructure’s CEO
On Monday, May 12 — the same day Instructure quietly announced it had reached an agreement with ShinyHunters — the House Homeland Security Committee, chaired by Rep. Andrew Garbarino (R-NY), sent a formal letter to Instructure CEO Steve Daly requesting a briefing as part of the committee’s investigation into the Canvas breaches.
“With students at more than 8,000 institutions navigating final examinations and end of semester deadlines, the disruption of a platform that Instructure itself describes as serving more than 30 million active users globally is a matter of national concern,” Garbarino wrote. The letter, obtained by The Register, requests that Daly or a senior representative schedule a briefing covering both intrusions, the nature of the data accessed, containment measures, and the company’s coordination with federal law enforcement and CISA.
This is the first Congressional investigation into an education technology data breach of this scale, and it signals that lawmakers are beginning to treat student data security as a national security issue — not just a consumer protection problem.
Instructure Paid the Ransom — Here’s What We Know
Late Monday, Instructure confirmed what many security researchers had suspected: the company paid an undisclosed sum to ShinyHunters in exchange for the deletion of stolen data. The timing was critical — the ransom deadline was set for May 12, after which ShinyHunters had threatened to publicly release the records of all 8,800 affected institutions.
Instructure said it received “digital confirmation of data destruction (shred logs)” from ShinyHunters, and stated it had been informed that no Instructure customers would be extorted as a result of the incident, publicly or otherwise. Whether that promise holds remains to be seen — data extortion groups have a well-documented history of breaking such agreements.
Here’s the problem with trusting a ransomware gang’s “shred logs”: there is no technical way to verify that stolen data has actually been deleted. A group like ShinyHunters can generate fake destruction logs, keep copies on offline storage, or sell the data to other criminal groups before claiming deletion. In our research, we’ve tracked over a dozen cases where ransomware victims paid for data deletion only to find the data resurface on leak sites months later. The only thing a ransom payment guarantees is that the attackers got paid.
How ShinyHunters Actually Broke Into Canvas
The Register reported that ShinyHunters exploited cross-site scripting (XSS) vulnerabilities in Canvas’ Free-for-Teacher learning software to gain administrative access to the platform. During the first intrusion, detected on April 29, the attackers claimed to have stolen approximately 3.6 TB of uncompressed data, including usernames, email addresses, course names, enrollment information, and messages between users.
On May 2, Instructure’s Chief Information Security Officer Steve Proud declared the incident “contained.” That declaration turned out to be premature. On May 7, ShinyHunters broke back into Canvas via the same XSS vulnerability — the patch hadn’t been deployed comprehensively — and injected JavaScript ransom demands directly into hundreds of Canvas school login portals. Instructure had no choice but to take the entire platform offline during final exams and Advanced Placement testing.
Security researcher Dipan Mann, founder and CEO of Cloudskope, slammed Instructure’s handling of the incident. Mann noted that this is at least the third time in eight months that ShinyHunters has breached Instructure’s environment. In September 2025, ShinyHunters used a Canvas-mediated access path to steal University of Pennsylvania donor records, internal memos, and confidential materials — an incident that was treated as an isolated Penn problem rather than a systemic Instructure vulnerability.
“Penn was the named victim,” Mann wrote. “Instructure was the mechanism. The incident was treated as a Penn-specific story by most of the national press and quietly handled by Instructure as a customer-specific matter. That framing was wrong then. It is dramatically more wrong in light of the May 2026 events.”
What Data Was Actually Stolen — and What Wasn’t
Instructure’s official statement on May 6 confirmed that the stolen data includes names, email addresses, student ID numbers, and internal messages. The company stated it found no evidence that passwords, dates of birth, government identifiers, or financial information were compromised.
We’ve seen this pattern before in major education breaches. In our credential stuffing guide, we warned that even non-financial data like email addresses and usernames are extremely valuable to cybercriminals. ShinyHunters claims the stolen dataset includes “several billion private messages among students and teachers,” along with phone numbers — claims Instructure has not confirmed or denied.
The key concern for affected students and faculty: even if your Canvas password wasn’t in the stolen data, your email address and student ID now are. That puts you at risk of targeted phishing attacks — personalized emails that reference your specific courses, instructors, or classmates to trick you into handing over login credentials.
If you or your children are affected, we’ve put together a practical checklist below. For a broader look at how credential leaks feed into credential-stuffing attacks, see our guide on what credential stuffing is and how to prevent it.
Timeline: How the Canvas Breach Unfolded Over Three Weeks
- September 2025: ShinyHunters breaches Instructure’s Salesforce environment, steals UPenn data. Incident framed as a Penn-specific issue.
- April 29, 2026: ShinyHunters exploits XSS in Canvas Free-for-Teacher software, gains admin access. 3.6 TB of data exfiltrated.
- May 1: ShinyHunters demonstrates the breach to Instructure.
- May 2: Instructure CISO Steve Proud declares the incident contained.
- May 6: Instructure issues public statement confirming stolen data includes names, emails, student IDs, and messages. Denies passwords or financial data were taken.
- May 7: ShinyHunters re-exploits the same unpatched XSS vulnerability, defaces hundreds of Canvas login portals with ransom demands. Instructure takes Canvas offline.
- May 12: Instructure pays ransom and receives “shred logs” from ShinyHunters. House Homeland Security Committee sends formal letter demanding CEO briefing. ShinyHunters removes Instructure from its leak site.
- May 13 (today): Instructure plans public webinar with leadership team to detail the cyber attack across multiple time zones. Congressional investigation ongoing.
What Students and Faculty Should Do Right Now
If you’re a student, teacher, or administrator at a school or university that uses Canvas, here’s our recommended action plan:
- Change your university password immediately — even if Instructure says passwords weren’t leaked. Many schools use the same credentials for Canvas, email, and campus portals. Use a secure password generator to create a strong, unique password.
- Enable multi-factor authentication on your university account. Most institutions support MFA through authenticator apps like Google Authenticator or Authy — turn it on right now. Microsoft research shows MFA blocks 99.9% of automated account attacks.
- Watch for targeted phishing emails — your name, email, and student ID are now in the hands of a known cybercrime group. Any message claiming to be from your school’s IT department asking you to “verify your Canvas account” should be treated as suspicious. AI-generated phishing attacks have surged 1,265% in 2026, and this breach gives attackers exactly the personalization data they need.
- Check your accounts on Have I Been Pwned — enter your university email address to see if it appears in known breach datasets. Set up breach monitoring alerts for all your email addresses.
- Use a password manager to generate and store unique passwords for every account. If one service gets breached, your other accounts stay safe because every password is different. Bitwarden and 1Password both offer free tiers for students.
For a complete walkthrough of auditing all your accounts, see our step-by-step guide on how to perform a personal password security audit in 2026.
FAQs
Should I change my Canvas password?
Yes. Even though Instructure says passwords weren’t stolen, ShinyHunters compromised administrative access to Canvas and could have accessed password hashes. Change your Canvas password immediately using a strong password generator, and make sure it’s different from your campus email password.
Did Instructure actually confirm they paid the ransom?
They used the phrase “reached an agreement with the unauthorized actor” and stated they received “digital confirmation of data destruction (shred logs).” Security researchers universally interpret this as a ransom payment. The exact amount has not been disclosed.
Can ShinyHunters be trusted to have actually deleted the data?
No. There is no technical mechanism for a victim to verify that stolen data has been permanently deleted. Ransomware groups have a long history of selling or re-leaking data after claiming deletion. The NIST and CISA guidance on ransomware response recommends organizations never pay ransoms for this exact reason.
How many schools and students are affected?
ShinyHunters threatened to leak data from 275 million students and faculty across 8,800 educational institutions using Canvas. The actual number of affected individuals may be lower, but Instructure has not provided a precise count.
Is my financial information at risk?
Instructure stated it found no evidence that financial information, government IDs, or dates of birth were compromised. However, your name, email address, and student ID are now accessible to a known cybercrime group — and those are sufficient for highly targeted phishing attacks.
What is the Congressional investigation looking into?
The House Homeland Security Committee has requested a briefing from CEO Steve Daly covering four areas: how both intrusions happened, what data was accessed, what Instructure has done to contain the threat and notify affected institutions, and the adequacy of the company’s coordination with federal law enforcement and CISA.
Does the NIST password guidelines (SP 800-63B) help in this situation?
Absolutely. NIST SP 800-63B recommends changing passwords only when there is evidence of compromise — which there absolutely is here. The updated 2026 guidelines emphasize length over complexity and recommend passphrases for high-security accounts. Read our breakdown of the updated NIST guidelines for detailed recommendations.
To stay protected against evolving threats like infostealer malware and credential theft, consider a comprehensive security suite like Kaspersky Premium. It includes advanced malware protection, password monitoring, and breach alerts that help you detect compromised credentials early.