Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Ransomware Group ShinyHunters Disrupts Canvas LMS, Affecting 30 Million Students and Educators

ShinyHunters leveraged an undocumented flaw in Canvas's Free‑For‑Teacher version to redirect users to a ransom note, forcing Instructure to temporarily shut down the platform. The incident impacts over 30 M users across K‑12 and higher‑education institutions and raises concerns about data privacy and supply‑chain risk.

LiveThreat™ Intelligence · 📅 May 08, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

Ransomware Group ShinyHunters Disrupts Canvas LMS, Affecting 30 Million Students and Educators

What Happened — The ransomware gang ShinyHunters compromised Instructure’s Canvas learning‑management system, redirecting users to a ransom note and forcing the vendor to take the platform offline. The attackers exploited an unspecified vulnerability in the free “Free‑For‑Teacher” version, leading to two breach attempts within a week.

Why It Matters for TPRM —

  • Service outage impacts academic continuity for millions of K‑12 and higher‑education users.
  • Threat actors claim to have exfiltrated student and teacher data from ~8,000 institutions, raising data‑privacy risk.
  • The incident highlights supply‑chain exposure when a SaaS vendor’s free tier is leveraged as an attack surface.

Who Is Affected — K‑12 schools, colleges, universities, and other educational institutions worldwide that use Canvas (≈30 M active users).

Recommended Actions — Review Instructure’s security controls and incident‑response posture, validate that no credential or data leakage occurred, and ensure contractual clauses address vulnerability management for free‑tier services.

Technical Notes — Attack vector: exploitation of an undocumented vulnerability in the Free‑For‑Teacher version of Canvas; no evidence of persistence, credential theft, or data exfiltration was found by Instructure’s forensics. The ransomware note was delivered via page redirection after login. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/canvas-e-learning-platform-breached-by-cybercriminals-a-31639 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →