5 min read

ShinyHunters Canvas Extortion Campaign

ShinyHunters Canvas Extortion Campaign

Jump to...

Section 1: Executive Summary (Current Status as of May 24, 2026)

On April 30, 2026, the threat actor group ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account program to gain unauthorized access to Canvas, one of the most widely used learning management systems in the United States. The breach exposed sensitive information belonging to students, faculty, and staff across 8,809 institutions worldwide. ShinyHunters claimed to have stolen 275 million records and exfiltrated approximately 3.65 terabytes of data. 

This incident is not ShinyHunters’ first intrusion into Instructure’s environment. In September 2025, the group breached Instructure’s Salesforce business systems through social engineering. The September 2025 Salesforce incident may have provided the actor with additional knowledge of Instructure’s environment, but no public source has confirmed that it directly enabled the April/May 2026 Canvas intrusion. Rather than negotiate following the second breach, Instructure applied security patches. ShinyHunters responded by escalating. On May 7, 2026, the group simultaneously defaced Canvas login portals across affected institutions, disrupted final examinations at multiple universities, and issued a new ransom deadline of May 12, 2026. 

ShinyHunters operates under a pay-or-leak extortion model, applying pressure through countdown timers, dark web leak sites, and live production defacement as coercive instruments. Notably, no malware was deployed during this operation. There is currently no public indication of traditional malware deployment or ransomware encryption during the Canvas incident. Reported activity appears to have relied on abused account access, application-layer vulnerabilities, and platform/API functionality. 

This report provides an overview of the incident, a technical analysis of the exploited attack surface and associated MITRE ATT&CK techniques, infrastructure, and related indicators of compromise, and recommended remediation and mitigation actions for affected institutions and their users.

shinyhunter_screenshot

Figure 1. ShinyHunters Defacement Warning Displayed on Affected Canvas Portals 

II. Technical Analysis

A. Exploited Attack Surface

Per Bitdefender, the May 2026 incident exploited an issue related to Instructure’s Free-For-Teacher account program. These accounts allowed educators to create Canvas accounts without institutional affiliation or verification, and ran on production Canvas infrastructure, not a separate sandbox [1].

Red Piranha reported that the exploited Free-For-Teacher infrastructure lacked sufficient permission isolation from institutional data stores, creating a potential trust boundary weakness within the Canvas SaaS environment [2].

These Free-For-Teacher accounts shared infrastructure with paid institutional tenants. Weak logical isolation within a multi-tenant SaaS environment may have enabled lateral movement between tenants [3].

NOTE: At this time, Instructure has not disclosed the exact technical mechanism; we cannot conclude yet which exploitation method was utilized.

B. Exposed Data

Confirmed exposed data included names, email addresses, student IDs, and some private messages, creating a significant risk for personalized phishing after the breach window closed.

C. Infrastructure and Related Indicators

The following infrastructure and indicators were publicly referenced in reporting associated with the ShinyHunters Canvas Incident.

Indicator Type Data Description
URL hxxp://91[.]215[.]85[.]103/pay_or_leak/instructure_affected_schools_list[.]txt  hxxp://91[.]215[.]85[.]103/pay_or_leak/instructure_affected_schools_list[.]txt 
URL hxxp[:]//shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid[.]onion/  ShinyHunters public data leak site (defanged – access only from sandboxed environment, must use Tor or similar browsers) 
IP  91[.]215[.]85[.]103   ShinyHunters infrastructure hosting affected-schools list (defanged)  
 
D. MITRE ATT&CK Technique Mapping

The following MITRE ATT&CK mappings were provided by Red Piranha based on observed ShinyHunters activity, FBI reporting, and MITRE Campaign C0059. Some techniques were directly observed during the Canvas incident, while others reflect historically associated ShinyHunters tradecraft [2]. 

 

Tactic Technique MITRE ATT&CK ID Observed Content
Reconnaissance Gathering Victim’s Organization Information T1591 Dark web forum data, SaaS portal scanning, BPO targeting lists
Initial Access Phishing: Voice Phishing T1566.004 IT impersonation calls to help desk and BPO agents; OAuth authorization guidance
Initial Access Utilizing Valid Accounts T1078 Stolen credentials from infostealer markets; FFT account exploitation (Canvas)
Initial Access Exploiting Public-Facing Application T1190 Salesforce Aura API guest profile misconfiguration; Canvas FFT account vulnerability
Execution Command and Scripting Interpreter T1059 Automated SOQL queries; S3 API calls via S3 Browser; API scripting tooling
Persistence Utilizing Additional Cloud Credentials  T1098.001 OAuth app registration within Salesforce for persistent access
Defense Evasion Utilizing Valid Cloud Accounts T1078.004 Reported activity appeared to rely heavily on legitimate OAuth tokens, valid accounts, and platform functionality. At the time of writing, public reporting had not identified evidence of traditional malware deployment associated with this phase of the incident. 
Defense Evasion Exploiting for Privilege Escalation T1068 Canvas FFT account privilege escalation to access institutional data
Credential Access Stealing Application Access Token T1528 AWS keys, Snowflake tokens, OAuth tokens from Salesforce objects and public repos 
Credential Access Input Capture T1056 Credential harvesting pages mimicking enterprise identity provider login flows 
Discovery Data from Information Repositories T1213 SOQL enumeration of Salesforce objects; Canvas database record traversal 
Discovery Cloud Infrastructure Discovery T1580 S3 bucket configuration enumeration; code repository scanning for secrets 
Lateral Movement Application Access Token T1550.001 SSO token reuse across identity providers, collaboration platforms, and cloud data stores 
Lateral Movement Exploitation of Remote Services T1210 Supply chain pivot via third-party analytics partner to cloud data environments 
Collection Email Collection T1114 Exfiltration of private messages and communications data (Canvas LMS breach) 
Exfiltration Transfer Data to Cloud Account  T1537 Data moved via S3 Browser and WinSCP to attacker-controlled storage 
Exfiltration Exfiltration Over Web Service  T1567.002 Data Loader API; Aura API bulk export; Canvas API data retrieval 
Impact Financial Theft/Extortion T1657 Pay-or-leak ransom model; countdown timers; named executive contact 
Impact Defacement T1491 Canvas login portal defacement on 7 May 2026 across 9,000 institutions 
Impact Data Encrypted for Impact T1486 ShinySp1d3r RaaS in development, Windows encryptor confirmed, Linux version imminent 

Table 2. MITRE ATT&CK Technique Mapping 

III. Remediation and Mitigation

This is ShinyHunters’ second breach within Canvas’ parent company, Instructure, in eight months. The first breach occurred in September 2025 and had a different attack surface, involving voice phishing and social engineering for initial access. This breach involves the exploitation of the Free-For-Teacher account program, a lower-friction onboarding that allows educators to create accounts without institutional verification, gaining access to Canvas features for their classrooms [4].

A. Information Potentially Exposed

According to Instructure, exposed information includes:

  • Usernames
  • Email addresses
  • Course names
  • Enrollment information
  • Private messages
B. Actions Taken by Instructure

Instructure stated it has:

  • Temporarily shut down Free-For-Teacher accounts to remove the access path used by the threat actor.

  • Revoked privileged credentials and access tokens tied to affected systems.

  • Rotated internal keys, restricted token creation pathways, and added monitoring across their platforms 

Beyond immediate response, Instructure is working on hardening administrative access, token management, permissions, monitoring, and related workflows. They are prioritizing three things: completing a rigorous investigation, communicating verified information to impacted customers, and continuing to strengthen safeguards to protect customer and student data.

C. Recommended Actions for Institutions and Users

Because private messages and enrollment information may have been exposed, threat actors may attempt to craft highly targeted phishing campaigns impersonating instructors, school administrators, or Canvas notifications. Institutions are advised to continue monitoring for phishing attempts and suspicious activity associated with educational data that has been exposed. 

Students, parents, faculty, and staff should:

  • Be cautious of unexpected emails or messages referencing this incident.

  • Avoid clicking on suspicious links.

  • Report anything unusual to your school or institution's IT or security team. 

     

Your respective school/institution should be the first point of contact. Instructure states that it is committed to providing frequent updates. Instructure Incident Update serves as the central source for confirmed updates, customer communications, and updated FAQs about this incident. 

IV. References

  1. Bitdefender. (2026, May 8). Technical advisory: ShinyHunters breach of Instructure Canvas LMS. Bitdefender Business Insights

    https://businessinsights.bitdefender.com/technical-advisory-shinyhunters-breach-instructure-canvas-lms

  2. Red Piranha (2026). ShinyHunters Canvas breach. Red Piranha.

    https://redpiranha.net/news/shinyhunters-canvas-breach

  3. Halcyon. (2026). Education sector in the crosshairs: ShinyHunters extortion campaign against Instructure. Halcyon.

    https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure

  4. Instructure (2026). Incident update. Instructure.

    https://www.instructure.com/incident_update

Other posts of interest...

Qilin Ransomware – A Double Extortion Campaign

1 min read

Qilin Ransomware – A Double Extortion Campaign

Originally Published December 8, 2025

Read More
Malware Campaign Exploits Microsoft Dev Tunnels

1 min read

Malware Campaign Exploits Microsoft Dev Tunnels

Originally Published March 31, 2025

Read More
BRICKSTORM APT Intrusion Campaign

1 min read

BRICKSTORM APT Intrusion Campaign

Originally Published December 3, 2025

Read More