1 min read
Qilin Ransomware – A Double Extortion Campaign
Originally Published December 8, 2025
5 min read
Cyber Florida SOCAP Team
:
Updated on September 16, 2026
On April 30, 2026, the threat actor group ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account program to gain unauthorized access to Canvas, one of the most widely used learning management systems in the United States. The breach exposed sensitive information belonging to students, faculty, and staff across 8,809 institutions worldwide. ShinyHunters claimed to have stolen 275 million records and exfiltrated approximately 3.65 terabytes of data.
This incident is not ShinyHunters’ first intrusion into Instructure’s environment. In September 2025, the group breached Instructure’s Salesforce business systems through social engineering. The September 2025 Salesforce incident may have provided the actor with additional knowledge of Instructure’s environment, but no public source has confirmed that it directly enabled the April/May 2026 Canvas intrusion. Rather than negotiate following the second breach, Instructure applied security patches. ShinyHunters responded by escalating. On May 7, 2026, the group simultaneously defaced Canvas login portals across affected institutions, disrupted final examinations at multiple universities, and issued a new ransom deadline of May 12, 2026.
ShinyHunters operates under a pay-or-leak extortion model, applying pressure through countdown timers, dark web leak sites, and live production defacement as coercive instruments. Notably, no malware was deployed during this operation. There is currently no public indication of traditional malware deployment or ransomware encryption during the Canvas incident. Reported activity appears to have relied on abused account access, application-layer vulnerabilities, and platform/API functionality.
This report provides an overview of the incident, a technical analysis of the exploited attack surface and associated MITRE ATT&CK techniques, infrastructure, and related indicators of compromise, and recommended remediation and mitigation actions for affected institutions and their users.

Figure 1. ShinyHunters Defacement Warning Displayed on Affected Canvas Portals
Per Bitdefender, the May 2026 incident exploited an issue related to Instructure’s Free-For-Teacher account program. These accounts allowed educators to create Canvas accounts without institutional affiliation or verification, and ran on production Canvas infrastructure, not a separate sandbox [1].
Red Piranha reported that the exploited Free-For-Teacher infrastructure lacked sufficient permission isolation from institutional data stores, creating a potential trust boundary weakness within the Canvas SaaS environment [2].
These Free-For-Teacher accounts shared infrastructure with paid institutional tenants. Weak logical isolation within a multi-tenant SaaS environment may have enabled lateral movement between tenants [3].
NOTE: At this time, Instructure has not disclosed the exact technical mechanism; we cannot conclude yet which exploitation method was utilized.
Confirmed exposed data included names, email addresses, student IDs, and some private messages, creating a significant risk for personalized phishing after the breach window closed.
The following infrastructure and indicators were publicly referenced in reporting associated with the ShinyHunters Canvas Incident.
| Indicator Type | Data | Description |
| URL | hxxp://91[.]215[.]85[.]103/pay_or_leak/instructure_affected_schools_list[.]txt | hxxp://91[.]215[.]85[.]103/pay_or_leak/instructure_affected_schools_list[.]txt |
| URL | hxxp[:]//shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid[.]onion/ | ShinyHunters public data leak site (defanged – access only from sandboxed environment, must use Tor or similar browsers) |
| IP | 91[.]215[.]85[.]103 | ShinyHunters infrastructure hosting affected-schools list (defanged) |
The following MITRE ATT&CK mappings were provided by Red Piranha based on observed ShinyHunters activity, FBI reporting, and MITRE Campaign C0059. Some techniques were directly observed during the Canvas incident, while others reflect historically associated ShinyHunters tradecraft [2].
| Tactic | Technique | MITRE ATT&CK ID | Observed Content |
| Reconnaissance | Gathering Victim’s Organization Information | T1591 | Dark web forum data, SaaS portal scanning, BPO targeting lists |
| Initial Access | Phishing: Voice Phishing | T1566.004 | IT impersonation calls to help desk and BPO agents; OAuth authorization guidance |
| Initial Access | Utilizing Valid Accounts | T1078 | Stolen credentials from infostealer markets; FFT account exploitation (Canvas) |
| Initial Access | Exploiting Public-Facing Application | T1190 | Salesforce Aura API guest profile misconfiguration; Canvas FFT account vulnerability |
| Execution | Command and Scripting Interpreter | T1059 | Automated SOQL queries; S3 API calls via S3 Browser; API scripting tooling |
| Persistence | Utilizing Additional Cloud Credentials | T1098.001 | OAuth app registration within Salesforce for persistent access |
| Defense Evasion | Utilizing Valid Cloud Accounts | T1078.004 | Reported activity appeared to rely heavily on legitimate OAuth tokens, valid accounts, and platform functionality. At the time of writing, public reporting had not identified evidence of traditional malware deployment associated with this phase of the incident. |
| Defense Evasion | Exploiting for Privilege Escalation | T1068 | Canvas FFT account privilege escalation to access institutional data |
| Credential Access | Stealing Application Access Token | T1528 | AWS keys, Snowflake tokens, OAuth tokens from Salesforce objects and public repos |
| Credential Access | Input Capture | T1056 | Credential harvesting pages mimicking enterprise identity provider login flows |
| Discovery | Data from Information Repositories | T1213 | SOQL enumeration of Salesforce objects; Canvas database record traversal |
| Discovery | Cloud Infrastructure Discovery | T1580 | S3 bucket configuration enumeration; code repository scanning for secrets |
| Lateral Movement | Application Access Token | T1550.001 | SSO token reuse across identity providers, collaboration platforms, and cloud data stores |
| Lateral Movement | Exploitation of Remote Services | T1210 | Supply chain pivot via third-party analytics partner to cloud data environments |
| Collection | Email Collection | T1114 | Exfiltration of private messages and communications data (Canvas LMS breach) |
| Exfiltration | Transfer Data to Cloud Account | T1537 | Data moved via S3 Browser and WinSCP to attacker-controlled storage |
| Exfiltration | Exfiltration Over Web Service | T1567.002 | Data Loader API; Aura API bulk export; Canvas API data retrieval |
| Impact | Financial Theft/Extortion | T1657 | Pay-or-leak ransom model; countdown timers; named executive contact |
| Impact | Defacement | T1491 | Canvas login portal defacement on 7 May 2026 across 9,000 institutions |
| Impact | Data Encrypted for Impact | T1486 | ShinySp1d3r RaaS in development, Windows encryptor confirmed, Linux version imminent |
Table 2. MITRE ATT&CK Technique Mapping
This is ShinyHunters’ second breach within Canvas’ parent company, Instructure, in eight months. The first breach occurred in September 2025 and had a different attack surface, involving voice phishing and social engineering for initial access. This breach involves the exploitation of the Free-For-Teacher account program, a lower-friction onboarding that allows educators to create accounts without institutional verification, gaining access to Canvas features for their classrooms [4].
According to Instructure, exposed information includes:
Instructure stated it has:
Temporarily shut down Free-For-Teacher accounts to remove the access path used by the threat actor.
Revoked privileged credentials and access tokens tied to affected systems.
Rotated internal keys, restricted token creation pathways, and added monitoring across their platforms
Beyond immediate response, Instructure is working on hardening administrative access, token management, permissions, monitoring, and related workflows. They are prioritizing three things: completing a rigorous investigation, communicating verified information to impacted customers, and continuing to strengthen safeguards to protect customer and student data.
Because private messages and enrollment information may have been exposed, threat actors may attempt to craft highly targeted phishing campaigns impersonating instructors, school administrators, or Canvas notifications. Institutions are advised to continue monitoring for phishing attempts and suspicious activity associated with educational data that has been exposed.
Students, parents, faculty, and staff should:
Be cautious of unexpected emails or messages referencing this incident.
Avoid clicking on suspicious links.
Report anything unusual to your school or institution's IT or security team.
Your respective school/institution should be the first point of contact. Instructure states that it is committed to providing frequent updates. Instructure Incident Update serves as the central source for confirmed updates, customer communications, and updated FAQs about this incident.
Bitdefender. (2026, May 8). Technical advisory: ShinyHunters breach of Instructure Canvas LMS. Bitdefender Business Insights
Red Piranha (2026). ShinyHunters Canvas breach. Red Piranha.
Halcyon. (2026). Education sector in the crosshairs: ShinyHunters extortion campaign against Instructure. Halcyon.
Instructure (2026). Incident update. Instructure.
1 min read
Originally Published December 8, 2025
1 min read
Originally Published March 31, 2025
1 min read
Originally Published December 3, 2025