Instructure (Canvas LMS) Reaches Agreement with ShinyHunters to Suppress Stolen Data – May 2026
Instructure, the company behind the Canvas learning management system, has reportedly reached an 'agreement' with the ShinyHunters extortion group following a data breach to prevent the stolen data from being publicly leaked. ShinyHunters is a prolific cybercriminal group known for large-scale data theft and extortion. The incident raises significant concerns about the exposure of student and institutional data across the many educational organisations that rely on Canvas. The nature of the 'agreement' implies a ransom or non-disclosure arrangement, though full details have not been confirmed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Canvas is one of the most widely used LMS platforms globally, meaning the breach potentially affects millions of students, faculty, and institutional records. However, the 'agreement' to suppress the leak may limit immediate downstream harm, and direct property or physical damage is absent.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
1 active match
- TRIA Certified AreasRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts