Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Canvas Security Incident: What Happened and Who Are ShinyHunters?

Instructure's 2026 Canvas incident affected page access and exposed some account data. Here is the confirmed timeline, possible impact, and user guidance.

Table of Contents

Canvas by Instructure suffered two related security incidents in April and May 2026. The second incident, on May 7, briefly changed pages shown to some users and led Instructure to place Canvas in maintenance mode. The company later said the same threat actor used a second vulnerability but did not exfiltrate additional data during the May 7 intrusion.

Canvas hacked: Who are the ShinyHunters group? Picture 1

What Instructure says happened

According to Instructure's incident updates, it detected unauthorized Canvas activity on April 29. The attacker entered through a Free-for-Teacher account, and the company revoked access and began a forensic investigation.

On May 7, the attacker exploited a second vulnerability associated with the same route. Some customer-facing pages were modified, including custom styling and, in some cases, authentication-provider settings. Instructure says enhanced monitoring detected and disabled the second attack in about 10 minutes, after which it temporarily took Canvas offline to investigate and apply safeguards.

The company permanently discontinued the Free-for-Teacher service and later introduced additional security changes. Canvas's paid institutional service returned online.

What data may have been involved

Instructure's investigation found that the earlier activity may have exposed fields such as usernames, email addresses, course names, enrollment information, and messages for affected institutions. The company said it had not identified core learning data—such as course content and submissions—or credentials as involved, and reported no evidence that the May 7 incident caused further data exfiltration.

Impact was not identical for every institution. Administrators should rely on direct notices and institution-specific reports from Instructure rather than assuming that every Canvas tenant exposed the same data.

Who are ShinyHunters?

ShinyHunters is a name associated with financially motivated data theft, extortion, and the sale of stolen records. It is not necessarily a single stable organization with a public membership list; threat-actor names can be reused or represent overlapping participants and campaigns.

A 2024 US Department of Justice case described a conspirator linked to ShinyHunters who helped create phishing sites and steal company data. The DOJ said data from more than 60 companies was advertised for sale between 2020 and 2021. That case documents earlier activity, but it should not be treated as proof of the identity of every person involved in a later incident.

What students and instructors should do

  • Follow instructions from your school or university IT department; it has the institution-specific incident information.
  • Be cautious with emails or login pages that create urgency around Canvas access. Open the known school portal directly instead of following an unexpected link.
  • If your institution tells you credentials were affected, change the relevant password and any other account that reused it.
  • Enable multi-factor authentication where your institution supports it. Read when a password change is actually useful.
  • Check course email, the official status page, and instructor announcements for deadline or exam changes during an outage.

What Canvas administrators should check

Instructure advised customers that logs could show unusual access by support-representative accounts between April 25 and April 30 and briefly on May 7. Administrators should compare suspicious access with legitimate support tickets, preserve relevant logs, identify the designated security contact, and follow Instructure's tenant-specific guidance.

Organizations using single sign-on should review authentication settings with their identity provider. Those using native Canvas authentication should apply Instructure's current MFA and password guidance rather than issuing an uncoordinated reset that could disrupt access or conceal evidence.

The official Instructure incident page contains the current timeline and customer guidance. The Department of Justice case summary provides background on earlier ShinyHunters-linked crimes.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.