The Login Page That Demanded a Ransom
ShinyHunters defaced Canvas mid-finals week, taking the learning platform offline and exposing what one researcher calls an eight-month attack arc against Instructure.

A computer science student at the University of Texas signed in to submit a problem set on Thursday morning and found, instead of the familiar red Canvas dashboard, a ransom note. By lunchtime the screenshots were everywhere. Group chats lit up. Professors emailed apologies. Someone in a Reddit thread joked that the hackers had bought them all an extra day on the take-home.
The joke did not last. Canvas, the learning management system run by Instructure and used by roughly 9,000 schools and universities, was pulled offline Thursday after the extortion crew ShinyHunters defaced its login portal with a threat to leak data on 275 million students and faculty. Instructure swapped the ransom message for a notice claiming "scheduled maintenance." Nobody bought it.
This is at least the third time in eight months that ShinyHunters has been inside Instructure's environment, according to Dipan Mann, founder and CEO of Cloudskope, who published a timeline calling the May 7 defacement a deliberate sequel. The first act, Mann argues, was the September 2025 University of Pennsylvania breach, in which roughly 461 megabytes of donor records and internal memos surfaced on the group's leak blog after Penn refused a $1 million ransom demand. "Penn was the named victim. Instructure was the mechanism," Mann wrote.
The second act came on May 1, when ShinyHunters first told Instructure they were back. Chief Information Security Officer Steve Proud declared the incident contained on May 2. Five days later, the login page itself was carrying the ransom note.
Instructure says the stolen data includes names, email addresses, student ID numbers and messages between users. No passwords, dates of birth, government IDs or financial data, the company said in its May 6 statement. ShinyHunters tells a bigger story, claiming several billion private messages. Both could be true. Neither is reassuring to a freshman in the middle of finals.
The extortion message urged individual schools to negotiate their own payments, regardless of what Instructure does. A person close to the investigation said several universities have already opened conversations. The samples ShinyHunters had posted are now gone from the leak blog, a signal that usually means money is moving or talks have started.
ShinyHunters has had a busy spring. The same crew claimed the ADT breach last month, which they say began with a vishing call against an employee's Okta single sign-on. Charles Carmakal, chief technology officer at Mandiant Consulting, would not comment on Canvas specifically but said "there are multiple concurrent and discrete ShinyHunters intrusion and extortion campaigns happening right now."
By Friday morning Instructure said Canvas was working again and blamed Free-for-Teacher accounts, the same vector as the week before. Those accounts are now shut off. The finals will be rescheduled. The messages, wherever they are, have already been read by someone.



