A learning management system is an unusually complete record of a young person. It holds the name, the institutional identifier, the coursework, the messages to and from staff, and the years over which all of it accumulated. Canvas holds that for a substantial share of North American education.
ShinyHunters compromised Instructure’s Canvas environment in late April 2026 and claimed 3.65 terabytes covering roughly 275 million records across about 8,800 institutions. The route it described was a weakness in the Free-For-Teacher service — the free tier, running alongside the paid one.
Instructure confirmed exposure of names, email addresses, student identifiers and some private messages. It stated there was no evidence that passwords, financial data or Social Security numbers were taken. Those two accounts are not in conflict: the record count and the field list describe different things, and the company’s narrower list is the one supported by its own investigation.
When The Deadline Passed, The Pressure Moved Downstream
The escalation is the instructive part. When the initial negotiation window closed, the group defaced Canvas login portals at around 330 institutions and began approaching schools individually. That converts one negotiation the vendor controls into hundreds it does not, each conducted with a customer who has less information and more immediate panic.
What A Shred Log Proves
Under the reported agreement, the group returned the data and supplied “shred logs” as confirmation that its copies were destroyed. Treat that as what it is: a file produced by the party with an interest in its contents, describing an action that cannot be observed.
This is not an argument that Instructure decided wrongly. An institution facing school-by-school extortion of minors’ records is choosing between bad options on a clock. It is an argument about what the artefact establishes, which is nothing beyond the group’s willingness to produce it.
The durable question for the sector is narrower and more answerable: why a free tier shared enough infrastructure with the paid product that a weakness in one reached the data of the other.
Compiled from public reporting and Instructure’s own statements, listed below. Record counts and volume figures originate with the actor and are labelled as claims throughout; the field list is the company’s. We did not review the returned data or the deletion logs. Corrections: corrections@forensicpost.com.