Desk live·
ForensicPost
Breaches/Education/File 26-0501

Instructure Paid, and Got Shred Logs Back

ShinyHunters claimed 3.65 terabytes from Canvas across roughly 8,800 institutions, defaced hundreds of login portals when the deadline passed, then settled. The receipt was a set of deletion logs — a form of proof nobody can audit.

Constructed geometry · not a chart of case data
TargetInstructure — Canvas
ActorShinyHunters
S. Rosler & D. Kennedy13 min readConfidence: high3 sources reviewed

A learning management system is an unusually complete record of a young person. It holds the name, the institutional identifier, the coursework, the messages to and from staff, and the years over which all of it accumulated. Canvas holds that for a substantial share of North American education.

ShinyHunters compromised Instructure’s Canvas environment in late April 2026 and claimed 3.65 terabytes covering roughly 275 million records across about 8,800 institutions. The route it described was a weakness in the Free-For-Teacher service — the free tier, running alongside the paid one.

Instructure confirmed exposure of names, email addresses, student identifiers and some private messages. It stated there was no evidence that passwords, financial data or Social Security numbers were taken. Those two accounts are not in conflict: the record count and the field list describe different things, and the company’s narrower list is the one supported by its own investigation.

When The Deadline Passed, The Pressure Moved Downstream

The escalation is the instructive part. When the initial negotiation window closed, the group defaced Canvas login portals at around 330 institutions and began approaching schools individually. That converts one negotiation the vendor controls into hundreds it does not, each conducted with a customer who has less information and more immediate panic.

Reported sequence — April to May 2026Source: public reporting and vendor statements, listed below
TimeEventEvidence
25 AprInitial accessFree-For-Teacher service weakness, per actor claim
Early MayListing3.65 TB claimed across ~8,800 institutions
Early MayDefacementLogin portals altered at ~330 institutions
11 MaySettlementAgreement reached one day before the stated deadline
12 MayDeadlinePublication deadline passes without a leak

What A Shred Log Proves

Under the reported agreement, the group returned the data and supplied “shred logs” as confirmation that its copies were destroyed. Treat that as what it is: a file produced by the party with an interest in its contents, describing an action that cannot be observed.

This is not an argument that Instructure decided wrongly. An institution facing school-by-school extortion of minors’ records is choosing between bad options on a clock. It is an argument about what the artefact establishes, which is nothing beyond the group’s willingness to produce it.

The durable question for the sector is narrower and more answerable: why a free tier shared enough infrastructure with the paid product that a weakness in one reached the data of the other.

How we reported this

Compiled from public reporting and Instructure’s own statements, listed below. Record counts and volume figures originate with the actor and are labelled as claims throughout; the field list is the company’s. We did not review the returned data or the deletion logs. Corrections: corrections@forensicpost.com.

Sources
  1. Technical advisory: ShinyHunters breach of Instructure Canvas LMSBitdefender
  2. Education sector in the crosshairs: ShinyHunters’ extortion campaign against InstructureHalcyon
  3. Canvas/Instructure cyberattack — key developments and action items for higher educationReed Smith
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary