TL;DR: ShinyHunters' May 8 leak deadline passed without a data dump, but not because anyone paid. On May 6, Instructure publicly told customers the incident was "resolved" and Canvas was "fully operational" [1]. On May 7 around 3:30 p.m. ET, Canvas login pages at Harvard, the University of Pennsylvania, Duke, the University of Wisconsin-Madison, the University of Oklahoma, and dozens of other universities went black with a fresh extortion screen [2][3][4]. The new message: "ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches'" [5][6]. The reset deadline is end-of-day May 12, 2026. The full 275-million-record trove is still being held back, for now. Here is what changed in the last 36 hours, what it means for 9,000 schools sitting on finals, and where this fits in the 400-company ShinyHunters Salesforce campaign.
The Weekend Reset, Hour by Hour
The compressed timeline matters because Instructure's public statements are now part of the story:
- May 1: Instructure detects the original intrusion. The company later said it became aware of "a cybersecurity incident" the evening of May 1 [7].
- May 3: ShinyHunters lists Instructure on its Tor extortion site claiming 275 million records and 3.65 TB across 9,000 schools. Initial deadline: May 6 [8].
- May 5: TechCrunch confirms it reviewed sample data from two US schools: names, email addresses, phone numbers, teacher-student messages [8]. Wayzata Public Schools in Minnesota becomes the first US K-12 district to formally notify parents.
- May 6: Initial deadline lapses. ShinyHunters extends to May 8. Instructure's status page reports the incident "resolved" and Canvas "fully operational" [1][2].
- May 7, ~3:30 p.m. ET: Canvas goes down at Harvard. By 4:20 p.m. the platform is showing a "scheduled maintenance" message [4]. Within hours, the login pages at multiple universities are redirecting to a black screen with the ShinyHunters ransom note [3][5].
- May 7, evening: Duke's IT Security Office emails all faculty and students confirming Duke is among the affected institutions. Chief information security officer Nick Tripp tells the campus that Instructure has indicated no compromise of passwords, dates of birth, government identifiers, or financial information [9].
- May 8 (today): Instructure's status page still reports 100% uptime for May 7-8 [10]. Canvas, Canvas Beta, and Canvas Test are intermittently unavailable depending on institution [6]. The 275-million-record dataset has not been published.
The New Ransom Note, In Their Own Words
The screen that replaced Canvas login pages on May 7 is unusually candid for a ransom message. Per the text seen by The Harvard Crimson, Inside Higher Ed, TechCrunch, and WRAL, ShinyHunters wrote [4][5][6][11]:
"ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some 'security patches.' You have till the end of the day by 12 May 2026 before everything is leaked."
The note instructed Instructure or affected schools to "consult with a cyber advisory firm" and contact the group "to negotiate a settlement" before May 12. A second line, repeated in the WRAL pickup, accused the company directly: "The Company seemingly does not care about all the students affected" [11].
A ShinyHunters member told TechCrunch the group "couldn't comment on specifics" but confirmed "this is a second, separate breach" [3]. Instructure did not immediately respond to TechCrunch's request for comment. As of the morning of May 8, the company's status page still does not list an active incident for May 7 or May 8 [10].
Why the May 8 Leak Did Not Happen
The most useful thing to know about the leak deadline passing is what it does not mean. It does not mean Instructure paid. It does not mean ShinyHunters lost interest. And it does not mean the data is safe.
Three readings of what happened, in descending order of how flattering they are to Instructure:
- Operational pressure read: Instructure refused to negotiate, applied patches, and pushed Canvas back online. ShinyHunters responded by demonstrating that the patches were inadequate, taking the platform down again at the start of finals, and resetting the clock. The leak is being held back as leverage, not as mercy.
- Theater read: Both sides are running clocks for their own audiences. Instructure needs to look operational so its school district customers don't switch vendors mid-semester. ShinyHunters needs to look unstoppable so its next 50 victims pay faster. A May 8 leak would have ended the leverage; a May 12 redo gives the company another chance to capitulate.
- Negotiation-in-progress read: Some quiet back-channel exists. The original Tor listing has not flipped to "leaked." Instructure has gone unusually silent: no spokesperson, no executive statement, no SEC 8-K acknowledgment of the second breach as of midday May 8. That kind of silence is consistent with a company that has lawyered up and is talking to insurers and counsel, not necessarily one that is paying.
None of those readings is good for the 275 million people whose data is sitting on a ShinyHunters drive.
The Schools Caught in the Middle of Finals
Canvas dominates US higher education: roughly 41% market share, more than 30 million active users, and contracts with most of the country's elite universities [12]. Going dark on May 7-8 hit during the worst possible week. WRAL's reporting confirmed the platform was disabled at:
- UNC Chapel Hill, NC State, NC Central, NC A&T, East Carolina, Wake Forest, Duke, Fayetteville State
- Wake County Public Schools, Durham Public Schools, Orange County Schools, Cumberland County Schools, Johnston County, Franklin County, Wilson County school districts
- Multiple campuses in the University of California system and Sacramento State [13]
- 44 educational institutions in the Netherlands; multiple Australian, UK, New Zealand, and Swedish institutions [13]
The Daily Pennsylvanian confirmed roughly 306,000 Penn users are in scope: students, faculty, and alumni dating back to Canvas's deployment at the university [14]. Harvard University Information Technology spokesperson Tim Bailey told The Crimson the university was "aware that the Canvas platform is currently unavailable due to a cyber incident" and was "actively investigating" [4].
Wake County Public School System's response was the cleanest of any district reporters reached: "Our teachers will do what they do every day, continue delivering exceptional instruction" [11]. Virginia Tech promised additional finals-week guidance via email [11]. The University of Iowa's IT director called the situation "a national-level cyber-security incident" [11].
What Duke's Notification Actually Said
Duke's email, which went out the evening of May 7, is the most useful template for what other universities are about to send their own communities. Per The Duke Chronicle, the IT Security Office confirmed Duke was among the schools affected and laid out exactly what data Instructure has indicated is in the breach scope [9]:
- Names
- Email addresses
- Student ID numbers
- User-to-user messages within Canvas
And what Instructure has said is not in scope:
- Passwords
- Dates of birth
- Government identifiers (SSN, driver's license, passport)
- Financial information
Two cautions. First, "no evidence" is not "no exposure": companies revise the scope of breaches upward, not downward, as forensic work proceeds. PowerSchool's January 2025 breach scope kept growing for weeks. Second, "user-to-user messages" is a much bigger category than the phrase suggests. It includes assignment submissions, discussion-board posts, private one-to-one teacher-student messages, group-project chat threads, and in some cases messages between minor students and adult teachers. That last category is going to attract regulator attention regardless of whether there is government ID exposure.
How This Connects to the 400-Company Salesforce Campaign
This is not a one-off attack on an edtech vendor. ShinyHunters' May 7 leak listing for Instructure explicitly claims access to the company's Salesforce instance, which is consistent with the group's broader campaign throughout 2026: vish a help-desk worker into authorizing a malicious OAuth app, dump customer data out of Salesforce Experience Cloud, demand ransom, repeat.
The same playbook has hit, in roughly the order they were disclosed: TransUnion, Kemper, Ameriprise Financial, Canada Life, Cushman & Wakefield, McGraw-Hill, ADT, Woflow (DoorDash/Walmart/Uber supply chain), Wynn Resorts, and Cushman's neighbor down the office tower at the European Commission. Mandiant's tracker put the affected company count at 300 to 400 organizations by mid-March.
What separates Instructure is scale and demographics. The Crunchyroll, Bumble, Wynn, and Kemper victims are adults. Canvas's user base is, by definition, students, including K-12 minors. That changes the regulatory calculus. FERPA, COPPA where applicable, and state-level student-privacy statutes all kick in. The Department of Education's Student Privacy Policy Office accepts complaints from parents whose districts fail to notify them.
What the Re-Hack Tells Us About Instructure's Response
Two things, both uncomfortable.
First, when Instructure said the incident was "resolved" on May 6, it apparently meant "we patched the original intrusion vector," not "we are confident the attackers are out of our environment." Those are different statements. Real incident response after a successful exfiltration includes assuming persistence, rotating every credential and OAuth token across affected SaaS integrations, and watching for re-entry. The fact that ShinyHunters got back in within 24 hours suggests at minimum that the post-breach hardening was incomplete.
Second, the radio silence from Instructure executives on May 8 is conspicuous. CEO Steve Daly has not addressed customers publicly since the original disclosure. The status page reports 100% uptime for a day on which Canvas was demonstrably down at hundreds of universities [10]. There has been no SEC 8-K filing about the second incident as of late morning Eastern, although the original incident was disclosed in a May 5 8-K. Companies in this posture either have nothing to add or have been told by counsel to add nothing. Either way, the customers running 9,000 schools have to make procurement and notification decisions in an information vacuum.
What Districts and Universities Should Do Today
- Get a written, dated statement from Instructure confirming whether your institution's data was in either exfiltration scope. The first one. The second one. Both. "We are still investigating" two weeks from now is not adequate.
- Rotate Salesforce OAuth tokens for any Canvas-Salesforce integration. ShinyHunters' listing claims access to Instructure's SFDC org. If your institution has a connected app, that token is potentially in the dump.
- Pre-draft your community notification. Duke's email is workable. Wayzata's parent letter is workable. Your state's breach-notification clock has been running since at least May 1. Do not wait for Instructure to formally tell you to send it.
- Plan for finals contingencies. Canvas was down for hours on May 7. It could go down again before May 12. Faculty need a paper-based or alternate-platform fallback for in-progress final exams that depend on Canvas submission.
- Reassess Canvas as a vendor. This is Instructure's second disclosed breach in eight months and the second time in a week the platform has gone dark mid-incident. Procurement officers have a fiduciary basis to ask about alternatives.
What Students and Parents Should Do
- Freeze your child's credit at all three bureaus: Equifax, Experian, TransUnion. Free, takes about an hour, valid until the child lifts it. Do this even if your school has not formally notified you. SSNs are not in this breach per Instructure, but identity-fraud kits combine multiple data sources.
- Treat any "Canvas" email as suspicious through May 12 and beyond. Real Canvas communications come through your school district's portal, not generic
canvas-support@addresses. Phishers with access to actual teacher-student message threads can craft emails that are nearly impossible to flag as fake. - Log into Canvas only through your institution's portal. Not through links in email, not through Google searches, not through saved bookmarks if the platform has been intermittently redirected. Type the URL.
- Document everything. Save your district or university's notification. Save screenshots of any Canvas outage you encounter. If your child is later targeted in a Canvas-themed phishing attack or identity-theft scheme, that documentation is the basis for both insurance claims and any class action recovery.
What to Watch Between Now and May 12
- Whether Instructure publicly acknowledges the second breach. An 8-K filing or executive statement before May 12 would be a meaningful change.
- Whether the Tor listing flips from "deadline" to "leaked." If it flips at any point May 12-13, expect researcher analysis of the dump within 24 hours via Have I Been Pwned, DataBreaches.net, and BleepingComputer.
- Class action filings. Chimicles Schwartz Kriner & Donaldson-Smith and Class Action U opened investigations in the first 72 hours after the original disclosure. The District of Utah, where Instructure is headquartered, is the most likely venue. Expect filings within 30 days regardless of whether the leak materializes.
- State AG action. California, New York, Texas, and Massachusetts AGs typically lead on multistate education-vendor investigations. Utah AG is the home-state regulator and is on the spot.
- Whether other Salesforce-campaign victims start getting re-hacked. If ShinyHunters' "again" tactic on Instructure works as a pressure tool, expect repeat visits to Cushman, Kemper, and others who refused to pay the first time.
The May 8 leak deadline passed without 275 million records hitting the open internet. That is the only piece of good news in this story. The platform that 41% of US college students use to turn in their finals has been hacked twice in a week, the parent company is publicly silent, and the same criminal group that has run this playbook on 400 other companies just demonstrated it can come back at will. May 12 is four days away.
Sources
- Cloudskope: 275 Million Users Exposed. 8,809 Schools Down. Instructure Calls It "Scheduled Maintenance" (May 2026)
- Malwarebytes: Millions of students' personal data stolen in major education cyberattack (May 2026)
- TechCrunch: Hackers deface school login pages after claiming another Instructure hack (May 7, 2026)
- Harvard Crimson: Harvard Canvas Site Goes Down After University Listed in Instructure Breach (May 8, 2026)
- Inside Higher Ed: Hackers Target Canvas, Again (May 7, 2026)
- Wikipedia: 2026 Canvas Security Incident
- SOCRadar: ShinyHunters Breached Instructure: 275 Million Students, Teachers and Staff Potentially Exposed
- TechCrunch: Hackers steal students' data during breach at education tech giant Instructure (May 5, 2026)
- Duke Chronicle: Duke among 9,000 schools affected by Canvas cyberattack (May 7, 2026)
- Instructure Status Page (referenced May 7-8, 2026)
- WRAL: Hacker group disables Canvas for NC students during crucial end-of-school-year stretch (May 7, 2026)
- Men's Journal: Canvas Hacked: ShinyHunters Hackers Shut Down Wildly Popular Platform Used by 41% of U.S. Colleges
- EdScoop: ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
- Daily Pennsylvanian: Over 300,000 Penn users affected in Canvas hack, cybercrime group claims
Published: May 8, 2026