An empty lecture hall with rows of seats facing a whiteboard.
Photo via Unsplash

TL;DR: ShinyHunters' ransom deadline for 275 million student records expires end-of-day Monday, May 12. Instructure has not paid. The company has not publicly negotiated. The FBI and CISA were notified on May 1, but neither agency has announced enforcement action [1][2]. On the other side, ShinyHunters has already hacked Instructure twice, demonstrated it can bypass the company's patches, and told Penn's student newspaper that the company "has not even bothered speaking to us" [3]. Three things will happen Monday or shortly after: the data leaks, the deadline extends again, or someone quietly pays. None of those outcomes make 275 million stolen records un-stolen. Here is what is actually at risk, what happens in each scenario, and what you should do before Monday.

The Clock: What Led to May 12

This story has moved fast enough that most people catching up have missed at least one escalation. Here is the compressed version:

  • April 29: Instructure detects unauthorized activity in Canvas and revokes attacker access the same day [1].
  • May 1: Instructure issues its first public statement. External forensics firm engaged. FBI and CISA notified [1][2].
  • May 3: ShinyHunters lists Instructure on its Tor extortion site (275 million records, 3.65 TB, 8,809 schools). Deadline: May 6 [4].
  • May 5: TechCrunch confirms it reviewed sample data from two US schools: names, emails, phone numbers, teacher-student messages [5]. Wayzata Public Schools in Minnesota becomes the first US K-12 district to formally notify parents.
  • May 6: Instructure declares the incident "resolved" and Canvas "fully operational." Deadline passes. ShinyHunters extends to May 8 [6].
  • May 7, ~3:30 p.m. ET: ShinyHunters breaks back into Canvas (through an exploited Free-For-Teacher account) and redirects login pages at Harvard, Penn, Duke, Wisconsin, Oklahoma, and dozens of other schools to a black screen with a new ransom note [3][7][8]. New deadline: end-of-day May 12.
  • May 8: Canvas comes back online. Instructure's status page reports 100% uptime for a day the platform was demonstrably down at hundreds of institutions [9]. CEO Steve Daly has still not addressed customers publicly.
  • May 9 (today): The data has not leaked. It has not been confirmed safe. The deadline is 72 hours away.

What Data Is Actually at Risk

Instructure's CISO Steve Proud has said the breach includes names, email addresses, student ID numbers, and messages exchanged between users [1][10]. The company says passwords, dates of birth, government IDs, and financial information are not in the stolen dataset.

That sounds manageable until you think about what "messages exchanged between users" actually means inside a learning management system used by 30 million people. It means:

  • Private one-on-one messages between students and teachers
  • Assignment submissions and feedback
  • Discussion-board posts, including ones in health, counseling, and disability-accommodation courses
  • Group-project chat threads
  • Messages between minor K-12 students and adult faculty

That last category is why privacy regulators will care about this breach regardless of whether Social Security numbers are involved. A dump of private messages between minors and adults, searchable by name and school, is a nightmare for school districts that already face scrutiny over student-teacher communications.

And here is the part companies always bury: "no evidence" is not "no exposure." Breach scopes get revised upward. PowerSchool's January 2025 breach kept growing for weeks. ShinyHunters claims to have "billions of private messages with personal information" [11]. Instructure disputes this. But Instructure also said the incident was "resolved" 24 hours before getting hacked again.

What Happens Monday: Three Scenarios

The May 12 deadline is the third one ShinyHunters has set. The original was May 6. Then May 8. Now May 12. Each extension has come with an escalation: first the Tor listing, then the defacement of login pages at elite universities during finals. Here is what happens in each scenario:

Scenario 1: The Data Leaks

ShinyHunters publishes the dataset on its Tor site or a public file-sharing service. Within hours, security researchers download samples. Within 24 hours, Have I Been Pwned indexes the records. Within a week, the data is being sold in parsed form, sorted by school, by state, by age group.

For schools, this triggers state breach-notification clocks. Most states give institutions 30 to 60 days from discovery. But discovery, for many districts, arguably started May 3 when ShinyHunters posted the claim. Schools that have not yet notified parents may already be behind [12].

For students and parents, a leak means your name, email, student ID, and years of Canvas messages are now searchable by anyone. The phishing campaigns will start within days, and they will be unusually convincing because the attackers will have real teacher names, real course names, and real message threads to reference.

Scenario 2: The Deadline Extends Again

ShinyHunters pushes the deadline to May 15, May 19, or whenever. This is the most likely outcome based on the pattern so far. The group is not in a hurry. The data has value as a bargaining chip, not just as a dump. Every day the deadline extends, Instructure faces more pressure from school districts demanding answers, more law firms opening investigations, and more parents calling their state attorney general.

An extension is not relief. It is prolonged uncertainty for institutions that already have litigation holds, vendor-review deadlines, and parents demanding answers.

Scenario 3: Someone Pays

Instructure (or more likely, its cyber-insurance carrier) negotiates a payment in exchange for data deletion. The Tor listing quietly disappears. The company issues a statement about "taking all necessary steps to protect our customers."

This has precedent. Medtronic's listing on the ShinyHunters leak site disappeared this week, strongly suggesting ransom was paid, though the company has not confirmed it [13]. Penn refused a $1 million ShinyHunters ransom demand in February and watched additional data get published [3].

But paying does not delete the data. It buys a promise from criminals that they will delete it. ShinyHunters has re-hacked Instructure once already. There is no reason to believe a payment would prevent a third visit.

The Legal Mess That Is Already Here

Forget Monday. The legal consequences are already in motion.

Class action investigations: Bryson Harris Suciu & DeMay, ClassAction.org, and at least two other firms have opened investigations into Instructure [11]. No federal class action has been filed yet, but the District of Utah (where Instructure is headquartered) is the most likely venue. Expect filings within 30 days regardless of whether the data leaks.

FERPA: Schools, not Instructure, hold the FERPA obligation to protect student education records. Instructure operates as a "school official" under FERPA's exception that lets vendors process student data [12]. When the vendor gets hacked, the school is still on the hook for notification and remediation. Districts that have not yet contacted affected families are running a legal risk that grows every day.

COPPA: The FTC's updated COPPA rule took effect April 22, 2026, one week before ShinyHunters broke in [12]. It tightens consent and breach-notification requirements for data on children under 13 and carries penalties up to $51,744 per affected child. K-12 districts with elementary-age Canvas users should be talking to counsel right now.

State student-privacy laws: Over 100 state-level statutes impose vendor-specific notification duties with varying timelines. New York Education Law 2-d, California's SOPIPA, Illinois' SOPPA, and their equivalents across 40+ states all apply. Schools in those states cannot wait for Instructure to tell them what to do [12].

GDPR: The 72-hour supervisory notification window applies to European institutions: Oxford, Cambridge, the 44 Dutch schools, Swedish and UK universities in the breach scope. Some of those clocks have arguably already expired [12].

Why Instructure's Silence Is the Story

CEO Steve Daly has not made a public statement. The company's status page reported 100% uptime on a day Canvas was down at hundreds of schools. There has been no SEC 8-K filing about the second breach as of May 9, although the original incident was disclosed in a May 5 8-K [9].

ShinyHunters told the Daily Pennsylvanian that Instructure "has not even bothered speaking to us to understand the situation or to even negotiate with us to prevent the release of this data" [3]. Whether that is true or a pressure tactic, the company's public posture has been indistinguishable from a company that is pretending this is over.

It is not over. Canvas commands 41% of the US higher-education market [14]. Over 30 million people use it. The platform has now been hacked twice in eight days by the same group that has hit 300 to 400 other companies through the same Salesforce vishing playbook this year [15]. School districts making procurement decisions for the 2026-2027 academic year are watching.

What Students and Parents Should Do Before Monday

  • Freeze your child's credit at all three bureaus. Equifax, Experian, TransUnion. Free, takes about an hour, valid until the child lifts it. Do this even if your school has not formally notified you. Student IDs and email addresses are enough to fuel identity-fraud kits when combined with other data sources.
  • Treat any "Canvas" email as a phishing attempt through May and beyond. Real Canvas communications come through your school's portal, not from generic canvas-support@ addresses. Attackers with access to actual teacher names and course rosters can craft emails that are nearly impossible to distinguish from legitimate ones.
  • Log into Canvas only through your institution's official portal. Not through email links. Not through Google searches. Not through saved bookmarks. Type the URL. ShinyHunters has already redirected login pages once.
  • Change any password you have ever reused with your Canvas email. Canvas passwords are reportedly not in the breach, but your email address is. If you used the same email and password combination anywhere else, credential-stuffing bots will find it.
  • Document everything. Save your school's notification (or screenshot the absence of one). Save any Canvas outage you encounter. If your child is later targeted by a Canvas-themed phishing attack, that documentation is the basis for both insurance claims and class action recovery.
  • File a complaint with the Department of Education. The Student Privacy Policy Office accepts complaints from parents whose districts fail to provide timely breach notification. The form is on studentprivacy.ed.gov.

What Schools Should Do Before Monday

  • Get a written, dated statement from Instructure confirming whether your institution's data was in either exfiltration: the April 29 breach or the May 7 re-compromise. "We are still investigating" is not adequate with a leak deadline 72 hours away.
  • Pre-draft your community notification. Duke's May 7 email and Wayzata's parent letter are both workable templates [8]. Your state's breach-notification clock may have been running since May 3. Do not wait for Instructure to tell you to send it.
  • Rotate Salesforce OAuth tokens for any Canvas-Salesforce integration. ShinyHunters' listing claims Salesforce instance access. If your institution has a connected app, that token is potentially in the stolen data.
  • Plan finals contingencies. Canvas went down for hours on May 7. It could happen again Monday. Faculty need a paper-based or alternate-platform fallback for any exam that depends on Canvas submission.
  • Talk to your cyber-insurance carrier. If your institution received a direct ransom demand (and some have) that is a covered event under most cyber policies. Your carrier's breach-response panel can advise on notification, forensics, and legal exposure.

What to Watch on Monday and After

  1. Whether the Tor listing flips from "deadline" to "leaked." If it does, expect researcher analysis within 24 hours via Have I Been Pwned, DataBreaches.net, and BleepingComputer.
  2. Whether Instructure breaks its silence. An 8-K filing, a CEO statement, or a formal customer advisory before May 12 would be a meaningful change in posture. The absence of one is its own signal.
  3. Class action filings. The District of Utah is the most likely venue. Multiple firms are past the investigation stage and waiting for the right moment to file.
  4. State AG action. California, New York, Texas, and Massachusetts attorneys general typically lead on multistate education-vendor investigations. The updated COPPA rule gives the FTC additional standing for K-12 exposure.
  5. Whether ShinyHunters re-hacks Instructure a third time. The group demonstrated on May 7 that it can bypass the company's patches. If the deadline passes without payment, another defacement or outage is the most obvious pressure tool.

Monday is not the end of this story. It is the point where a ransom standoff becomes a data-breach reality, or stretches into another week of uncertainty for 275 million people whose names, emails, and private messages are sitting on a criminal group's servers. The students taking finals this week did not choose Canvas. Their schools chose it for them. Those schools owe them an answer before the deadline hits.

Sources

  1. ComplexDiscovery: Canvas breach moves from disclosure to demand as ShinyHunters sets May 12 deadline (May 2026)
  2. Fisher Phillips: The Canvas Breach: What Educational Institutions Need to Know (May 2026)
  3. Daily Pennsylvanian: Cybercrime group crashes Penn's Canvas system, demands ransom (May 2026)
  4. SOCRadar: ShinyHunters Breached Instructure: 275 Million Students, Teachers and Staff Potentially Exposed
  5. TechCrunch: Hackers steal students' data during breach at education tech giant Instructure (May 5, 2026)
  6. Malwarebytes: Millions of students' personal data stolen in major education cyberattack (May 2026)
  7. TechCrunch: Hackers deface school login pages after claiming another Instructure hack (May 7, 2026)
  8. Duke Chronicle: Duke among 9,000 schools affected by Canvas cyberattack (May 7, 2026)
  9. Instructure Status Page (referenced May 7-9, 2026)
  10. Wikipedia: 2026 Canvas Security Incident
  11. ClassAction.org: Instructure Data Breach Confirmed, Attorneys Investigating (May 2026)
  12. McLane Middleton: Canvas/Instructure Data Breach Action Items for Schools (May 2026)
  13. GBlock: Instructure Canvas Breach: Second Hit in 8 Months Exposes Student Data (May 2026)
  14. Men's Journal: Canvas Hacked: ShinyHunters Shut Down Platform Used by 41% of U.S. Colleges
  15. State of Surveillance: ShinyHunters Weaponized a Security Tool to Breach 400 Companies via Salesforce