A diverse group of students collaborating around a laptop in a classroom
Photo via Unsplash

Today in Surveillance:

  • Canvas LMS breach: 275 million users. ShinyHunters added Instructure to its leak site Sunday, claiming 3.65 terabytes stolen from roughly 9,000 schools worldwide. Names, emails, student IDs, and private messages.
  • Meta v. New Mexico Phase 2 opens today. Judge Bryan Biedscheid hears three weeks of arguments on whether Facebook and Instagram constitute a public nuisance. Meta has threatened to leave the state rather than fix the algorithm.
  • Pentagon's seven AI replacements get classified network access. The companies that took Anthropic's place after the February ban are now hooked into DoD classified systems. None published acceptable use limits on military surveillance.
  • EU CSAR trilogue #4 today. Parliament vs. Council on whether your encrypted messages get scanned. The fight that decides whether end-to-end encryption survives in Europe.
  • Utah's VPN law goes live Wednesday. First state to make websites liable for users who hide behind VPNs. NordVPN calls it an "unresolvable compliance paradox."

ShinyHunters Hit Canvas. 275 Million Students, Teachers, and Staff Are in the Bag.

Instructure, the company behind Canvas, the learning management system used by roughly 9,000 schools and universities, confirmed a breach over the weekend. On May 3, ShinyHunters added Instructure to its Tor leak site and claimed 3.65 terabytes of stolen data covering 275 million users [1]. We broke down the full scope in our Canvas LMS breach report.

Instructure first noticed something wrong on April 30, when tools relying on API keys started breaking. By May 1 the company's CISO went public: a criminal threat actor had broken in. By May 2 Instructure said the stolen data includes names, email addresses, student ID numbers, and messages between users. The company says no passwords, dates of birth, government identifiers, or financial information were taken. ShinyHunters also claims the company's Salesforce instance was compromised, the same playbook the group used against Crunchyroll, Bumble, Wynn, and the rest of the 2025-2026 Salesforce vishing campaign [2].

This is Instructure's second breach in less than a year. The first one was disclosed in summer 2025. The same Salesforce-adjacent attack chain keeps working, and the same 9,000 schools keep being on the receiving end of it. Canvas is where students submit assignments, where teachers post grades, where messages flow between minors and faculty. "No financial information" is cold comfort when the alternative is a list of every kid in your district's email and student ID.

Affected institutions should already be telling parents. Most haven't. Watch for class actions in the next 60 days. The legal template from the Infinite Campus suit applies cleanly here.

Meta Phase 2 Opens Today: Judge Decides Whether Instagram Is a "Public Nuisance"

Phase 2 of State of New Mexico v. Meta opened this morning before Judge Bryan Biedscheid in Santa Fe. No jury this time: the judge alone decides whether Facebook, Instagram, and WhatsApp constitute a public nuisance under New Mexico law, and what to do about it [3].

Phase 1, decided in March, hit Meta with $375 million for 75,000 violations of the state's consumer protection law. That's already the first jury verdict against a major US tech company for endangering children. Phase 2 is where it gets dangerous for Meta. Attorney General Raúl Torrez is asking for a $3.7 billion abatement fund, a ban on under-13 accounts, mandatory guardian accounts for minors, age verification, mandatory algorithm redesigns to kill infinite scroll and autoplay for minors, and a court-appointed safety monitor for at least five years [4].

Meta's filed response, made public last week: the state's demands are "technically impractical, impossible for any company to meet," and "if a workable solution to Attorney General Torrez's demands is not reached, we may have no choice but to remove access to its platforms for users in New Mexico entirely" [5].

Torrez called it a PR stunt and pointed out that Meta has built custom platform versions for authoritarian governments when the money was right. The trial is expected to run three weeks. A ruling could take longer. Whatever Biedscheid decides becomes the template every other state AG copies.

Background: Meta Would Rather Quit New Mexico Than Stop Harming Kids

Pentagon Wires Seven AI Companies Into Classified Networks

The Pentagon spent April quietly giving classified-network access to the seven AI companies it lined up after banning Anthropic in February. Most of those deals were announced May 1, and the details that have surfaced since are worse than the topline made it sound [6].

Recap: Anthropic refused to remove restrictions on mass domestic surveillance and autonomous weapons from its acceptable use policy. Trump signed an order on February 27 cutting all federal ties. The Pentagon labeled Anthropic a "supply chain risk." A federal judge in California called that designation "Orwellian" and tried to block it. The DC appeals court let the ban stand pending litigation. So Anthropic's out, except the NSA is still using Mythos Preview, Anthropic's most capable cyber model, because the DoD CTO calls Mythos a "separate national security moment" [7].

The seven replacement companies (names not yet fully public) get the contracts Anthropic refused. None of them have published acceptable use policies barring military surveillance applications or autonomous targeting. They had no reason to publish them. They got the contract because they didn't have them. We covered the full Mythos paradox here.

EU CSAR Trilogue #4 Today: Encryption's Defining Round

The fourth trilogue meeting between Parliament, Council, and Commission on the Child Sexual Abuse Regulation runs today in Brussels. This is the round that sets the negotiating boundaries before the (likely) final session on June 29 [8].

The positions: Parliament passed its line in March, no scanning of end-to-end encrypted communications, period. Council wants a "voluntary" scanning framework that escalates into mandatory detection orders. The Commission is brokering between them. The voluntary derogation that allowed scanning under the old rules expired April 3 [9].

If Council prevails, client-side scanning becomes EU law by fall. If Parliament holds, encrypted messaging in Europe survives this round. We'll publish an outcome piece tonight or tomorrow as details emerge. Leaks usually come within 48 hours of these meetings.

Related: Full Preview: What's at Stake in the CSAR Trilogue | Chat Control Is Dead. Long Live Chat Control.

Utah's VPN Law Hits Wednesday: First State to Hold Sites Liable for Tunneled Users

Senate Bill 73, the "Online Age Verification Amendments," takes effect May 6. Utah becomes the first US state to make websites legally responsible for users who try to bypass age-verification gates with VPNs, proxies, or any other geographic-masking tool [10].

The law's mechanic: if you are physically located in Utah, you count as a Utah user, regardless of what your IP address says. Websites can't hide behind "we thought they were in Belgium." On top of that, sites covered by the age-gate rules are forbidden from explaining how to use a VPN to get around the rules, a content restriction that EFF calls a clear First Amendment problem [11].

NordVPN's response was blunt: the law is a "liability trap" and an "unresolvable compliance paradox." It tells websites to identify users whose tools are designed specifically to make identification impossible. Within hours of the law going live, motivated users will move to private cloud tunnels, residential proxies, and self-hosted endpoints that look exactly like normal home traffic. The collateral damage falls on commercial VPN customers (journalists, abuse survivors, business travelers) who use these tools for actual security [12].

FISA 702: Recess Continues, Clock Ticks Toward June 12

It's been four days since the 45-day extension passed. Both chambers are still on recess. No reform talks scheduled. The new deadline is June 12 [13].

The doomed three-year reauthorization the House passed last week included real reforms: warrant requirements for FBI queries of Americans' data, Office of the Director of National Intelligence written justifications for each query, and criminal penalties up to five years for intentional misuse. The Senate killed it because Republican hardliners attached an unrelated CBDC ban as a poison pill [14].

That fight resumes mid-May when Congress returns. The Freedom Caucus still wants warrants. The intelligence community still says warrants would "cripple" the program. The FISA Court still found ongoing compliance failures in March. The pattern keeps repeating: deadline, extension, no reform, your data stays in the database.

Deep dive: Why FISA 702 Reform Keeps Dying: Three Deadlines, Three Failures

Quick Hits

  • DHS Inspector General launches biometric audit. Joseph Cuffari opened a formal probe into how DHS, ICE, and CBP collect and share biometric data and personally identifiable information for immigration enforcement. Senators Warner and Kaine pushed for the investigation in January. The audit will look at PenLink's $2.3M Webloc location-tracking contract, ICE's location data buying, and the post-2021 absence of a department-wide commercial location data policy [15].
  • BlackCat sentencings. The DOJ sentenced two US cybersecurity professionals to four years each on May 1 for deploying BlackCat ransomware against multiple US victims between April and December 2023. The defendants (Ryan Goldberg and Kevin Martin) were practicing infosec professionals when they pivoted to extortion [16].
  • cPanel zero-day exploited. Researchers detected May 2 attacks against government and military domains in the Philippines and Laos, plus MSPs and hosting providers, using public proof-of-concept code for CVE-2026-41940. The vulnerability allows authentication bypass on cPanel and WHM. If you run cPanel and you haven't patched, do it today [17].
  • California escalates data broker enforcement. CalPrivacy's January-April 2026 enforcement push has hit Datamasters ($45,000), ROR Partners ($56,600), and two more brokers ($42,000 and $34,400) for failing to register or selling health-condition lists for ad targeting. The August 1 deadline for brokers to honor Delete Act requests via the central platform is pushing more enforcement out the door [18].

What to Watch

  • Tonight or tomorrow, CSAR trilogue outcome. Expect leaks within 48 hours. We'll publish as soon as the negotiating positions are clear.
  • Wednesday, May 6, Utah VPN law live. Watch for the first compliance failures and the first sites that just block Utah entirely rather than try.
  • Mid-May, Congress returns from recess. FISA 702 reform back on the table. Probably dies again.
  • Through May, Meta Phase 2 trial. Three weeks of testimony on what Meta knew, when, and what it should be forced to fix. Ruling likely in summer.
  • June 12, FISA 702 expires (again). The third deadline in three months.
  • June 29, CSAR trilogue #5. Backup if today doesn't produce a deal. Last round before EU summer recess.

Sources

  1. BleepingComputer. Instructure confirms data breach, ShinyHunters claims attack
  2. DataBreaches.net. Instructure discloses second data breach in less than a year
  3. Boston Globe. New Mexico seeks child safety restrictions on Meta apps and algorithms in trial's second phase
  4. NM DOJ. Statement from AG Raúl Torrez on Meta's Refusal to Protect Children
  5. The Next Web. Meta would rather leave New Mexico than rebuild its apps for kids
  6. CNN. Pentagon strikes deals with 7 Big Tech companies after shunning Anthropic
  7. CNBC. Pentagon tech chief says Anthropic is still blacklisted, Mythos is a separate issue
  8. European Parliament. Legislative Train: Combating child sexual abuse online
  9. EDRi. CSA Regulation Document Pool
  10. EFF. Utah's New Law Targeting VPNs Goes Into Effect Next Week
  11. Tom's Hardware. Utah first state to hold websites liable for VPN-tunneled users
  12. TechRadar. NordVPN slams Utah age verification law as a 'liability trap'
  13. Security Boulevard. Congress Punts FISA Section 702 Renewal to June
  14. NPR. Congress extends FISA 702 surveillance program for 45 days
  15. 404 Media. Inspector General Investigating Whether ICE's Surveillance Tech Breaks the Law
  16. SecurityWeek. Two US Cybersecurity Pros Sentenced Over Ransomware Attacks
  17. The Hacker News. cPanel CVE-2026-41940 exploitation in Southeast Asia
  18. Frankfurt Kurnit. CalPrivacy Escalates Data Broker Enforcement Into Health Data