TL;DR: Instructure confirmed on May 11 that it reached a settlement with ShinyHunters and received "digital confirmation of data destruction (shred logs)" [1]. The company said the agreement "covers all impacted Instructure customers" and that no schools will face individual extortion [1][2]. CEO Steve Daly broke his silence to apologize for the company's communication failures, saying "we got the balance wrong" [1]. The ransom amount is undisclosed. The Register confirmed Instructure also acknowledged two separate unauthorized intrusions (in April and again in May) both exploiting its Free-for-Teacher system [3]. CrowdStrike was hired for forensics. The FBI and CISA were notified. And the entire resolution rests on digital shred logs provided by the same criminal group that hacked Instructure twice, defaced 330 school login pages, and stole billions of private messages between students and teachers.
What Instructure Actually Said
On May 11, one day before ShinyHunters' third and final deadline, Instructure issued a statement confirming three things it had refused to say for ten days [1][2]:
- It reached "an agreement" with ShinyHunters.
- It received "digital confirmation of data destruction (shred logs)."
- "No Instructure customers will be extorted as a result of this incident, publicly or otherwise."
Translation: they paid. Instructure will not confirm the amount, but the company went from "the incident is resolved" on May 6 to "we reached an agreement" on May 11 after ShinyHunters broke back in, defaced login portals at Harvard, Penn, Columbia, and hundreds of other schools during finals week, and set a public deadline that threatened to dump 3.65 terabytes of student data [3][4].
CEO Steve Daly also issued an apology, his first public statement since the breach began on April 29: "We got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates" [1].
That is a polite way of saying the company's status page showed 100% uptime on a day Canvas was down at hundreds of institutions, its CEO said nothing for 12 days, and it took getting hacked a second time to produce a public acknowledgment that the first hack was serious.
The Double Breach Is Now Confirmed
The Register reported on May 12 that Instructure formally acknowledged two separate unauthorized intrusions [3]:
- Breach 1 (April 29): ShinyHunters exploited a vulnerability in the Free-for-Teacher (FFT) system, a free signup program that lets teachers create Canvas accounts without institutional verification. The attackers exfiltrated data before Instructure detected the activity and revoked access the same day.
- Breach 2 (May 7): ShinyHunters exploited the same FFT system again, using a different entry point. This time they defaced login pages at roughly 330 institutions, replacing them with a ransom note [3][5].
After the second breach, Instructure permanently shut down the Free-for-Teacher program, revoked credentials and access tokens, rotated internal keys, and brought in CrowdStrike for forensic analysis [3].
The stolen data includes usernames, email addresses, course names, enrollment information, and messages, but Instructure says "core learning data (course content, submissions, credentials) was not compromised" [3]. ShinyHunters claims the haul includes "several billions of private messages among students and teachers" [1][4].
Why "Shred Logs" Do Not Mean What Instructure Wants You to Think
Instructure is leaning hard on those shred logs. Here is the problem: a shred log is a text file that says data was deleted. It is generated by the person doing the deleting. In this case, that person is a member of ShinyHunters, the same group that:
- Hacked Instructure twice through the same system
- Defaced 330 school login pages during finals week
- Told Penn's student newspaper that Instructure "has not even bothered speaking to us" before the settlement [5]
- Published 50GB of Cushman & Wakefield data after that company refused to pay [6]
- Removed Medtronic from its leak site this month, suggesting a ransom was paid for 9 million stolen medical records [7]
There is no independent verification that ShinyHunters deleted every copy. There is no forensic chain of custody. There is no third-party audit. There is a text file from a criminal organization that says "trust us, it's gone."
This is not hypothetical skepticism. ShinyHunters has re-sold data from previous breaches. The group's entire business model is built on having something other people want. A shred log is a receipt, not a guarantee.
The Ransom Math
Instructure will not say how much it paid. ShinyHunters told Inside Higher Ed that the initial demand "was not even as high as you might think" [1]. For context:
- ShinyHunters demanded $1 million from the University of Pennsylvania in February. Penn refused. Additional data was published [5].
- Medtronic's breach (9 million medical records) likely involved a ransom payment this month after the company's listing disappeared from ShinyHunters' leak site [7].
- Instructure's annual revenue is approximately $570 million [8]. Its breach affected 8,800+ institutions and 275 million user records. The scale alone makes this one of the largest education-sector ransoms ever negotiated.
Whatever Instructure paid, it paid with someone else's money. Most publicly traded companies carry cyber insurance with ransomware riders. The premium increase hits next renewal cycle. The cost gets passed to the schools. The schools pass it to students.
What This Means for 275 Million People
If you are a Canvas user (student, teacher, administrator) here is what the settlement changes and does not change:
What changed:
- ShinyHunters has committed not to publish or sell the stolen data. The Instructure listing has been removed from their leak site.
- Individual schools will not receive direct extortion demands.
- Canvas is operational and Instructure says it is safe to use.
What did not change:
- Your data was stolen. Names, emails, student IDs, and private messages were exfiltrated. That happened. The settlement does not un-steal it.
- There is no independent confirmation the data was actually deleted. You are trusting ShinyHunters' word.
- ShinyHunters may have copied the data before "destroying" it. The group operates across multiple members and infrastructure nodes. A shred log from one server does not account for copies on others.
- The phishing risk remains. Attackers who had access to real teacher names, course rosters, and message threads can craft targeted phishing campaigns whether or not the bulk dataset is published.
- The class action investigations are still open. At least four law firms (including ClassAction.org) have active investigations [9]. The settlement with ShinyHunters does not resolve Instructure's civil liability to affected users.
What You Should Still Do
- Freeze your credit (or your child's) at Equifax, Experian, and TransUnion. Free, takes an hour. Student IDs and email addresses are enough fuel for identity fraud when combined with other leaked datasets.
- Change any password shared with your Canvas email. Canvas passwords reportedly were not in the breach, but your email address was. Credential-stuffing bots will try it everywhere.
- Treat any "Canvas" email as suspicious through the rest of 2026. Even if the bulk data stays off the dark web, fragments from the breach will circulate in criminal markets. Phishing campaigns referencing real course names and teacher names are coming.
- Ask your school what they are doing. Schools hold the FERPA obligation, not Instructure. Your institution should have sent (or be preparing) a formal breach notification with specifics about your data exposure. If they have not, file a complaint with the Department of Education's Student Privacy Policy Office at studentprivacy.ed.gov.
The Precedent Problem
Instructure just taught every ransomware group on the planet that hacking an education platform is a payday. The playbook is now documented:
- Find a vendor that sits upstream of thousands of institutions.
- Exploit a free-tier signup system with no institutional verification.
- Steal everything. Set a deadline.
- When they patch and declare victory, break in again through the same system.
- Deface login pages at Harvard and Penn during finals week for maximum media pressure.
- Collect payment. Provide a shred log. Move on.
ShinyHunters has hit over 400 companies this year through its Salesforce-based campaign [10]. It has now demonstrated that education is a soft target with a guaranteed payer. Doug Thompson from Tanium called it "a clear pattern we've been watching for the last 18 months: attackers are moving up the data supply chain to the platforms that sit underneath thousands of institutions at once" [4].
The FBI's official guidance is not to pay ransoms. The reasoning is simple: payment funds the next attack. Instructure paid anyway. Now every LMS, SIS, and ed-tech platform is wondering if they are next, and every ransomware crew knows the answer is yes.
What Happens Next
- Class action lawsuits: Multiple firms are past the investigation stage. Expect filings in the District of Utah, Instructure's home jurisdiction, within weeks [9].
- State AG investigations: California, New York, and Texas attorneys general have standing under student-privacy and breach-notification laws. The updated COPPA rule (effective April 22, 2026) gives the FTC additional authority for K-12 data involving children under 13 [11].
- FERPA and COPPA enforcement: Schools, not Instructure, bear the FERPA obligation. Districts that have not yet notified parents are accumulating legal exposure daily.
- Procurement fallout: Canvas holds 41% of the US higher-education LMS market [8]. Schools making vendor decisions for the 2026-2027 academic year now have to explain to boards, parents, and faculty senates why they are sticking with a platform that got hacked twice in eight days and resolved it by paying criminals.
- The data resurfaces: The most likely long-term outcome. Shred logs or not, stolen data has a way of reappearing: sold in fragments, leaked by a disgruntled member, or used in targeted operations. The settlement buys time. It does not buy safety.
Instructure's breach started on April 29. It took 12 days, two hacks, 330 defaced login pages, an FBI notification, a CrowdStrike engagement, and a ransom payment to get a CEO to say "we got the balance wrong." For 275 million people whose private messages, student IDs, and email addresses were stolen from a platform they did not choose, "the balance" was never theirs to lose.
Sources
- Inside Higher Ed: Instructure Pays Ransom to Canvas Hackers (May 11, 2026)
- Wikipedia: 2026 Canvas Security Incident
- The Register: Double Canvas breach acknowledged as ShinyHunters sets new deadline (May 12, 2026)
- Computing UK: Cyberattack on Canvas disrupts exams at universities worldwide (May 2026)
- Daily Pennsylvanian: Cybercrime group crashes Penn's Canvas system, demands ransom (May 2026)
- CyberNews: ShinyHunters posts 50GB Cushman & Wakefield dataset (May 2026)
- State of Surveillance: Medtronic Data Breach: ShinyHunters Claims 9 Million Records
- Men's Journal: Canvas Hacked: ShinyHunters Shut Down Platform Used by 41% of U.S. Colleges
- ClassAction.org: Instructure Data Breach Confirmed, Attorneys Investigating (May 2026)
- State of Surveillance: ShinyHunters Weaponized a Security Tool to Breach 400 Companies via Salesforce
- McLane Middleton: Canvas/Instructure Data Breach Action Items for Schools (May 2026)
Published: May 12, 2026