In April 2026, the ShinyHunters extortion group stole data from Instructure, the company behind the Canvas learning management system used by schools and universities around the world. Instructure says the attacker created a Free-for-Teacher account and submitted a support ticket containing malicious code. When a customer service agent opened it on 25 April, a cross-site scripting flaw let the attacker obtain an authorisation token and gain elevated access within Canvas, which was then used to pull data through Canvas's APIs. Instructure says usernames, email addresses, course names, enrolment information and messages were taken, and its FAQ refers to around 8,800 institutions. On 7 May the group got back in through a second flaw, generating a token through the OAuth flow and defacing roughly 300 login pages during end-of-year exams. The Canvas breach shows how one privileged support session, and the tokens it can mint, can open a multi-tenant SaaS platform to a single attacker.
Key takeaways
- According to Instructure, the malicious ticket was submitted on 22 April 2026, executed in a support agent's authenticated session on 25 April, and data was taken through Canvas APIs between 28 and 30 April. Instructure detected the activity on 29 April.
- Entry point: a stored cross-site scripting (XSS) payload in a support ticket, submitted from a self-service Free-for-Teacher account, which gave the attacker an authorisation token with elevated access.
- On 7 May the attacker used a second, unpatched XSS flaw in the Canvas discussion feature and the OAuth flow to generate a new token, sidestepping the first fix, and pushed a ransom note onto login pages.
- ShinyHunters claimed data on 275 million people at nearly 9,000 schools. Instructure's own FAQ frames the incident as access "across 8,800 institutions", but it has not published a count of individuals.
- Instructure announced an "agreement" with the attacker on 11 May, rotated staff sessions and tokens, and shut down Free-for-Teacher.
At a glance
| Organisation | Instructure (Canvas LMS) and the schools, colleges and universities that use Canvas |
|---|---|
| When | Malicious ticket submitted 22 April 2026; access gained 25 April; data exfiltrated 28 to 30 April; detected 29 April; disclosed 1 May; second intrusion 7 May; agreement with attacker announced 11 May |
| Attacker | ShinyHunters, which claimed both intrusions |
| Entry point | Stored XSS in a support ticket raised from a Free-for-Teacher account, triggered when a customer service agent opened it |
| Identities abused | A self-service Free-for-Teacher account; a customer service agent's authenticated session and the authorisation token taken from it; a token generated through the OAuth flow in the second intrusion; Canvas API access |
| Impact | Usernames, email addresses, course names, enrolment information and messages taken, according to Instructure, across about 8,800 institutions; login pages defaced; Canvas taken offline during exams |
| Category | Human identity (support agent session), with tokens and API access as the means of data theft |
What happened
Instructure disclosed the incident on 1 May 2026. Chief Security Officer Steve Proud said the company "recently experienced a cybersecurity incident perpetrated by a criminal threat actor", and BleepingComputer reported that Canvas Data 2 and Canvas Beta were placed in maintenance mode. By 3 May the company had confirmed that names, email addresses, student ID numbers and messages among users were involved, while saying it had no evidence that passwords, dates of birth, government identifiers or financial information were affected. ShinyHunters listed Instructure on its leak site the same weekend.
Instructure later explained the entry point in its incident FAQ: "By creating a Free-for-Teacher account, the threat actor submitted a support ticket containing malicious code. When a customer service agent accessed the ticket, the code triggered a cross-site scripting (XSS) vulnerability, allowing the threat actor to obtain an authorization token and gain elevated access within the Canvas application."
More detail came in a customer webinar on 18 May, summarised by education technology analyst Phil Hill. According to his account, "The April 22 payload sat dormant until April 25, when a customer service representative opened the ticket; the code then executed in the rep's authenticated session and the threat actor used those elevated privileges to obtain data via Canvas's APIs between April 28 and April 30." Instructure detected the activity on 29 April and revoked access by 30 April.
The fix did not hold. On 7 May, students and staff opening Canvas saw a ShinyHunters message instead of their courses. BleepingComputer reported that about 330 institutions had their login portals altered, with a message that began "ShinyHunters has breached Instructure (again)" and set a deadline of 12 May. Instructure took Canvas offline. It later said the attackers "regained access on May 7 using a similar method to exploit a second, unpatched XSS vulnerability in the Canvas discussion feature. This method sidestepped our earlier fix by using the OAuth flow to generate a token instead." Hill's account of the webinar says the flaw was used to push a CSS file through the custom themes feature, showing the ransom note on roughly 300 accounts. Instructure says it has not found evidence that data was taken during the 7 May activity.
On 11 May Instructure said it had reached an agreement with the attacker: "The data was returned to us. We received digital confirmation of data destruction (shred logs). We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise." It has not said whether it paid, and Dark Reading noted the company did not explicitly confirm a payment. Instructure permanently discontinued Free-for-Teacher.
This was not Instructure's first encounter with the group. BleepingComputer reports that in September 2025 a social engineering attack compromised Instructure's Salesforce instance, which ShinyHunters claimed. Dark Reading ties that incident to UNC6040, the cluster behind the wider ShinyHunters Salesforce data theft campaign. In its 2026 extortion note, the group also claimed "Your Salesforce instance was also breached", according to BleepingComputer. Instructure's own account of the 2026 intrusion describes the XSS path, not Salesforce.
Timeline
| Date | Event |
|---|---|
| September 2025 | Separate social engineering compromise of Instructure's Salesforce instance, claimed by ShinyHunters. |
| 22 April 2026 | Attacker submits a support ticket carrying malicious code from a Free-for-Teacher account. |
| 25 April 2026 | A customer service agent opens the ticket; the payload runs in the agent's authenticated session and an authorisation token is obtained. |
| 28 to 30 April 2026 | Data is pulled through Canvas APIs. Instructure detects the activity on 29 April and revokes access by 30 April. |
| 1 May 2026 | Instructure discloses a cybersecurity incident; some services enter maintenance mode. |
| 2 to 3 May 2026 | Instructure confirms the data types involved; ShinyHunters claims the attack and lists the company on its leak site. |
| 7 May 2026 | Second intrusion through an XSS flaw in discussions and an OAuth-generated token; login pages at around 330 institutions show a ransom note; Canvas is taken offline. |
| 11 May 2026 | Instructure announces an agreement with the attacker and receipt of "shred logs". |
| 18 May 2026 | Instructure holds a technical webinar for customers on the attack path. |
How it happened: the identity attack path
- A free, self-service account. A Free-for-Teacher account gave the attacker a legitimate foothold from which to raise a support ticket.
- A payload aimed at a privileged human. The ticket carried stored XSS, which did nothing until a customer service agent opened it on 25 April.
- Session hijack becomes token theft. The script ran inside the agent's authenticated session and let the attacker obtain an authorisation token with elevated access within the Canvas application, according to Instructure.
- APIs as the exfiltration channel. With that token, the attacker pulled data through Canvas's APIs between 28 and 30 April.
- A second way to mint a token. After the first flaw was fixed, a second XSS flaw in discussions let the attacker use the OAuth flow to generate a fresh token on 7 May.
- Tenant-wide changes for extortion. The new access was used to push a CSS file through the custom themes feature, replacing login pages with the ransom note until Canvas was put into maintenance mode.
Impact
- Data: Instructure says the fields involved were usernames, email addresses, course names, enrolment information and messages, and that core learning data such as course content and submissions was not compromised. Its earlier updates also listed student ID numbers.
- Scale: Instructure refers to around 8,800 institutions. ShinyHunters claimed data on 275 million people at nearly 9,000 schools and, according to KrebsOnSecurity, "several billion private messages". BleepingComputer could not confirm the attacker's figures, and Instructure has not published a count of individuals.
- Response: Instructure says it proactively cycled "all employee sessions, internal access tokens, and many partner tokens, even though we had no evidence that these credentials were directly compromised", and deployed CrowdStrike Falcon across its network.
- Scrutiny: House Homeland Security Committee chairman Andrew Garbarino asked Instructure for a briefing by 21 May and wrote that the repeat intrusion raised "serious questions about the company's incident response capabilities", and a Senate committee also wrote to the company, Dark Reading reported.
What this means for identity security
The Canvas breach did not start with a stolen password or a leaked key. It started with a support agent doing their job. Support staff often need to see across customers, so when content an outsider submits can drive their browser session, that session becomes the attacker's identity. Instructure says the attacker obtained "an authorization token", and that token, not the agent's password, carried the data out through the APIs.
That is where human and non-human identity meet. Tokens are how SaaS platforms represent trust between people, internal tools and integrations. The second intrusion made the point again: once the first route was closed, the attacker used the OAuth flow to mint a new token. Instructure's own remediation list reads like a token governance programme: enforced token expiration, "elimination of lifetime tokens", tighter controls on Site Admin and API access, protections around developer keys and service-user access, and restricting third-party integrations by network.
There is also a lesson about fixing the class of flaw, not the instance. Phil Hill argues that the 7 May exploit showed the first fix was insufficient. Once an attacker has turned user content into a privileged token, every way of issuing a token needs review. The same group's earlier campaigns against Salesforce data through stolen OAuth tokens and Snowflake customer accounts followed the same pattern: find one trusted identity with wide reach, then use the platform's own interfaces to take data at scale.
Recommendations
- Treat support consoles as privileged access. Isolate help desk tools from customer-submitted content, render attachments and rich text in sandboxed viewers, and give support staff scoped, time-limited access to a single tenant rather than the whole estate. The Privileged Session Management Guide covers the controls.
- Harden staff-facing web apps against XSS. Apply a strict Content Security Policy to internal and support interfaces and collect its violation reports, so an injected script is blocked or at least noticed.
- Bind and shorten tokens. Remove lifetime tokens, set short expiry on session and API tokens, bind them to device or network where possible, and alert when a staff token is used from an unexpected location or for bulk API reads.
- Govern OAuth issuance and integrations. Inventory which apps and users can mint tokens, restrict scopes, and review integrations regularly, as set out in the SaaS OAuth App Governance Guide.
- For Canvas customers, rotate and review. Instructure says broad rotation is not required, but institutions and partners may proactively cycle API keys and reauthorise integrations, including LTI tools. The API Key Management Guide explains how to do this without breaking services.
- Detect abnormal data access, not just logins. Monitor bulk API reads by privileged accounts across tenants, and prepare users for targeted phishing using the stolen data.
Frequently asked questions
What happened in the Canvas Instructure breach?
In April 2026 ShinyHunters used a malicious support ticket, raised from a Free-for-Teacher account, to exploit a cross-site scripting flaw when a support agent opened it. The attacker obtained an authorisation token with elevated access and took usernames, email addresses, course and enrolment information and messages through Canvas APIs. A second intrusion on 7 May forced Canvas offline.
How did ShinyHunters get into Canvas the second time?
Instructure says the attacker exploited a second, unpatched XSS flaw in the Canvas discussion feature and used the OAuth flow to generate a token, which sidestepped the fix for the first flaw.
Was my school affected by the Canvas breach, and were passwords stolen?
Instructure's FAQ refers to around 8,800 institutions, and the company began delivering affected data to institutions in July 2026. It says it has no evidence that passwords, dates of birth, government identifiers or financial information were involved, so check with your school for its specific notice.
Related NHI Mgmt Group resources
ShinyHunters Salesforce data theft campaign · Salesloft Drift OAuth token breach · Snowflake breach · CitrixBleed session token theft · Identity Provider and SSO Security Guide
How NHI Mgmt Group can help
The Canvas breach turned one support session into tokens and API access that reached thousands of institutions, the kind of non-human access most organisations cannot fully see. Our NHI Foundation Level Training Course helps teams inventory, scope and govern tokens, API keys and integrations alongside the people who use them.
References
- Instructure: For Customers, Security Incident Update and FAQs (27 July 2026)
- Instructure: Security Incident Update and FAQs (8 May 2026, updated 21 July 2026)
- On EdTech (Phil Hill): A Technical Deep Dive Is Not a Crisis Response (19 May 2026)
- BleepingComputer: Edu tech firm Instructure discloses cyber incident, probes impact (1 May 2026)
- BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack (3 May 2026)
- BleepingComputer: Canvas login portals hacked in mass ShinyHunters extortion campaign (7 May 2026)
- KrebsOnSecurity: Canvas Breach Disrupts Schools & Colleges Nationwide (7 May 2026)
- Dark Reading: Congress Puts Heat on Instructure After Canvas Outage (15 May 2026)