Instructure confirms hackers used Canvas flaw to deface portals

Instructure says hackers used Canvas flaw for extortion message on login portals

Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message.

BleepingComputer has learned that both the breach and defacements involved multiple cross-site scripting (XSS) vulnerabilities that enabled the attacker to obtain authenticated admin sessions.

The second hack was to draw attention and to pressure Instructure into entering negotiations to pay a ransom following an initial breach disclosed a week before.

Instructure is the developer of Canvas, a popular learning management system (LMS) used by schools and universities around the world to handle assignments and coursework.

On April 29, the company discovered that its network had been breached and “immediately revoked the unauthorized party’s access, started an investigation, and engaged outside forensic experts.”

A few days later, the company confirmed that data was stolen in the cyberattack, and ShinyHunters published Instructure on their data leak site, stating that they stole more than 3.6 terabytes of uncompressed data.

In an attempt to coerce Instructure into paying a ransom, the threat actor hacked Instructure again on May 7 using the same vulnerability used in the initial intrusion.

ShinyHunters injected malicious JavaScript exploiting XSS bugs within user-generated content features, which gave them access to authenticated admin sessions and allowed them to perform privileged actions.

In an email to BleepingComputer on Sunday, Instructure confirmed that the exploited security issue affected the Free-for-Teacher environment, the free, limited version of Canvas LMS for individual educators.

“The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas” – Instructure

At the time, the organization added that it temporarily took Canvas offline to prevent the malicious activity from spreading, determine the cause, and to “apply additional safeguards.”

ShinyHunters used the flaw to add a message to Canvas login portals, warning that the company, as well as schools using its platform, had until May 12 to reach out and negotiate a ransom.

ShinyHunters message left on University of Texas San Antonio Canvas login page
Hackers’ message on the Canvas login page of the University of Texas San Antonio
​​​​

Instructure has shut down Free-For-Teacher accounts until the issues have been resolved. However, Canvas has been restored and is available for use since May 9th.

While no data was compromised when defacing Canvas login portals, the data that ShinyHunters exfiltrated in the first breach likely includes usernames, email addresses, course names, enrollment information, and messages.

According to ShinyHunters, the Instructure breach impacts 8,809 educational organizations (schools, universities, colleges, online platforms) and the hackers claim to have stolen 275 million records belonging to students, teachers, and other staff members.


article image

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Claim Your Spot

Read More
Ionut Ilascu

Latest

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Newsletter

Don't miss

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Kehlani at 30: How ‘Folded’ Changed Everything | Billboard Women In Music 2026

MusicBillboard Women in Music 2026 Impact Award recipient...

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand