Stolen Canvas data was “returned” after hacker agreement, Instructure says


The Instructure/Canvas data breach that has dominated cybersecurity coverage recently has reached a new stage.

Millions of students had personal data stolen, with extortion group ShinyHunters claiming credit for the data breach and applying extra pressure for their ransom demands by bothering Canvas users directly.

Which seems to have paid off. On the Instructure web page about the recent data breach, a status update dated May 11, 26 says:

“We know that concerns about the potential publication of data related to this incident remain top of mind for many customers. We understand how unsettling situations like this can be, and protecting our community remains our top priority.

With that responsibility in mind, Instructure reached an agreement with the unauthorized actor involved in this incident.”

Read more…
Source: Malwarebites Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Asos customers receive ‘hack’ notification threatening to leak data

    October 6, 2026

    Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging ...

  • Blinder Tunnel Campaign Targets Iraqi Infrastructure

    October 6, 2026

    Palo Alto Unit 42 discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign they call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging ...

  • Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach

    October 5, 2026

    A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...

  • ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau

    October 3, 2026

    A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...

  • AI agents aggressively tried to hack US and Canadian government websites

    October 2, 2026

    AI agents simply won’t take ‘no’ for an answer. Security researchers from nonprofit Transluce found bots making numerous attempts to hack US and Canadian government websites in search of private information. In a new report, Transluce singled out two incidents: one against the US Department of Education, and one against Library and Archives Canada. Both seem ...

  • SMTP is the key: BPFDoor and AVERAT hitting the network edge

    October 2, 2026

    Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...