
In a troubling development for the education technology sector, Instructure has revealed a data breach that has jeopardized the personal information of students. The breach includes sensitive details such as student names, personal email addresses, and communications exchanged between students and teachers. Following this initial incident, hackers have re-emerged, targeting several schools by defacing the login pages of Instructure's Canvas platform, which is widely used for managing coursework and facilitating student-teacher communication. The cybercrime group known as ShinyHunters has claimed responsibility for this latest attack, showcasing their message on the altered login screens of at least three institutions. Upon examining the compromised portals, it was found that the hackers had inserted an HTML file that modified the login interface to deliver their ultimatum. The group has threatened to release the stolen data on May 12 unless Instructure engages in negotiations for a settlement. As of now, Instructure's website is only partially accessible, with users occasionally encountering a “too many requests” error. Meanwhile, the Canvas portal has announced that it is undergoing scheduled maintenance. Instructure has yet to respond to inquiries from TechCrunch regarding this alarming situation. ShinyHunters had previously claimed responsibility for the initial breach, which they publicized on their leak site—an online platform used by hackers to release stolen data and exert pressure on their targets for ransom. This latest breach, coupled with the group's decision to inform TechCrunch about the defaced login pages, suggests a strategic move to intensify pressure on Instructure and its user base, aiming to coerce them into conceding to their threats. The specifics of how these hackers managed to breach the login pages remain unclear. A representative from ShinyHunters indicated that this incident constitutes a separate breach from the original one. Following the first hack, the group asserted that they had acquired data from nearly 9,000 educational institutions globally, with the stolen files purportedly containing information on 231 million individuals. The group's modus operandi has consistently involved hacking, publicizing stolen data, and attempting extortion, raising serious concerns about ongoing cybersecurity vulnerabilities in the education sector.
In the heart of America's data center hub, Ashburn, Virginia, a heat wave has raised alarms about the sustainability of ...
Business Insider | Jul 11, 2026, 04:15In a significant legal move, Apple has filed a lawsuit against OpenAI, claiming that the AI company has unlawfully utili...
CNN | Jul 10, 2026, 20:35In a significant legal move, Apple has launched a lawsuit against OpenAI, accusing the AI company of stealing trade secr...
TechCrunch | Jul 10, 2026, 20:45
A lengthy legal battle between Fizz, a social app catering to college students, and its competitor Sidechat has taken a ...
TechCrunch | Jul 10, 2026, 18:20
In a significant development in the ongoing battle for AI talent, Apple has filed a lawsuit against OpenAI, accusing the...
Business Insider | Jul 10, 2026, 22:50