8,000+ institutions. 41% of North American higher-ed. Instructure's second ShinyHunters breach in eight months — Protos AI mapped the full attack chain, TTPs, and affected targets in under 30 minutes.
.png)
On 25 April 2026, ShinyHunters — operating within the Scattered LAPSUS$ Hunters (SLSH) alliance — breached Instructure’s Canvas platform via its Free-For-Teacher account program. Confirmed exposed data includes names, institutional email addresses, student IDs, and private Canvas inbox messages across thousands of institutions. This is Instructure’s second ShinyHunters breach in eight months.
The immediate risk is not ransomware — it’s a wave of highly credible phishing and vishing attacks using stolen course names, instructor details, and message content. This report gives your security team the full picture: attack timeline, threat actor profile, MITRE ATT&CK TTP mapping, IOCs, and nine prioritised actions for this week.
18-page threat intelligence pack for education sector security leaders. TLP:CLEAR — free to share.
Your downloads are ready ↓
⤓ CISO Information Pack — Canvas × ShinyHunters⤓ Technical Details — Canvas × ShinyHunters