GoFirm
Back to Blog
Case Studies·4 min read

One Phone Call. Thirty Million Students. The Instructure Breach and the Credential That Was Never Confirmed.

By GoFirm

On 30 April 2026, the Canvas learning management system, operated by education technology company Instructure and used by over 9,000 institutions in more than 100 countries, was breached by the cybercriminal group ShinyHunters. The attackers did not exploit a software vulnerability to gain initial access. They placed a phone call. Posing as IT support personnel, ShinyHunters contacted Instructure staff and manipulated them into providing or resetting account credentials, a technique the group had used across dozens of enterprise targets throughout 2025 and into 2026.

ShinyHunters' method is consistent and documented. The group operates in English, contacts IT help desks and support teams by phone, and presents as either a colleague locked out of their account or an IT technician requiring elevated access to resolve an incident. The social engineering is not elaborate. It relies on the gap between what an IT support agent can verify and what a caller can assert. Once credentials were obtained, the attackers traversed Instructure's production environment, reaching data stores containing student and staff records across the platform's global client base.

Instructure disclosed the breach on 1 May 2026 and confirmed on 2 May that the data stolen included names, email addresses, identification numbers, and private messages exchanged between students and teaching staff. The company confirmed that more than 30 million individuals had been affected. The attackers' own figure was substantially higher: ShinyHunters claimed to have taken 3.65 terabytes of data containing records on 231 million people across 8,809 institutions. On either figure, the breach represents the largest confirmed educational data theft on record.

Instructure announced on 6 May that the incident had been contained. It had not. On 7 May, ShinyHunters defaced the Canvas login portals of three universities, replacing student-facing screens with an extortion message and a deadline of 12 May to pay or face publication of the stolen data. The timing was calculated: institutions across the United States and worldwide were in the middle of examination season. Students attempting to access coursework, submit assignments, and review grades encountered a ransom demand instead. The FBI advised Instructure not to pay. Instructure paid on 11 May 2026, one day before the deadline.

The defences that failed here were not weak by conventional standards. Instructure operates at enterprise scale, serving some of the world's largest university systems, including many with significant security requirements of their own. Access controls, multi-factor authentication, and monitoring infrastructure were in place. The attack did not engage any of them. The failure point was a telephone conversation in which an Instructure IT employee had no way to confirm that the person requesting access was who they claimed to be. The attacker required no malware, no exploit, and no technical capability beyond the ability to make a believable call.

The initial breach in this incident was an authorised credential change: an IT support agent resetting or providing account access following a request from a caller whose identity was unverifiable. That credential change is an execution event. Before any IT administrator at Instructure can complete an account reset or grant elevated access permissions, a confirmation request goes to the named authority on their registered device, requiring biometric authentication via a separate, out-of-band channel. The caller can claim any identity. The confirmation request goes to the real person, on their real device. If the genuine account holder did not initiate the interaction, no confirmation is returned. The action does not execute.

The same principle applies at the second control point in this breach: the granting of access to production data environments containing student records. Every access grant to a sensitive data system is an execution event. GoFirm places a confirmation requirement at each of those boundaries. The attacker, operating remotely by phone, has no means of producing biometric confirmation on the registered device of the internal authority whose credentials they have just obtained. The breach chain breaks at the first contact point, before any credential changes take effect, before any data is reached. A caller posing as IT support, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Lorenzo Franceschi-Bicchierai, Zack Whittaker, "Hackers deface school login pages after claiming another Instructure hack," TechCrunch, 7 May 2026. https://techcrunch.com/2026/05/07/hackers-deface-school-login-pages-after-claiming-another-instructure-hack/

2. Zack Whittaker, "Hacked, leaked, and held for ransom: the worst breaches of 2026 so far," TechCrunch, 7 June 2026. https://techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/

3. "Canvas LMS Breach: 275M Records, 9K Schools Hit [2026]," Tech Insider, 2026. https://tech-insider.org/canvas-lms-breach-shinyhunters-275-million-records-2026/

4. "Education Sector in the Crosshairs: ShinyHunters Extortion Campaign Against Instructure," Halcyon.ai, 2026. https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure

5. "Canvas x ShinyHunters: Full Intelligence Report, May 2026," Protos Labs, May 2026. https://www.protoslabs.io/resources/shinyhunters-canvas-incident-full-report-may-2026

Share this article