Apps & Consumer
Instructure breach exposes student data around the world
Instructure has confirmed a data breach involving student information, with the hacking group ShinyHunters claiming to have compromised data from close to 9,000 schools around the world.
Education technology company Instructure has confirmed a data breach affecting students’ private information. ShinyHunters, a hacking and extortion gang, has claimed responsibility for the breach. The group claims to have stolen students’ names, personal email addresses, and messages sent between teachers and students. These communications occurred on Canvas, Instructure’s platform that allows educational institutions to manage coursework and assignments and communicate with students. When reached, Instructure spokesperson Kate Holmes did not answer several questions about the incident, referring instead to the company’s official page where it is publishing updates on the breach.
While the full extent of the breach remains unverified, the scope of the incident spans the United States, including Massachusetts and Tennessee, and other locations around the world. A member of ShinyHunters shared a sample of the stolen data, which included information from schools in Massachusetts and Tennessee. ShinyHunters also shared a list of about 8,800 schools allegedly affected by the breach. On its data leak site, where the group claims responsibility for data breaches and attempts to pressure victims into paying a ransom, ShinyHunters claims the breach affected close to 9,000 schools around the world. The hackers claim that 275 million people’s data was affected. In an online chat, a member of the group told TechCrunch that the total unique emails included in the stolen data amount to 231 million. These figures contrast with Instructure’s official site, which states the company has more than 8,000 institutions as customers.
These cybercriminals, operating as financially motivated hacking groups, are known to target organizations—including universities and cloud database companies in recent months—to steal vast amounts of personal information. They typically threaten to post the stolen data online if the victim companies do not pay a ransom. As of Tuesday, Instructure said some of its products, such as Canvas, were restored for customers after undergoing maintenance.
Why it matters
As education systems increasingly centralize data on platforms like Canvas, this breach highlights the significant security risks facing EdTech infrastructure around the world and the students who rely on it.