Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Instructure Reaches Deal to Prevent Data Leak

Instructure Reaches Deal to Prevent Data Leak

Posted on May 12, 2026 By CWS

Instructure, a leading educational technology firm based in the United States, has announced a resolution with a cybercrime group to prevent the release of sensitive data stolen from its network. This agreement follows a breach that jeopardized information from numerous educational institutions worldwide.

On Monday, the Utah-based company confirmed it had reached a settlement with the group involved in the breach, expressing concerns over the potential exposure of confidential data. As part of the settlement, Instructure paid a ransom to reclaim the stolen data and received digital proof of its destruction. The company assured that its customers would not face individual extortion threats related to the incident.

Background of the Cyber Attack

The breach, orchestrated by the ShinyHunters cybercrime group, targeted Canvas, a widely-used online learning management system, and resulted in the theft of 3.65 terabytes of data. Nearly 9,000 organizations were affected by this security lapse. Although initially thought to be contained, further unauthorized access was detected on May 7, 2026, leading to defacement of login portals for about 330 institutions.

This breach exploited an unspecified vulnerability linked to support tickets within Canvas’s Free-for-Teacher environment. The attackers accessed approximately 275 million records, including personal details such as usernames, email addresses, course information, and enrollment data. However, Instructure assured that no course content, student submissions, or login credentials were compromised during the breach.

Security Measures and Future Prevention

In response to the breach, Instructure has temporarily disabled Free-for-Teacher accounts and has not disclosed specific details about the vulnerability exploited. The company has taken decisive steps to bolster its security, including revoking privileged credentials, rotating internal keys, restricting token creation, and enhancing overall security protocols.

Additionally, Instructure is collaborating with cybersecurity experts to conduct a thorough forensic analysis and strengthen its security framework. The company is committed to ensuring that such incidents do not recur and is actively reviewing its data handling and protection measures.

Implications and Advisory

The breach poses significant risks, as the extracted data could facilitate targeted phishing campaigns against students, faculty, and parents. Cybersecurity firm Halcyon warned that the leaked information could be exploited to impersonate school officials or IT departments in subsequent attacks. Institutions are advised to issue phishing warnings and communicate directly with their communities to mitigate potential threats.

Instructure’s decision to settle with the cybercriminals underscores the complexities and ethical dilemmas organizations face when dealing with data breaches. As educational institutions increasingly rely on digital platforms, robust cybersecurity measures are imperative to safeguard sensitive information and maintain trust.

The Hacker News Tags:Canvas LMS, cyber attack, Cybersecurity, data breach, data security, digital extortion, education technology, Instructure, network security, phishing risk, ransom agreement, ShinyHunters, Vulnerability

Post navigation

Previous Post: Android Zero-Click Flaw Allows Remote Access
Next Post: TrickMo Android Malware Threatens Financial Apps

Related Posts

Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems The Hacker News
Trusted Open Source Insights: AI and Security Trends Trusted Open Source Insights: AI and Security Trends The Hacker News
38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases The Hacker News
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure The Hacker News
Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns The Hacker News
OpenClaw Flaws Risk Data Security and System Control OpenClaw Flaws Risk Data Security and System Control The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark