Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Instructure Reaches Deal to Prevent Data Leak

Instructure Reaches Deal to Prevent Data Leak

Posted on May 12, 2026 By CWS

Instructure, a leading educational technology firm based in the United States, has announced a resolution with a cybercrime group to prevent the release of sensitive data stolen from its network. This agreement follows a breach that jeopardized information from numerous educational institutions worldwide.

On Monday, the Utah-based company confirmed it had reached a settlement with the group involved in the breach, expressing concerns over the potential exposure of confidential data. As part of the settlement, Instructure paid a ransom to reclaim the stolen data and received digital proof of its destruction. The company assured that its customers would not face individual extortion threats related to the incident.

Background of the Cyber Attack

The breach, orchestrated by the ShinyHunters cybercrime group, targeted Canvas, a widely-used online learning management system, and resulted in the theft of 3.65 terabytes of data. Nearly 9,000 organizations were affected by this security lapse. Although initially thought to be contained, further unauthorized access was detected on May 7, 2026, leading to defacement of login portals for about 330 institutions.

This breach exploited an unspecified vulnerability linked to support tickets within Canvas’s Free-for-Teacher environment. The attackers accessed approximately 275 million records, including personal details such as usernames, email addresses, course information, and enrollment data. However, Instructure assured that no course content, student submissions, or login credentials were compromised during the breach.

Security Measures and Future Prevention

In response to the breach, Instructure has temporarily disabled Free-for-Teacher accounts and has not disclosed specific details about the vulnerability exploited. The company has taken decisive steps to bolster its security, including revoking privileged credentials, rotating internal keys, restricting token creation, and enhancing overall security protocols.

Additionally, Instructure is collaborating with cybersecurity experts to conduct a thorough forensic analysis and strengthen its security framework. The company is committed to ensuring that such incidents do not recur and is actively reviewing its data handling and protection measures.

Implications and Advisory

The breach poses significant risks, as the extracted data could facilitate targeted phishing campaigns against students, faculty, and parents. Cybersecurity firm Halcyon warned that the leaked information could be exploited to impersonate school officials or IT departments in subsequent attacks. Institutions are advised to issue phishing warnings and communicate directly with their communities to mitigate potential threats.

Instructure’s decision to settle with the cybercriminals underscores the complexities and ethical dilemmas organizations face when dealing with data breaches. As educational institutions increasingly rely on digital platforms, robust cybersecurity measures are imperative to safeguard sensitive information and maintain trust.

The Hacker News Tags:Canvas LMS, cyber attack, Cybersecurity, data breach, data security, digital extortion, education technology, Instructure, network security, phishing risk, ransom agreement, ShinyHunters, Vulnerability

Post navigation

Previous Post: Android Zero-Click Flaw Allows Remote Access
Next Post: TrickMo Android Malware Threatens Financial Apps

Related Posts

CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalog CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalog The Hacker News
Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns The Hacker News
Zero Trust Data Movement: The Overlooked Challenge Zero Trust Data Movement: The Overlooked Challenge The Hacker News
Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals The Hacker News
New Android Malware Threatens Pix Payments and Banking Apps New Android Malware Threatens Pix Payments and Banking Apps The Hacker News
BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark