A Second Attack in Eight Months
Instructure, the company behind the Canvas learning management system used by thousands of schools and universities, had already been breached once by the extortion group ShinyHunters, back in September of last year, in an attack that ran through Salesforce. So when unauthorized activity showed up on its systems again around April 30 of this year, it was not a new adversary. It was the same one, back for a second try.
This time the attackers got in using stolen API keys. By early May, Instructure confirmed the scale of what happened: 3.65 terabytes of data, affecting roughly 275 million users across more than 9,000 schools. Names, email addresses, student ID numbers, and in some cases private messages were exposed. Reports from the time say that when Instructure did not pay the initial ransom demand, ShinyHunters came back a second time and defaced Canvas login screens in the middle of school finals, disrupting exams for students who had nothing to do with any of it.
Who Is ShinyHunters, Actually
ShinyHunters is not one person or a tight-knit crew in the traditional sense. It operates more like an extortion-as-a-service business, and 2026 has kept it busy. The group has been linked to more than 40 breaches this year using three main playbooks: voice phishing calls that impersonate IT support to trick employees into handing over their Okta, Microsoft, or Google single sign-on credentials, MFA codes included; misconfigured Salesforce Experience Cloud sites left exposed to the public internet; and OAuth-based supply chain attacks in the same spirit as the Klue and Salesloft Drift incidents from earlier this year.
Instructure is just one entry on a longer list. Charter, the internet provider, lost roughly 40 million records to the group. Carnival Cruise Line had close to 6 million customer records exposed after attackers used social engineering to talk their way in. Add those to a string of incidents touching higher education, finance, and government targets throughout the year, and a pattern shows up clearly: ShinyHunters does not need a novel zero-day. Convincing one employee to hand over a password over the phone works often enough.
The Bigger Wave This Fits Into
Instructure and Charter are not outliers. Between January and June of 2026, there were 45 confirmed major breaches exposing more than 683 million records across 14 industries and 17 countries. Education alone accounted for a huge share of that total, driven almost entirely by the Instructure incident.
What stands out across nearly all of it is how ordinary the entry points were. Not sophisticated malware. Not nation-state tradecraft. A phone call to a help desk. A forgotten integration. A cloud setting configured once and never looked at again. Most of the technical sophistication in these breaches shows up after the attacker is already inside, not at the point of entry.
If Your Information Was Ever Part of a Breach Like This
If you work at, attend, or have a child enrolled at an institution that uses Canvas, or if you have ever been a Charter or Carnival customer, there is a real chance some of your personal information is sitting in a dataset that has already been stolen and possibly already sold or leaked. Statistically, the same is true for most adults after enough years online. A handful of steps meaningfully reduce what that exposure can be used against you for.
Change reused passwords first, starting with your email account, since email is the master key to nearly everything else you own online. Turn on multi-factor authentication everywhere it is offered, and choose an authenticator app over text message codes when you have the option. Freeze your credit with all three bureaus. It costs nothing and it stops new accounts from being opened in your name even if your Social Security number is already circulating. Check whether your email shows up in known breaches using a service like Have I Been Pwned, and treat any hit as a reason to change that password everywhere else you reused it. And be skeptical of unexpected calls from "IT support." ShinyHunters built an entire attack playbook around this one trick because it keeps working, and a real IT department will never ask you for your MFA code over the phone.
Why This Keeps Happening
ShinyHunters succeeds because organizations keep leaving the same doors unlocked: help desks that will reset a password for anyone who sounds confident enough, cloud services configured once and never reviewed again, third-party integrations nobody remembers granting access to. None of that requires a sophisticated attacker. It just requires someone willing to try the easy way in first, and in 2026, the easy way in has worked often enough to make ShinyHunters one of the most prolific extortion operations active today.
For individuals, this is exactly the gap a personal security audit is built to close: finding out where your information has already been exposed and shutting down the paths that make you an easy target for whatever version of this playbook shows up next. At AetherGuard Technologies, that is what our personal security audit service does, and for businesses, we help harden the help desk verification steps and cloud configurations that groups like ShinyHunters are counting on being left open.







