Instructure Pays Bitcoin Ransom After Canvas Hack, Fueling Crime Concerns
Canvas, a cloud-based learning management system operated by Instructure, is used by nearly 9,000 schools worldwide to manage courses and data on students and teachers. ShinyHunters claimed it breached the platform on April 29, 2026, and stole about 3.5 TB of data, potentially including names, email addresses, student identification numbers and private messages. The incident coincided with final exams in Europe and the United States, heightening the potential impact of service disruptions and personal-data exposure.
Instructure said on May 11, 2026, that it had reached an agreement with the attackers and confirmed paying an undisclosed ransom in Bitcoin. In return, it received the stolen data, records of its destruction and a promise that customers would not face further extortion. ShinyHunters had planned to publish the data by May 12. Experts warned that the payment could fund future attacks and that the hackers’ proof of deletion could not be independently verified.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →