Observed Signal · May 5, 2026 · Data Breach · Source: techcrunch · Impact: 2/5 · Sentiment: Neutral

Instructure Breach: ShinyHunters Steal Student Data

Executive Signal Summary

Instructure confirmed a data breach that exposed students' private information after the hacking gang ShinyHunters claimed responsibility. TechCrunch reviewed a sample of allegedly stolen records that included student and staff names, personal email addresses, messages between teachers and students, and some phone numbers from two U.S. schools (one in Massachusetts and one in Tennessee). The sample did not contain passwords. ShinyHunters posted a list of roughly 8,800 schools it says were affected and claimed the breach impacts about 275 million people; the group told TechCrunch the unique emails in the dataset number about 231 million. Instructure says it has more than 8,000 institutional customers and is publishing incident updates on its status site, and some products such as Canvas have been restored after maintenance.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A large education‑sector data breach involving a high‑profile hacking group raises privacy, security and potential regulatory concerns; however the incident primarily affects an ed‑tech vendor rather than core AdTech/MarTech infrastructure, so its direct industry impact is limited.

SIGNAL RADAR

Track Instructure Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Instructure confirmed a data breach affecting students' private information.
  • The hacking gang ShinyHunters claimed responsibility for the incident.
  • A sample of allegedly stolen data included names, personal email addresses, teacher-student messages and some phone numbers; it did not include passwords.
  • ShinyHunters published a list of ~8,800 schools and claimed the breach affected up to 275 million people; the group cited ~231 million unique emails.
  • Instructure reported it has more than 8,000 institutional customers and said some products (e.g., Canvas) were restored after maintenance.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 5, 2026
Original Coverage Title: “Hackers steal students’ data during breach at education tech giant Instructure”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Data BreachMay 7, 2026

Hackers Deface Canvas Login Pages After Instructure Breach

On 2026-05-07, TechCrunch reported that the cybercrime group ShinyHunters claimed a second compromise of education‑technology provider Instructure, publishing an extortion message on the Canvas login pages of three separate schools. The attackers injected an HTML file that altered login screens and threatened to publish stolen student data on May 12 unless Instructure negotiated a settlement. The incident follows an earlier disclosed breach (reported May 5) in which attackers stole students’ names, personal emails and teacher‑student messages. Instructure spokesperson Brian Watkins said the company took Canvas offline, confirmed the actors exploited an issue related to Free‑For‑Teacher accounts, temporarily shut down those accounts, investigated, and then restored access to Canvas. ShinyHunters previously publicized stolen files on a leak site and claimed data affecting thousands of schools and millions of people.

Read assessment
Security / Data BreachMay 13, 2026

US Lawmakers Demand Answers from Instructure

U.S. House Homeland Security Committee members have asked Instructure to testify after the education‑software maker was breached twice, with hackers stealing personal data belonging to millions of students. Committee chair Representative Andrew Garbarino wrote to Instructure CEO Steve Daly seeking explanations about how threat actors repeatedly accessed Canvas systems, what data were taken, how affected schools were notified, and the company's coordination with CISA. Instructure confirmed it “reached an agreement” with the hackers and said the attackers provided evidence that stolen data were deleted; a representative of the ShinyHunters group told TechCrunch it would not continue extortion but declined to disclose ransom details. Lawmakers say the repeated intrusion raises questions about Instructure’s incident response and obligations to institutions and individuals whose data it stores.

Read assessment
IdentityFeb 18, 2026

Figure Data Breach Exposes Nearly One Million Customers

Figure, a blockchain-based lending company, confirmed a data breach after hackers stole what the firm described as "a limited number of files." Security researcher Troy Hunt, creator of the breach-notification site Have I Been Pwned, analyzed the allegedly leaked dataset and found 967,200 unique email addresses tied to Figure customers. The exposed records reportedly include customer names, dates of birth, physical addresses and phone numbers. Cybercriminal group ShinyHunters claimed responsibility and published roughly 2.5 GB of data on its leak site. Figure has not publicly detailed the scope or specific types of data stolen beyond its initial statement and did not respond to inquiries about Hunt’s analysis. The incident raises privacy, fraud and regulatory risks for affected customers and data holders.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.