This event is archived. Final snapshot from when the story concluded. View on Dashboard
Accidents cyberattack and data breach

Instructure Canvas Cyberattack and Data Breach

Analysis based on 80 articles · First reported May 07, 2026 · Last updated May 14, 2026

Sentiment
-70
Attention
8
Articles
80
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The cyberattack on Instructure's Canvas platform and the subsequent data breach have a negative impact on the education technology market, raising concerns about the security of cloud-based learning systems. Instructure's stock price may face selling pressure due to reputational damage and the costs associated with remediation and potential legal actions. The incident also highlights the growing cybersecurity risks for companies handling sensitive personal data, potentially leading to increased investment in cybersecurity solutions across the industry.

education software cybersecurity

Instructure, the company behind the widely used Canvas learning management system, experienced a major cyberattack perpetrated by the hacking group ShinyHunters. The attack caused widespread disruption, knocking Canvas offline during final exam periods for millions of students and educators across thousands of schools and universities worldwide. ShinyHunters claimed to have stolen 6.65TB of data, including student names, email addresses, ID numbers, and private messages, and threatened to leak it unless a ransom was paid. Instructure initially detected unauthorized activity on April 29 and again on May 7, leading to temporary shutdowns of the platform. The company later announced it reached an agreement with ShinyHunters for the return of the stolen data and received digital confirmation of its destruction, though experts remain skeptical about the complete eradication of the data. The incident has drawn congressional scrutiny, with the United States — United States House Committee on Homeland Security requesting a briefing from Instructure's CEO. The breach exposed vulnerabilities in education technology and highlighted the significant impact of cyberattacks on critical infrastructure, leading to academic disruptions, extended deadlines, and increased stress for students and faculty.

per
Steve Daly, CEO of Instructure, was requested by the United States — United States House Committee on Homeland Security to provide a briefing on the cyberattack, highlighting his leadership role in responding to the crisis.
Importance 50.0 Sentiment -20.0
per
Steve Proud, Instructure's chief information security officer, signed updates regarding the cybersecurity incident and confirmed the types of data involved in the breach.
Importance 50.0 Sentiment -20.0
priv
Emsisoft is a cybersecurity firm whose threat analyst, Luke Connolly, provided insights and confirmed ShinyHunters' responsibility for the breach, contributing to the understanding of the attack.
Importance 30.0 Sentiment 10.0
per
Luke Connolly, a threat analyst at Emsisoft, identified ShinyHunters as the perpetrators of the Canvas cyberattack and provided details about the breach and the hacking group.
Importance 30.0 Sentiment 10.0
oth
Montgomery County Public Schools in Maryland restricted access to Canvas services out of caution following the breach, despite Canvas returning to service.
Importance 30.0 Sentiment -50.0
oth
The South Orange-Maplewood School District was one of the affected entities, informing parents about the security breach and its timeline.
Importance 30.0 Sentiment -50.0
govactor
The United States — United States House Committee on Homeland Security requested a formal briefing from Instructure CEO Steve Daly, indicating congressional scrutiny and the national importance of the cyberattack.
Importance 30.0 Sentiment 0.0
per
Cynthia Kaiser, former deputy director of the United States — Federal Bureau of Investigation's Cyber Division and senior vice president of the Halcyon Ransomware Research Center, offered expert skepticism regarding the effectiveness of paying ransoms.
Importance 20.0 Sentiment 10.0
priv
Picus Labs, through its security research lead Huseyin Can Yuceel, provided expert commentary on the timing and motivation behind the cyberattack.
Importance 20.0 Sentiment 10.0
per
Huseyin Can Yuceel, security research lead at Picus Labs, commented on the deliberate timing of the cyberattack to maximize impact and extortion potential.
Importance 20.0 Sentiment 10.0
per
Allan Liska of Recorded Future offered insights into the deliberate nature of the outage and the common practices of hacking groups regarding data leaks and ransom negotiations.
Importance 20.0 Sentiment 10.0
oth
The University of Nevada, Reno was affected by the Instructure outage, with its WebCampus services disrupted, and faculty working to address impacts on final examinations.
Importance 15.0 Sentiment -10.0
subs
Live Nation Entertainment — Ticketmaster, a subsidiary of Live Nation Entertainment, was a past victim of a ShinyHunters cyberattack, demonstrating the group's modus operandi and reach.
Importance 10.0 Sentiment -10.0
stock
Live Nation Entertainment's Live Nation Entertainment — Ticketmaster subsidiary was previously targeted by ShinyHunters, highlighting the hacking group's history of high-profile breaches.
Importance 10.0 Sentiment -10.0
oth
Halcyon Ransomware Research Center is where Cynthia Kaiser serves as senior vice president, offering expert commentary on the cybersecurity event.
Importance 5.0 Sentiment 0.0
+ 23 more entities View on Dashboard
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.