ShinyHunters claims second Canvas breach as universities face fresh outage
The cybercrime group ShinyHunters says it has breached Instructure, the company behind the Canvas learning platform, for a second time, according to a report dated 2026-05-07 in the packet.
The claim, if true, would affect a huge number of students and staff. The source material says ShinyHunters claims to have compromised 280 million records from 8,809 colleges, school districts and online education platforms. It also says the attack blocked access to Canvas and that the group threatened to release stolen data unless schools contacted it by May 12.
Because the packet is built around a claim from the hackers, the reporting has to be careful. The group is a known cyber extortion operation, and its numbers are not independently verified in the excerpt. The article can report the claim and the institutions that responded, but should not present the stolen-record figure as established fact without confirmation.
The packet notes that universities including Harvard, Stanford, Columbia, Rutgers, Princeton, Kent State and Georgetown issued warnings to students about the incident. Several school districts in multiple U.S. states were also affected. That response is important because it shows the attack was not limited to one institution or one region, but had broad educational reach.
Stanford said Canvas was unavailable because of an issue with the vendor and later added that a wider outage was affecting numerous educational institutions nationwide. That suggests the incident had both a security and service-disruption dimension.
The source also says Instructure had previously disclosed a nationwide information security issue it said had been contained. The hackers, however, claimed the company had been breached again and mocked its response. That claim is central to the story, but it remains the hackers’ own account.
The packet gives a few details about what the original breach exposed, including names, email addresses, student ID numbers and private messages exchanged between users. Those data types would be highly sensitive if confirmed, because they combine identity details with potentially private communications.
Given the sensitivity and the fact that the claims come from an extortion group, the article should remain disciplined. It should report that schools were warned, access was disrupted and a second breach was claimed, while making clear that the scale of compromise is asserted by the hackers rather than independently confirmed in the packet.
The wider significance is obvious: education technology platforms sit at the center of daily operations for thousands of schools. A breach or outage can affect not only data security but also classroom access, administrative systems and student communications.
That is why the incident drew rapid attention across higher education and school districts. Even a temporary outage can cause disruption, but a breach claim of this scale raises the stakes much further.
The verified story, then, is not that every figure is proven. It is that ShinyHunters has claimed a second hit on Canvas, institutions across the United States reacted quickly, and Instructure’s platform was again disrupted.



