An empty classroom with rows of student desks and chairs.
Photo via Unsplash

TL;DR: ShinyHunters gave Instructure until May 6, 2026 to pay or watch the full 3.65 terabyte Canvas trove drop on its Tor leak site. As of the morning before the deadline, Instructure has not publicly responded to the demand. Wayzata Public Schools in Minnesota became one of the first US districts to formally warn parents on May 4. Rutgers IT issued a campus-wide alert the same day. Chimicles Schwartz Kriner & Donaldson-Smith, the firm that ran the Infinite Campus class action, has opened an investigation. TechCrunch confirmed it reviewed sample data from two US schools, meaning ShinyHunters' claim is not just talk. Here is what students, parents, and districts should expect when the clock runs out tomorrow.

The Deadline, In Plain English

ShinyHunters listed Instructure on its Tor extortion site on May 3, 2026 with a 72-hour countdown. The wording on the listing is unequivocal: pay or face a full leak [1][2]. The group's stated terms (repeated almost verbatim in the Crunchyroll, Bumble, and Kemper extortion posts that ran earlier in this campaign) give Instructure until May 6 to either pay the ransom or watch 3.65 TB go public, plus what ShinyHunters describes as "several annoying digital problems" if Instructure stalls [2].

Instructure has not publicly addressed the ransom. The company's spokesperson Kate Holmes declined to answer TechCrunch's questions on May 5, instead pointing reporters to the company's status page [3].

That silence is doing two things at once. It signals Instructure does not intend to pay: companies that pay almost never confirm it, but they also stop appearing on the leak site. The countdown clock is still running. It also signals that Instructure has decided to absorb the reputational hit rather than fund the next round of attacks. ShinyHunters has historically followed through on leaks when ignored. The Crunchyroll and Bumble samples both went public after their respective deadlines lapsed.

This Is Not Bluff: TechCrunch Saw the Data

The single most important development in the last 48 hours is that TechCrunch confirmed it reviewed sample data from two US schools provided by ShinyHunters [3]. The samples included names, email addresses, some phone numbers, and teacher-student messages. The threat actor also told TechCrunch that the unique email count in the stolen archive is 231 million, a number that is consistent with, but smaller than, the 275 million users figure on the leak listing.

That distinction matters. 231M unique emails is a credible deduplicated count for an LMS where students often have multiple accounts (a personal one, a school one, a parent observer one). The 275M figure is total user records. Neither is inflated in the way ShinyHunters has occasionally inflated past listings.

For our prior coverage of the breach disclosure itself, see Canvas LMS Breach: ShinyHunters Claims 275 Million Students, 9,000 Schools, 3.65TB.

Wayzata Public Schools Goes First

Wayzata Public Schools, a 12,000-student district in the western Minneapolis suburbs, became one of the first US districts to formally notify parents on May 4 [4]. The district's official statement to families reads:

"The privacy and security of our students' data is our highest priority. The district has activated its Incident Response Team, is staying in close contact with Instructure and has started reviewing its own security protocols. Families are being urged to watch for phishing attempts and monitor school accounts for any unusual activity."

Wayzata's notice covers students in grades 4-12. The district told parents:

  • The breach was vendor-side: Wayzata's own internal networks were not compromised
  • Potentially exposed: student and staff names, email addresses, student ID numbers, internal Canvas messages
  • Per Instructure: no passwords, dates of birth, government IDs, or financial information were taken
  • Watch for unsolicited emails impersonating Canvas, especially password-reset prompts
  • Monitor student accounts for unusual activity

This is the template every other US district is going to copy this week. Expect formal notifications from larger districts (LAUSD, NYC DOE, Chicago Public Schools, Houston ISD) as soon as their legal departments finish the FERPA paperwork.

Higher Ed Is Quieter, But Watching

Rutgers IT pushed a public alert on May 4 confirming it had been notified about the "vendor-driven, nationwide event" but said the university had not been told its specific data was in the exfiltration scope [5]. The alert recommended monitoring Instructure's status page and contacting the OIT Help Desk for issues. It did not recommend specific user actions.

That cautious posture is going to age poorly if ShinyHunters drops a sample with Rutgers email domains in it. Universities are sitting on the same Canvas data as K-12 districts but with the additional complication of FAFSA-linked accounts, financial aid integrations, and adult students whose information has direct fraud value.

For reference, ShinyHunters has already breached Harvard and the University of Pennsylvania in this same campaign window. Higher ed is not a hardened sector for this group.

The Class Action Lawyers Are Already Lining Up

Two firms had public investigations open within 72 hours of the breach disclosure:

  • Chimicles Schwartz Kriner & Donaldson-Smith LLP opened an investigation [6]. This is the same firm that filed the major class action over the Infinite Campus breach earlier this year. They are the closest thing to a specialist in K-12 SIS/LMS breach litigation in the US right now.
  • Class Action U is collecting potential plaintiffs and signaling claims around privacy violations, emotional distress, and identity theft risk [7].

The legal template is going to look a lot like the Infinite Campus suit. That case alleged Instructure's smaller K-12 competitor failed to implement reasonable security measures, failed to detect intrusions in a reasonable time, and exposed minors' records in violation of state consumer protection statutes and FERPA's implementing rules. Substitute "Instructure" for "Infinite Campus," scale the class size up by roughly 25x (11M Infinite Campus students vs. 275M Canvas users claimed), and that is approximately what is coming.

This would not be Instructure's first privacy-related class action. There is a separate, pre-existing case alleging Instructure illegally monetizes student data collected through Canvas and other education products [8]. That suit has nothing to do with the ShinyHunters breach but it is going to get bundled into headlines as plaintiff lawyers compete for press.

Regulators on Deck

Three regulatory bodies have jurisdiction here:

  • The Department of Education's Student Privacy Policy Office. Under FERPA, schools are responsible for ensuring vendors handle student records appropriately. The SPPO accepts complaints from parents whose districts fail to notify them. Expect a complaint surge in the next 30 days.
  • State attorneys general. All 50 states have data breach notification laws. Most require notification within 30-60 days of a breach being identified. The clock for that started May 1. California, New York, and Texas AGs typically lead on multistate education breach probes.
  • The FTC. If Instructure made specific representations to schools about its security posture that turn out to have been inaccurate, that is FTC Section 5 territory. The FTC's 2024 settlement with edtech vendor Edmodo is the precedent.

None of these will move before the May 6 deadline. All of them will move within 60 days.

What Happens If ShinyHunters Drops the Full Trove

Three things happen in roughly this order if the data goes public on May 7:

  1. Initial seller analysis. Researchers at firms like Hudson Rock, Have I Been Pwned, and various academic threat-intel groups download the listing within hours and start parsing institution domains. Expect a public list of which schools were in the dump within 48 hours of the leak.
  2. Phishing weaponization. Lower-tier criminals buy or copy the data and start running targeted phishing within 7-14 days. The Canvas-specific angle is brutal here: a phisher with a real student-teacher message thread can craft a "your teacher needs you to log in" email that is nearly impossible to flag as fake.
  3. Identity theft against minors. Children's identities are the gold standard for long-running fraud: kids do not check credit reports for years. A SSN is not in the leak (per Instructure), but names, school district, ID numbers, and birth-month-style identifiers in messages are enough to seed credit-application fraud combined with other public-records data.

What Parents Should Do Tonight

  • Freeze your child's credit at all three bureaus. Free, takes about an hour, valid until the child turns 16 or you lift it. Equifax, Experian, and TransUnion all offer minor freezes through their websites. Do this even if your district has not sent a notice.
  • Treat any "Canvas" email this week as suspicious. Real Instructure communications route through your school district, not a generic canvas-support@ address. If a teacher seems to need an urgent password reset, log into Canvas through your district's portal, never click a link in an email.
  • Ask your district directly. Was your data in scope? When will the formal notice go out? Has Instructure provided a written confirmation? Districts that say "we are waiting for guidance" two weeks from now are dodging.
  • Document everything. Save the district's notification email. Save Instructure's status-page screenshots. If your child is later targeted in a Canvas-themed phishing attack, that documentation is the basis for both insurance claims and any class action recovery.
  • For older students with linked financial aid: if your high schooler or college student has a FAFSA-connected account or has used Canvas with single sign-on tied to financial aid records, monitor accounts and pull free weekly credit reports at AnnualCreditReport.com.

What Districts Should Do This Week

  • Get a written, dated statement from Instructure confirming whether your district's data was in the exfiltration scope. "We will let you know" is not adequate at this point in the timeline.
  • Audit any Salesforce-Canvas integration. ShinyHunters claimed in its leak listing that it also breached Instructure's Salesforce instance, meaning every customer with a connected SFDC org should rotate OAuth tokens.
  • Pre-draft your parent notification now. Wayzata's letter is a workable template. Do not wait for Instructure to formally tell you to issue one: your state breach law clock started May 1.
  • Reassess Canvas as a vendor. This is the second Instructure breach in eight months. Procurement officers have a fiduciary basis to ask about platform alternatives.

The Bigger Pattern

K-12 and higher ed have spent a decade outsourcing their data infrastructure to a small handful of SaaS vendors. Canvas, Infinite Campus, PowerSchool, and Blackboard hold records on something close to every American student. Each one has been breached at multi-million-record scale in the last 18 months. The PowerSchool breach in early 2025 hit roughly 62 million students. The Infinite Campus breach in March 2026 hit 11 million. Now Canvas, claimed at 275 million globally.

The structural problem is procurement. Districts pick edtech vendors based on user experience, price, and integration with existing tools. They sign contracts with liability caps that limit the vendor's exposure to whatever was paid that year. They trust that someone, somewhere, is running the security audits. Then ShinyHunters phishes one Salesforce admin and the records walk out the door: at Crunchyroll, at Kemper, at Bumble, at Wynn, at Harvard, at Penn, and now at the LMS vendor that a quarter of US K-12 students use every day.

The Canvas deadline tomorrow is not really about Instructure. It is about whether the edtech consolidation that put 9,000 schools into a single vendor's database is sustainable when that vendor's security team is one phone call away from a 3.65 TB exfiltration.

What to Watch Next

  1. May 6, end-of-day: Does ShinyHunters' Tor listing change to "leaked" or stay at "deadline"? If the listing flips to leaked, expect dataset analysis within 24 hours.
  2. May 7-10: Researcher analysis of any released data. Watch Have I Been Pwned, DataBreaches.net, and BleepingComputer for institution-level breakdowns.
  3. May 8-12: First wave of district notifications across major US K-12 systems. Larger districts move slowest because legal review takes longer.
  4. By May 31: First class action complaints filed (likely in the District of Utah, where Instructure is headquartered, plus parallel filings in California and New York).
  5. By June 30: Either a state AG enforcement action or a multistate investigation announcement. The Utah AG, as the home-state regulator, will be on the spot.

For now, 275 million students, parents, teachers, and staff are waiting on a Tor leak site refresh. Tomorrow is when we find out whether ShinyHunters meant it.

Sources

  1. DataBreaches.net: Instructure discloses second data breach in less than a year (May 3, 2026)
  2. NetCrook: ShinyHunters Threaten to Leak Massive Instructure (Canvas LMS) Data Trove (May 2026)
  3. TechCrunch: Hackers steal students' data during breach at education tech giant Instructure (May 5, 2026)
  4. FOX 9: Canvas data breach: Wayzata Public Schools sends warning letter to parents (May 4, 2026)
  5. Rutgers IT: Nationwide Security Breach Involving Canvas (May 4, 2026)
  6. Chimicles Schwartz Kriner & Donaldson-Smith LLP: Instructure (Canvas LMS) Data Breach Investigation
  7. Class Action U: Instructure Data Breach Lawsuit
  8. ClassAction.org: Class Action Lawsuit Claims Instructure Illegally Monetizes Student Data
  9. BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack (May 2026)
  10. Cybernews: Canvas breach? Hackers threaten to leak messages of 275M users (May 2026)