dailyloe.com – The education technology firm Instructure, based in Salt Lake City, Utah, experienced a data breach following a cyberattack. Disclosed on April 30, the incident disrupted services reliant on API keys. By Sunday, May 3, access to the Canvas Data 2 platform was restored.
On May 1, Instructure announced that cybercriminals perpetrated the incident and retained outside forensics experts for investigation. The company stated, “We are working quickly to understand the extent of the incident and actively taking steps to minimize its impact.”
By May 2, Instructure confirmed that the attack had been contained and certain application keys were reissued. Users were required to reauthorize access to tools to enhance security.
Instructure took additional measures, including revoking privileged credentials and access tokens, deploying security fixes, and implementing further monitoring. The attackers accessed personal information, including names, email addresses, and student ID numbers. User messages were also compromised.
Instructure stated, “At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.” However, the company did not disclose how many institutions and users were affected or identify the threat actor.
On May 3, the ShinyHunters extortion group added Instructure to its leak site, claiming to have stolen 3.65 terabytes of data. The group asserted that the theft includes information from 275 million individuals across nearly 9,000 education institutions globally, along with a compromise of Instructure’s Salesforce instance.
SecurityWeek has reached out to Instructure for further details on the attack and will provide updates if the company responds.


