Entire list of affected schools by Instructure breach
bd_b4e9916bda23695a · schema v1 · pii pii-v1
Full breach record for Entire list of affected schools by Instructure breach →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shinyhunters on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
The download button below is a list of affected schools by the Instructure Canvas LMS data breach. If any of the schools in the file are interested in preventing the release of their data please consult with a cyber advisory firm and contact us privately at TOX to negociate a settlement. You have till the end of the day by 7 May 2026 before everything is leaked and there will be no chance at a negociation for anyone. Instructure has not even bothered speaking to us to understand the situation or to even negociate with us to prevent the release of this data. Our demand was not even as high as you might think it is. The Company seemingly does not care about all the students affected and the institutions impacted by this data breach. They still have by 6 May 2026 to come speak with us. There is no better option but to come to an agreement with us. Not paying will only worsen the situation rather than resolving it. | Updated: 5 May 2026 | Warning: FINAL WARNING PAY OR LEAK
Source provenance
- Source URL
- https://www.ransomware.live/id/RW50aXJlIGxpc3Qgb2YgYWZmZWN0ZWQgc2Nob29scyBieSBJbnN0cnVjdHVyZSBicmVhY2hAc2hpbnlodW50ZXJz
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2026
- Raw hash
- fe2a7e737d808f2c7faff45590904cfdbb0439a45b800d2bac428d20f5e0d9ec
Reporting entity
- Name
- shinyhunters
Victim entity
- Name
- Entire list of affected schools by Instructure breachnorm: entire list of affected schools by instructure breach
- Industry
- Educationllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· shinyhunters
- Threat actor
- ShinyhuntersExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.