On 11 May 2026, Instructure, the company behind Canvas, quietly updated its status page. It had reached an agreement with ShinyHunters, the group that stole 275 million student records from nearly 9,000 institutions worldwide. The data, they said, had been destroyed. The amount paid was not disclosed. There was no explanation of why a platform that serves 41% of North American universities had been hit twice by the same group inside eight months.
Canvas is back online. The story is not over. And the South African angle is the part almost nobody is talking about.
What actually happened, in order
On 25 April 2026, ShinyHunters got into Canvas through the Free-For-Teacher signup pathway. That programme required no institutional verification but shared server infrastructure with every paying university on the platform.
On 1 May, Instructure confirmed a breach and called it contained. Names, emails, student ID numbers, and private messages had been accessed. No passwords. No financial information. They declared the situation resolved.
On 3 May, ShinyHunters posted a ransom note on Ransomware.live claiming 3.65 terabytes of data and 275 million records. They gave Instructure until 6 May to make contact or they would leak everything. Instructure did not make contact. They installed security patches instead.
On 7 May, ShinyHunters came back. They defaced login pages at roughly 330 institutions. Harvard. MIT. Oxford. Columbia. Students sitting down to submit final assignments saw a ransom demand on their screen. Canvas went offline globally. The new deadline was 12 May 2026.
On 11 May, Instructure announced a deal. They had received shred logs as confirmation the data was destroyed. The amount remains undisclosed.
Instructure has not directly said whether they paid. They paid.
The opinion nobody wants to say out loud
Paying ShinyHunters was the wrong call. Not on moral grounds. On strategic ones. And it has likely made things worse for the next institution in line.
Cybersecurity researchers are consistent on this. Paying ransoms funds future attacks, emboldens threat groups, and provides no verifiable guarantee of data destruction. Shred logs are files. Files can be copied before they are shredded. ShinyHunters is not a charity.
The precedent matters. PowerSchool, a student information system used across North American schools, paid a ransom in 2024. Months later, individual teachers started receiving messages demanding money to keep their personal data confidential. Proof of data was included. The ransom resolved nothing. It confirmed to the attackers that education-sector victims pay.
Allison Nixon, chief research officer at Unit 221B, said publicly after the deal that ShinyHunters should not be trusted. Not because they are incompetent. They clearly are not. The issue is that a group that runs a pay-or-leak model has every incentive to keep copies before destroying anything.
Instructure said the quiet part out loud in its own statement. "While there is never complete certainty when dealing with cyber criminals..." That is a company saying it paid for peace of mind it cannot verify.
The hard truth is that paying a ransom is sometimes the least bad option for the institution that paid. It almost always makes things worse for whoever is targeted next.
What this means for South Africa specifically
South Africa did not dominate the headlines on this one. The US absorbed 94.6% of affected institutions. Australia and the UK soaked up most of the coverage. But the breach hit 50 countries, and at least one South African institution sat squarely inside it.
Wits University confirmed the breach through its communications manager Shirona Patel on 8 May 2026. In a formal statement, Patel said Instructure had notified Wits that student and staff names, email addresses, student numbers, and Canvas inbox conversations may have been compromised. Wits urged students to be alert to phishing attempts and suspicious emails. Canvas, which Wits calls Ulwazi, was restored and learning continued as scheduled.
That was the right response. Wits confirmed, communicated, and gave students specific guidance. The question for other South African Canvas users is what they have done.
Saving Grace Education Group adopted Canvas in late 2025. As of 12 May 2026, no public statement from them has been found. Any other South African institution using Canvas, whether confirmed publicly or not, sits in the same position.
Under POPIA, the responsible party is the entity with the direct relationship to the data subject. That is the local institution, not Instructure. If your organisation processed personal information through Canvas and has not communicated with affected individuals, that is a potential compliance gap. The Information Regulator can be reached at inforegulator.org.za. For a plain-language walkthrough of section 22 timelines and what counts as a notifiable breach, see our POPIA data breach notification guide.
The real risk that survives the ransom deal
Instructure's claim that the data was destroyed is, legally and practically, unverifiable. ShinyHunters told them so through shred logs. ShinyHunters has, in previous operations, kept data after claiming otherwise.
Even if the data was genuinely destroyed, it was already accessed. It sat in the hands of a criminal group for roughly 17 days. During that window, it could have been copied, sampled, or sold. The shred log proves destruction of the files ShinyHunters chose to show. It proves nothing about copies.
What this means practically. Your name, student number, institutional email address, and any private messages you sent through Canvas between late April and 7 May 2026 should be treated as compromised. Not possibly compromised. Treated as compromised. That posture will protect you. Waiting for a status page to tell you otherwise will not.
Three things to do right now
- Change your Canvas password on a clean device. Not the phone you use for everything else. If that password exists anywhere else, banking, Gmail, WhatsApp, change it everywhere.
- Enable multi-factor authentication on your institutional email and every account connected to it. This is the single most effective thing you can do to survive a credential stuffing attack.
- Be suspicious for the next 60 days of any message that knows your student number, references your actual course, or arrives from an address that looks close to your university's domain. That is not a random phishing attempt. That is targeted.
If you are a Canvas user in South Africa, this is the week to act
Ubuntu Guard's free Cyber Toolkit includes a step-by-step account security guide built for exactly this kind of exposure. It walks you through changing credentials safely, enabling MFA on the platforms South Africans actually use, and setting up alerts so you know when your details appear in a new breach. No sign-up required. Use the Secure Your Accounts tool at ubuntuguard.co.za/cyber-toolkit.
Reach us at [email protected].
Sources
- Inside Higher Ed: Instructure Pays Ransom to Canvas Hackers (Published: 11 May 2026)
- The Register: Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline (Published: 12 May 2026)
- CyberScoop: Instructure claims hackers returned stolen Canvas data (Published: 12 May 2026)
- Wikipedia: 2026 Canvas security incident (Live-updating)
- Halcyon: ShinyHunters extortion campaign analysis (Accessed: 2026)
- Rescana: ShinyHunters Canvas LMS breach analysis and TTPs (Accessed: 2026)
- WRAL: Wake County / PowerSchool ransom precedent reference (Published: 2024)
- Information Regulator South Africa: POPIA reporting obligations (Published: 2024-2026)
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za