Why was Canvas hacked? Identity of the hacker explored as 275 million users impacted

One of the latest news that has caught everyone’s attention is why was Canvas hacked? The recent cyberattack has become one of the biggest education-related data breaches in recent years and caused distress among all users.

Reports explain that millions of students, teachers and even institutions across the world were affected after the learning platform, owned by Instructure, was targeted by the hacking group ShinyHunters and the reason was financial extortion.

The group claimed it accessed data connected to nearly 275 million users from around 9,000 schools and universities globally. Reports suggest the attack happened during finals week, which increased pressure on schools already relying heavily on Canvas for assignments, exams and communication.

The hackers allegedly stole names, email addresses, student IDs and a huge number of private messages exchanged on the platform. While Instructure claimed that government IDs, email addresses, financial data and passwords were safe, it already caused panic and distress among users.

More details below.


Why was the educational platform Canvas hacked? Here’s what we know

According to reports, the main reason behind the cyberattack on Canvas was financial extortion. ShinyHunters allegedly carried out what cybersecurity experts call a “pay-or-leak” campaign.

In simple terms, the hackers stole a huge amount of data and then demanded ransom money from Instructure, threatening to leak the information publicly if the company refused to cooperate.

The group reportedly set a deadline date of May 12, 2026 and also started to show ransom messages on some Canvas login pages after the company declined negotiations. Educational platforms like Canvas have a lot of data, and if it gets compromised, users and the company have to face loss.

Experts believe the hackers intentionally disrupted the platform during finals season to create panic and pressure institutions into paying quickly. Reports also suggest the attackers targeted schools directly and encouraged them to negotiate settlements separately.

Also Read: Why did Carly Gregg kill her mother? Horrific details about real life teen murderer, exposed


Who are the hackers behind the Canvas incident?

Reportedly, ShinyHunters is a well-known cybercrime group linked to several major global data breaches over the years. It’s said that this same group is responsible for hacking Canvas and creating panic and pressure on the users.

Rather than traditional ransomware attacks that lock systems completely, the group is more known for stealing databases and threatening companies with public leaks. The hackers allegedly operate as a loose online collective connected to other cybercrime networks.

Not only this, but the group has previously been linked to attacks involving large companies in the tech, gaming and even retail sectors. In the recent cyberattack, ShinyHunters reportedly claimed to have stolen 3.65 terabytes of data.

Right now, the full number of users impacted by this cyberattack is not revealed or independently verified. As mentioned before, this created a lot of stress among users especially when ransom messages were displayed and the group alleged that they had information about many users.

Authorities, including the FBI continue to investigate the breach while affected users are being advised to stay alert for phishing emails and suspicious activity tied to leaked information.


Also Read: Dateline: The Silhouette – A complete timeline of the Debbie Kelly murder case, revisited

Continue exploring SoapCentral for regular updates on breaking news.