THE WIRE · UPDATED 4:53 PM MDT No story is too small.
News

Hacker claims theft of 280 million records from 8,800 schools

AI-written from public sources Written by Utah News AI and quality-checked before publishing.
An open, broken padlock resting on an empty wooden school desk in a sunlit, vacant classroom, symbolizing a breach of security and loss of privacy in educational institutions.
Photo via AI illustration
A hacker has claimed to have stolen 280 million records belonging to students and staff from over 8,800 educational institutions following a breach at Instructure. The extortion gang ShinyHunters claims responsibility for the attack on the company known for its Canvas learning management system.

Key takeaways

  • ShinyHunters claims theft of 280 million records from 8,809 educational institutions.
  • The breach at Instructure exposed names, email addresses, and private messages.
  • Data was allegedly stolen using Canvas data export features and APIs.
  • Institutions including CU Boulder, Rutgers, and Tilburg University have issued statements regarding the breach.

The hacker responsible for a breach at education technology company Instructure claims to have stolen 2CO million records tied to students and staff from 8,809 colleges, school districts, and online education platforms.

The ShinyHunters extortion gang has claimed responsibility for the attack. The threat actors published a list of impacted institutions, sharing record counts per institution that range from tens of thousands to several million per institution.

Instructure, which provides the cloud-based Canvas learning management system used for managing coursework and communication, disclosed it was investigating a cyberattack last Friday. The company later revealed that the breach exposed users' names, email addresses, and private messages.

The threat actor claims the data theft was achieved using Canvas data export features, including user APIs, provisioning reports, and DAP queries. According to the hacker, hundreds of gigabytes of enrollment data, messages, and user records were harvested.

Various universities have issued statements regarding the incident. The University of Colorado Boulder stated it is aware of a nationwide data breach involving Instructure and noted that it is a reported event affecting multiple institutions.

Rutgers indicated that while they have not been notified of any direct impact to their campus, Canvas remains operational for faculty, staff, and students. Tilburg University stated an investigation is underway to determine if student or staff data was impacted and noted that further questions have been submitted to the supplier.

Article details

CategoryNews
ToneNeutral
SourceAI Generated