Instructure, the company behind Canvas LMS used by over 30 million educators and students, has reached an agreement with the ShinyHunters extortion group following a data breach. ShinyHunters claimed to have stolen 3.6TB of data by exploiting cross-site scripting (XSS) vulnerabilities in the Free-for-Teacher environment, which allowed them to hijack authenticated admin sessions. The group also defaced Canvas login portals on May 7 using the same vulnerability. Instructure says ShinyHunters returned the stolen data and provided shred logs confirming its destruction, though the FBI has repeatedly warned that paying ransoms does not guarantee data won't be resold or used for further extortion. This is the second breach Instructure has suffered at the hands of ShinyHunters, following a September 2025 incident involving their Salesforce instance.