Up Headlines

Startup News

Student Data Exposed in Instructure Hack Claims

2 min read
Student Data Exposed in Instructure Hack Claims

A major data breach at education tech firm Instructure is raising fresh concerns about student privacy, after a well-known hacking group claimed responsibility for stealing sensitive information.

The cybercrime gang ShinyHunters says it breached Instructure’s systems and accessed a range of student data. According to both the hackers and the company, the compromised information includes student names, personal email addresses, and even messages exchanged between teachers and students.

This type of data exposure is particularly worrying, as it reveals not just contact details but also private communication within educational platforms.

What Was Stolen?

The hackers reportedly shared samples of the stolen data, giving a glimpse into the scale of the breach. According to reports, the leaked samples included records from two U.S. schools—one in Massachusetts and another in Tennessee.

In the Massachusetts case, the data included messages between students and teachers, along with names, email addresses, and some phone numbers. Meanwhile, the Tennessee dataset mainly contained student names and email addresses.

However, there is a small relief: the sample did not include passwords or other highly sensitive credentials. Instructure also confirmed that certain types of data remained unaffected.

Platform at the Center

The breach appears to be linked to Canvas, Instructure’s widely used learning platform. Canvas is popular among schools and universities for managing coursework, assignments, and communication.

While the exact number of affected institutions is still unclear, the hackers claim the breach could impact thousands of schools. In fact, ShinyHunters shared a list of around 8,800 institutions they say were affected. For comparison, Instructure itself states it serves over 8,000 educational organizations globally.

Big Claims, Unclear Scale

ShinyHunters is also making bold claims about the scale of the breach. On its data leak site, the group alleges that nearly 9,000 schools and up to 275 million individuals—including students, teachers, and staff—may be impacted.

In private communication, a member of the group reportedly said the stolen dataset contains around 231 million unique email addresses.

Still, cybersecurity experts caution that such figures may be exaggerated. Financially motivated hacking groups often inflate numbers to attract attention and pressure victims into paying ransom demands.

Company Response

When asked for details, Instructure’s spokesperson directed inquiries to the company’s official updates page, without addressing specific questions about the breach.

The company has confirmed that some of its services, including Canvas, were temporarily taken offline for maintenance but have since been restored.

Growing Trend of Attacks

This incident is part of a broader pattern. ShinyHunters has been linked to multiple attacks targeting universities and cloud-based services in recent months. Their strategy typically involves stealing large amounts of data and threatening to release it publicly unless a ransom is paid.

As investigations continue, the breach highlights ongoing risks facing digital education platforms—and the importance of stronger cybersecurity measures to protect student data.

Also read : Nadella Signals Microsoft Will ‘Exploit’ New OpenAI Deal

Copyright © Up Headlines. All rights reserved. | Supported by eOffice4U.