# Will Instructure be subject to another major hack before September 1, 2026?

**Predict**: Follow

**Chance**: 15%  
**5% this week**

## Top Key Factors

1. **Copycats may target Instructure after breach**  
   Likelihood increases by 20

2. [**Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure**](https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure)  
   Likelihood increases by 10

3. **CrowdStrike is hardening Instructure's security**  
   Likelihood decreases by 20

---

**Comments**  
**User:** [jordan1casady](/content/accounts/profile/301871/index.html)  
**Date:** 2 weeks ago (May 28, 2026)

> I’m at **22%**.  
> The question is whether Instructure gets hit by another major hack, but I think the key issue is whether the remaining post-breach risk stays inside Instructure/Canvas itself or shifts into the surrounding school ecosystem.  
> The main thing I’m watching is whether there is still an exploitable Instructure-controlled path large enough to meet the question’s “major hack” threshold. After the recent Canvas incident, I expect a lot of the pressure to move outward first: school-side integrations, API keys, SSO setups, phishing, third-party tools, and institution-level cleanup problems.

> ...

---

**User:** [WasteTimeContinuum](/content/accounts/profile/271410/index.html)  
**Date:** 3 weeks ago (May 24, 2026)

> Initially, I incorrectly framed this as implying another [ShinyHunters](https://en.wikipedia.org/wiki/ShinyHunters) strike. My knee-jerk reaction was to go to 25–30% on this one, because [Instructure](https://en.wikipedia.org/wiki/Instructure) has been breached [twice](https://www.theregister.com/security/2026/05/12/double-canvas-intrusion-confirmed-as-shinyhunters-resets-leak-deadline/5238361) in eight months, paid a rumored $10M ransom, and just had 275 million records and 3.65TB of data walk out the door.

> ...

---

**User:** [darkives](/content/accounts/profile/103907/index.html)  
**Date:** May 14, 2026

> Thanks for the question! I made a few small edits.

---

## Key Factors Summary

- **Copycats may target Instructure after breach** (Increases Likelihood: 20)  
- **CrowdStrike is hardening Instructure's security** (Decreases Likelihood: 20)  
- [**Education Sector in the Crosshairs: ShinyHunters' Extortion Campaign Against Instructure**](https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure) (Increases Likelihood: 10)

---
