Tomorrow
Tomorrow, Wednesday May 6, 2026, two ShinyHunters extortion deadlines expire simultaneously.
The first is against Instructure, the operator of Canvas Learning Management System. The cybercrime collective's "FINAL WARNING — PAY OR LEAK" notice — relayed via BreachForums and observed by Privacy Rights Clearinghouse, Comparitech, and KrebsOnSecurity — cites approximately 3.65 terabytes of data covering an estimated 240 to 275 million records across roughly 9,000 to 15,000 educational institutions. The exfiltration includes billions of student-teacher private messages and Instructure's Salesforce instance. Wayzata Public Schools (Minnesota) was the first identified Canvas customer to warn parents.
Instructure has confirmed exposure of names, email addresses, student identifiers, and inter-user messages. The 3.65-terabyte figure remains a criminal-side claim. The conservative phrase: "tens to hundreds of millions of K-12 and post-secondary student records, including communications between students and teachers, are at imminent risk of public dump." Instructure's second confirmed breach in eight months. The previous incident, in September 2025, exposed approximately 1.7 million records.
The second deadline applies to Cushman & Wakefield, separately disclosed today, May 5, by The Register's Connor Jones. The intrusion is described as vishing-driven — a phone-call social-engineering attack against the company's help desk — with the help-desk-reached credentials used to access the company's Salesforce instance. Cushman & Wakefield is one of the world's largest commercial real estate services firms, with offices in approximately 60 countries and clients across financial services, government, retail, healthcare, and technology sectors. The Salesforce instance reportedly held customer relationship management records, deal pipelines, brokerage communications, and tenant data.
ShinyHunters' contact deadline, per the disclosure: May 6. The same day as Instructure's. Same actor, attributed by The Register's source.
Today, May 5, is the day before.
The Salesforce layer
Salesforce is the single carrier-of-trust SaaS layer where the largest concentration of cross-customer enterprise data sits. Approximately 150,000 customer organizations, per Salesforce's own published reporting, comprising the majority of Fortune 500 companies, hundreds of thousands of K-12 and post-secondary educational institutions, federal and state government agencies, and tens of thousands of nonprofits.
When a single vendor holds the customer relationship data of 150,000 organizations on a shared multi-tenant platform, every novel exploit against the platform — or against a single customer's authentication path to the platform — has the architectural potential to reach every customer simultaneously.
The 2024-2025 ShinyHunters cluster — Snowflake, AT&T, Ticketmaster, Advance Auto Parts, LendingTree, Pure Storage, approximately 165 customers — demonstrated the pattern. The vector then was misconfigured customer Snowflake instances; the data taken belonged to those customers' customers. The May 2026 Instructure and Cushman & Wakefield disclosures are the same pattern at a different vendor: Salesforce as the multi-tenant aggregator; vishing as the path to authentication; customer-of-customer data as the exfiltrated payload.
The architectural lesson from this pattern is structural. The carrier-of-trust SaaS choice is the single most consequential architectural decision an enterprise makes, because it determines the blast radius of every novel exploit. An enterprise that trusts its customer relationship data to a multi-tenant SaaS platform is, by the architectural test, accepting that an exploit against any one customer of that platform may reach the enterprise's data. An enterprise that operates its own Mailcow, Forgejo, Matrix homeserver, Nextcloud, Mautic, and SuiteCRM has bounded its blast radius to its own perimeter.
The contradiction
The same week the Instructure / Cushman & Wakefield deadlines are converging, regulation in multiple jurisdictions is moving to mandate more ID upload to vendors.
Apple's Declared Age Range API mandatory date is July 1, 2026 — fifty-seven days from today. The API, as currently specified, requires applications targeted at users under 18 to call into Apple's identity infrastructure to retrieve a declared age range for the device user. The mechanism by which the device user's age is established is not selective-disclosure cryptography; it is account-level identity attestation by Apple, with verification logs created at the verification call.
UK Ofcom enforcement reports on Meta, TikTok, YouTube, Snapchat, Roblox, and X were due immediately following the April 30 deadline. The Online Safety Act's age-assurance Section 12 requires platforms to implement "highly effective" age verification. Ofcom's CEO Melanie Dawes, in March 2026 testimony, described the regulation: "Platforms must be highly confident, at the time of access, of users' ages." "Highly confident" has been operationalized as government-issued ID upload, biometric face scan, or comparable identity attestation.
The European Union Digital Services Act and the EU's age-verification reference application. Late April 2026, the EU shipped an open-source age-verification reference application as the technical foundation for the upcoming EU age-verification mandate. UK security consultant Paul Moore, working independently, bypassed the application in two minutes by editing a plaintext configuration file. The EU patched the bypass within twenty-four hours. The reference application was built by skilled engineers under EU funding scrutiny. It was bypassed by a single contract security consultant in two minutes.
The European Digital Identity Wallet. Hard deadline December 24, 2026 — 233 days from today — for member states to provide functioning eIDAS 2.0 wallets. The architecture is, importantly, selective disclosure: the wallet, not the verifier, holds the credentials, and discloses only the requested attributes. This is the architecturally-correct mechanism. But the per-jurisdictional implementation maturity varies, and the regulatory framework around the wallet does not require third-party verifiers to accept selective-disclosure proofs in lieu of full ID disclosure.
Australia's under-16 social media ban. Effective late 2026, requires platforms to verify that users are 16 or older. Verification mechanism unspecified.
France SREN. Specifies age verification for adult content, with mechanisms ranging from credit-card validation to government-issued ID upload to biometric attestation.
State-level US age-verification laws. Texas SB 2420, enjoined December 23, 2025 by the Fifth Circuit, mandated ID upload for adult-content access. California, Florida, Mississippi, Tennessee, Virginia, and other states have passed comparable statutes.
The pattern in each jurisdiction: age verification, in the regulatory specification, has been operationalized as ID upload to a third-party vendor, with verification logs created at the verification call. The vendor is the operator pathway. The verification log is the surveillance vector.
The vendor
On February 16, 2026, Discord's age-verification vendor Persona had its government-facing operations dashboard exposed publicly. The dashboard displayed customer information, integration configurations, and verification logs. The exposure was discovered by a third-party security researcher and disclosed via responsible disclosure. Persona's customer base includes Discord (~300 million users), and a number of other consumer-platform clients.
The architectural significance: the vendor that Discord relies on to verify the ages of its users — meaning, to hold the government-issued ID documents and the cryptographic results of identity verification — had its operations dashboard exposed without authentication for an undisclosed period. The age-verification vendor is one more vendor in the carrier-of-trust SaaS supply chain, and is subject to the same operator-pathway compromise that affects every other carrier-of-trust SaaS.
On February 24, 2026, the UK Information Commissioner's Office fined Reddit £14.47 million ($18.4 million) over its handling of age-verification data. The specific finding: Reddit's age-verification mechanism collected and retained government-issued ID images beyond the legitimate verification window, in violation of UK GDPR Article 5(1)(e) — the storage limitation principle.
On April 23, 2026, Proton CEO Andy Yen, in a coordinated round of interviews including The Guardian, Bloomberg, and TechCrunch, characterized the proliferating age-verification mandates as the "death of anonymity online." Yen's specific argument:
"Age verification as currently being proposed in country after country would mean the death of anonymity online. The architecture is structurally indistinguishable from a database of every adult's identity documents and the services they accessed."
Yen's prescription: regulators must specify selective-disclosure credentials as the verification mechanism, not vendor-side identity attestation.
The architectural counter
The architectural counter to ID-upload regulation is a stack of cryptographic primitives shipping today.
W3C Verifiable Credentials version 2.0, ratified March 2026, supporting selective disclosure via BBS+, BBS24, and JWP signatures. A user holds a credential issued by an authority (a state DMV, a national identity authority, a university registrar). The user can disclose specific attributes from that credential — the attribute "age is at least 18" — without disclosing the underlying credential. The verifier learns only the disclosed attribute.
Decentralized Identifiers version 1.1, supporting did:web, did:peer, did:ion, did:key methods. The DID is the cryptographic identifier the user controls; the resolution is decentralized; the method-specific resolution does not require a single registry.
eIDAS 2.0 European Digital Identity Wallet. Hard deadline December 24, 2026 (233 days from today). The wallet, not the verifier, holds the credentials, and discloses only the requested attributes. Mandated for all 27 EU member states.
BBS+ signature suite. IETF standardization in progress. The cryptographic primitive that enables a single signed credential to be selectively disclosed: the verifier verifies the signature; the disclosure scope is determined by the user.
Privacy Pass anonymous tokens. RFC 9577, published October 2024. The verifier cannot link separate verifications back to the same user. Apple, Google, and Cloudflare are the three current production deployers.
Apple Wallet mobile driver's license (mDL), per ISO/IEC 18013-5, in thirteen states plus Puerto Rico. The phone holds the credential. Selective disclosure is implemented at the phone-to-verifier protocol layer. The user can disclose "over 21" without disclosing the underlying date of birth, photo, address, or driver's license number.
Google Wallet US states ID. Comparable architecture to Apple Wallet mDL.
IETF SCITT supply-chain integrity transparency. The cryptographic foundation for verifying claims about software supply chains without uploading the underlying software.
The stack ships today. The regulation landing in late 2026 should specify selective disclosure as the verification mechanism. Where the regulator does not specify it, vendors should adopt it voluntarily.
The state-level parallel
On April 21, 2026, the American Civil Liberties Union and Common Cause filed a federal lawsuit against the Department of Justice challenging a first-ever federal aggregation of all 50 states' voter rolls into a single federally-controlled database. The aggregation includes Social Security Numbers and dates of birth for the approximately 168 million registered U.S. voters. A senior DOJ privacy officer resigned April 3 over the project.
The architectural significance is the same as the Salesforce concentration. A single perimeter for the most politically-sensitive personal data of the entire voting public is, by the architectural test, a single compromise away from a 168-million-record disclosure of Social Security Numbers and dates of birth. A compromise by foreign intelligence service, criminal extortion group, or insider would render the data of 168 million Americans permanent and irreversibly distributed.
The architectural counter is federalism-by-design. State voter rolls ephemerally synchronized for election integrity (de-duplication, address-change tracking) but no permanent federal aggregation is created. Cryptographic protocols for ephemeral comparison — Private Set Intersection, multi-party computation — achieve the policy goal of cross-state de-duplication without the architectural risk.
The same week the Instructure / Cushman & Wakefield deadlines converge, the federal government is centralizing voter rolls — and it is being challenged in federal court by civil society over precisely the architectural-risk concern this edition is about.
The healthcare floor
Q1 2026 documented 201 hospital ransomware attacks in the United States alone, per Comparitech / KrebsOnSecurity / Privacy Rights Clearinghouse aggregations. Qilin is the leading ransomware family. Named victims still in active disclosure phases include University of Maryland Medical System, Insight Hospital Chicago, and Hospital Caribbean Medical Center.
HHS Office for Civil Rights' April 23 quadruple HIPAA settlement totaled approximately $1.7 million, covering 427,000 patients. Notably, one component of the settlement — Star Group / SG Health Plan, $245,000 — was an unusual hit on an employer-sponsored health plan, signaling that OCR is extending HIPAA enforcement to plan sponsors and not just covered-entity providers.
42 CFR Part 2, the federal rule governing substance-use-disorder treatment record privacy, became civilly enforceable on February 16, 2026. The rule is now binding with civil penalties. The Naviance / PowerSchool $17.25 million wiretap settlement entered claims phase, covering more than 10 million students.
The healthcare and education verticals are the two most acute current proof points of vendor-custody-as-trap. The architectural counter at this layer: minimum-necessary collection, selective-disclosure credentials for clinician access, segregated and offline backups, OS-level immutable recovery infrastructure, FIDO2 hardware authentication for clinician workstations.
The supply chain follow-on
April 22, 2026: the Bitwarden-CLI cascade — via the Checkmarx KICS Docker Hub takeover — reached production. The novel feature: the malicious Bitwarden-CLI payload was the first publicly-observed in-the-wild attack targeting Model Context Protocol server configurations.
The Bitwarden payload, when installed, scanned for .cursor/mcp.json, .claude/settings.json, and analogous AI-coding-assistant MCP server configuration files, and replaced legitimate MCP server endpoints with adversary-controlled endpoints. Subsequent invocations of the user's AI coding assistant routed through the adversary-controlled MCP server, exfiltrating prompts and code-completions.
The architectural significance: the federated Model Context Protocol architecture that should be the user-side counter to npm/PyPI/Docker-Hub centralized package surfaces is now itself a target. The first publicly-observed MCP-config attack closes the rebuttal "federated MCP is structurally safer than centralized package registries." Federated MCP is structurally different, but it is now also under attack. The user-side response: cryptographic-signature verification of MCP server endpoints, reproducible MCP server builds, per-organization MCP cadence with audit logging.
RightsCon Lusaka
Today, May 5, 2026: RightsCon 2026 Lusaka — the global digital-rights convening hosted annually by Access Now since 2011 — was cancelled days before opening after the Zambian government, under reported pressure from the People's Republic of China, demanded that Access Now exclude Taiwanese delegates from the convening. Access Now refused. The convening was cancelled. The Electronic Frontier Foundation, Human Rights Watch, and Front Line Defenders went on record.
The architectural significance to this edition: civil society's primary global digital-rights convening venue has been erased by Chinese pressure on the host government. RightsCon has been the venue where Tor Project deployed circumvention transports for high-risk users; where Citizen Lab presented Pegasus disclosures; where Apple, Google, Meta, Signal, Proton, and Tuta met privacy researchers; where the Global Encryption Coalition coordinated.
The cancellation does not eliminate the work, but it eliminates the in-person convening. Civil-society coordination tools that do not depend on a single host country — federated, peer-to-peer, asynchronous Matrix homeservers, Forgejo, Mailcow, Jitsi, Briar — become the architectural fallback. The same primitive stack that protects user-side custody of identity also protects civil-society coordination from single-host-country disruption.
Post-quantum
March 6, 2026: Signal began enforcing the post-quantum SPQR / Triple Ratchet protocol on new account registrations. The first hard cut of a non-post-quantum messenger path by a major consumer messaging platform. signal-cli accounts (the unofficial command-line client widely used for bots, automated workflows, and bridge integrations) were mass-de-registered. Many bots broke. The architectural significance is that forcing migration to post-quantum cryptography by hard-cutting non-PQ paths is a substantively different deployment posture than offering opt-in PQ extensions.
March 30, 2026: Google Quantum AI, with Justin Drake (Ethereum Foundation) and Dan Boneh (Stanford), published a paper demonstrating a roughly 20× reduction in the qubit count required to break Bitcoin's secp256k1 elliptic curve discrete logarithm. The new lower bound: fewer than 500,000 physical qubits, with attack runtime measured in minutes once such hardware exists. Bitcoin's secp256k1 secures approximately $2 trillion in market capitalization. The migration to post-quantum signatures requires consensus protocol changes; the BIP process for post-quantum migration is in active discussion.
April 21, 2026: a Coinbase / Stanford / Ethereum Foundation paper confirmed that ZK rollups (Aleo, Aztec, Railgun) are information-theoretically quantum-immune by design. The signature scheme over the rollup's settlement layer can be migrated to post-quantum primitives without changing the rollup's cryptographic guarantees.
The PQ-ready architectural counter for messaging, transport, and signatures: Signal SPQR, iMessage Contact Key Verification, Apple Wallet's PQ-ready signing infrastructure, Cloudflare's >60% hybrid ML-KEM TLS deployment, Akamai's January 31 default-PQ. FIPS 140-2 sunsets September 21, 2026, the federal procurement cliff.
The one-week arc
Today (May 5) sits in a particular cadence of clocks.
- Tomorrow (May 6): Instructure ShinyHunters deadline. Cushman & Wakefield ShinyHunters deadline.
- May 11-22: Trail of Bits audit of Monero FCMP++.
- May 14: Bartz v. Anthropic $1.5 billion settlement final fairness hearing. Digital euro PSP applications close.
- May 15: FISC March 17 declassification deadline (Section 702 reform).
- June 12: Section 702 sunset.
- June 30: Mexican CURP Biométrica deadline (127 million mobile lines).
- July 1: Apple Declared Age Range API mandatory date.
- August 2: EU AI Act GPAI go-live.
- September 11: EU CRA 24-hour vulnerability disclosure to ENISA.
- September 21: FIPS 140-2 sunset.
- December 24: EUDI Wallet hard deadline.
Each clock is an institutional, regulatory, or protocol deadline. The user-controlled primitive stack — the same stack named in the prior three editions — does not depend on which way these clocks run.
Closing
Tomorrow's deadline is not the moment of breach. The breach already occurred. Tomorrow is the moment of distribution.
275 million records of K-12 and post-secondary student data, plus billions of student-teacher private messages, plus the customer relationship data of one of the world's largest commercial real estate firms, all sit on Salesforce instances that today are simultaneously under extortion from the same actor. Today is the day before. ShinyHunters' "FINAL WARNING — PAY OR LEAK" notice cites May 6.
The same week, the regulatory architecture in multiple jurisdictions is mandating more ID upload to vendors. Apple Declared Age Range API. UK Ofcom enforcement. EU age-verification reference app. Australia's under-16 ban. France SREN. State-level US laws. The vendor that holds the ID is the vendor that gets compromised. The architectural counter — selective-disclosure credentials with user-held keys — exists in the W3C, IETF, and NIST standards, ratified, deployed, and shipping today. The regulatory specification has not yet caught up.
The user-controlled primitive stack named in the prior three editions — open clients with user-held keys, open-firmware hardware, FIDO2 authentication, censorship-resistant transports, privacy-preserving cryptocurrencies, local-inference AI, federated identity with selective disclosure, self-hosted services — has, by the architectural property "no upload," no surface that can be turned by the four turn-mechanisms named in edition 03 (corporate retreat, institutional compulsion, state coercion, forensic compromise) and no surface that can be turned by the vendor-custody-as-trap mechanism named in this edition.
Don't upload identity to the age-verification vendor. Disclose age cryptographically.
Don't upload student records to the SaaS LMS. Host the LMS on user-operated infrastructure.
Don't upload customer relationship data to a single multi-tenant platform. Segment per organization.
Don't upload medical records to a single EHR vendor. Hold the records under HIPAA's minimum-necessary rule.
Don't upload transactional data to a stablecoin operator. Settle in user-custody currencies.
Don't upload AI prompts to a third-party log. Run inference on user-controlled compute.
Don't upload state voter rolls to a federal database. Synchronize ephemerally with cryptographic comparison.
Don't upload.