Two hundred seventy-five million
The number is simple. The scale is not.
On April 25, 2026, the cybercriminal group ShinyHunters exploited a vulnerability in Instructure's Free-For-Teacher tier of Canvas, the learning management system used by universities, school districts, and educational ministries in approximately 100 countries. The breach yielded 3.65 terabytes of data: names, email addresses, student identification numbers, and private messages between teachers and students across 8,809 institutions.
Instructure's first public disclosure came May 1. By May 7, ShinyHunters had escalated: they defaced approximately 330 institutional Canvas login portals with ransom demands, breaching the system a second time. The attack landed during finals week. The University of Pennsylvania, Auburn University, and hundreds of other institutions could not administer exams. CNN described students "stranded" mid-semester.
On May 11 — one day before ShinyHunters' deadline to publish the stolen data — Instructure reached a ransom agreement. The hackers reportedly returned the data and provided "shred logs" as digital confirmation of its destruction. The ransom amount has not been disclosed.
Two hundred seventy-five million is approximately the population of Indonesia. It is more than every person who filed a US tax return in 2025. It is the largest educational data breach in recorded history, by an order of magnitude.
The platform you cannot leave
Canvas is not a consumer product. Students do not choose it. Institutions choose it, and students are required to use it — to submit assignments, receive grades, communicate with instructors, access course materials, take exams. There is no opt-out mechanism. There is no alternative path through the degree.
This is the structural property that distinguishes mandatory-platform breaches from consumer data breaches. When Equifax was breached in 2017 (147 million records), consumers could not have "opted out" of having credit — but they could theoretically freeze their files, switch bureaus, or sue. When Canvas is breached, the 275 million affected users had no prior choice, no concurrent alternative, and no exit. The breach happened to them through a system they were compelled to use by the institution that serves them.
The mandatory platform has a structural property that inverts normal market dynamics. When a consumer product is breached, users can leave and the company faces reputational and revenue consequences. When a mandatory platform is breached, users cannot leave and the company faces no user-driven market discipline. The only consequences come from regulators, litigation, or contractual penalties with the institutions — none of which operate at the speed of a data breach.
ShinyHunters understood this leverage. When initial extortion of Instructure failed, the group pivoted to school-by-school pressure: individually defacing university login portals, then threatening each institution separately. The mandatory platform's users — students in the middle of final exams — became the pressure mechanism.
Shred logs
Instructure paid the ransom and received "shred logs" — records purporting to show that ShinyHunters deleted the stolen data from their systems.
The cybersecurity consensus on shred logs is unambiguous. Digital data can be copied to any number of systems at any point between exfiltration and claimed deletion. A shred log proves that data was deleted from one specific storage location. It cannot prove the data was not copied to another location, shared with a third party, sold before the ransom was paid, or retained on a system the shred log does not cover. The operation to verify deletion would require access to every system the attacker controls, which the attacker will not provide.
The FBI's position remains that organizations should not pay ransoms. Payment incentivizes future attacks, funds criminal operations, and provides no guarantee of data destruction. Instructure's decision to pay — reportedly one day before the publication deadline — was made under the pressure of 275 million records, finals-week disruption across thousands of institutions, and the escalating school-by-school defacement campaign.
The precedent is the forward-looking concern. If ransom payment produces a satisfactory outcome for Instructure and its institutional clients, every mandatory platform in education, healthcare, and government becomes a candidate for the same playbook: breach the platform users cannot leave, extort the operator under time pressure, and collect payment in exchange for a promise that cannot be verified.
Inside Higher Ed's headline captured the dynamic precisely: "Pay or Leak."
The Free-For-Teacher door
The vulnerability that enabled the breach was in Canvas's Free-For-Teacher tier — a free account type designed to let individual teachers try Canvas without institutional procurement. The Free-For-Teacher tier exists in the same infrastructure as the institutional tier. The vulnerability allowed ShinyHunters to move from the free tier into the broader Canvas infrastructure, accessing data across all 8,809 institutional deployments.
The architectural lesson is that a free-tier entry point in a mandatory-platform ecosystem creates an attack surface with no proportional relationship between the access point and the data behind it. The Free-For-Teacher tier serves individual educators. The data behind it serves 275 million students at institutions that collectively pay millions in licensing fees for security assurances they believed the platform provided.
The second breach on May 7 — after Instructure's May 1 disclosure — demonstrated that the initial containment was incomplete. ShinyHunters accessed the system again, defaced login portals, and injected ransom messages directly into the user interface. Students attempting to log in for final exams saw the attackers' demands instead of their coursework.
The pattern
Canvas is not the only mandatory platform breached this month. The pattern extends across every institutional layer where users have no choice.
Employers. A study published May 21 by Northeastern University's Data Culture Group — led by Stephanie Nguyen, former chief technologist at the Federal Trade Commission — tested nine "bossware" employee monitoring platforms. All nine shared identifying worker data with third parties. All nine transmitted workers' online activity, including IP addresses, device information, and web page visits, to more than 145 external domains. The recipients include Google, Facebook, LinkedIn, Yandex, and AppLovin, a mobile advertising platform with a market capitalization exceeding $100 billion.
Employers require workers to install these platforms. Workers have no meaningful consent mechanism — refusal means job loss. The monitoring data flows from employer mandate to employee device to advertising network, with the employee as the product at every stage. The EU banned emotion recognition in employment settings effective February 2, 2025. The United States has no equivalent restriction.
Government. The Department of Government Efficiency copied the Social Security Administration's NUMIDENT database — containing every Social Security number application ever filed, covering more than 300 million Americans — to a cloud server without following required security protocols. A whistleblower, former SSA chief data officer Charles Borges, alleged the data was placed on an unauthorized Cloudflare instance. The SSA's own internal risk assessment estimated a 35-65 percent probability of a "catastrophic adverse effect" data breach resulting from the access practices.
The Supreme Court ruled 6-3 to allow the access. The Department of Justice admitted to "inaccuracies and misrepresentations" in court filings about the scope of DOGE's data access. At least twelve federal lawsuits allege violations of the Privacy Act of 1974.
Americans cannot opt out of Social Security. The NUMIDENT database exists because the government mandates participation. When the mandatory system's database is copied to an unauthorized server with a 35-65 percent catastrophic breach probability, the 300 million people whose data is at risk had no prior choice and have no recourse.
AI search. Perplexity AI, a search tool marketed as privacy-respecting, allegedly embedded Meta Pixel, Google Ads, Google DoubleClick, and Meta's server-side Conversions API directly in its code. A 135-page class action filed March 31 in the Northern District of California alleges that user conversations — including prompts, responses, email addresses, IP addresses, and device information — were transmitted to Meta and Google for advertising targeting. The tracking allegedly occurred even when users activated Perplexity's "Incognito mode," which the lawsuit calls a "sham."
The Meta Conversions API operates server-to-server. No browser-based privacy tool — no ad blocker, no tracking protection, no VPN — can detect or prevent the transmission. Users who took every available privacy precaution were allegedly tracked through a mechanism invisible to their defensive tools.
Developer tools. The TrapDoor supply chain campaign, first observed May 22, planted hidden instructions inside .cursorrules and CLAUDE.md configuration files using zero-width Unicode characters. These instructions trick AI coding assistants — tools like Cursor and Claude Code — into executing what appears to be a "security scan" that actually harvests credentials, SSH keys, cryptocurrency wallet data, and API tokens. The campaign targeted developers in cryptocurrency, DeFi, and AI communities through 34 malicious packages across npm, PyPI, and Crates.io.
Separately, a poisoned version of the Nx Console VS Code extension — installed by a GitHub employee on May 18 — led to the exfiltration of approximately 3,800 of GitHub's internal private repositories, including Copilot internals, CodeQL tools, and security infrastructure. TeamPCP and LAPSUS$ posted the stolen data for a joint sale at $95,000. The attack originated from a credential stolen through the TanStack npm supply chain compromise seven days earlier — a recursive supply-chain-to-platform breach where each compromise enabled the next.
The structural argument
The common property across these breaches is not a shared vulnerability, a shared attacker, or a shared technology stack. It is a shared architecture: the mandatory platform.
When a platform is mandatory — required by a school, an employer, a government, or the practical necessity of professional tooling — the user cannot leave. The user's continued presence on the platform is not a signal of trust or satisfaction; it is a condition of participation in the institution the platform serves. The breach does not produce the market consequence that disciplines voluntary platforms.
The result is an asymmetry. The attacker's leverage is proportional to the mandate's strength. ShinyHunters understood that finals week at 8,809 institutions created irresistible time pressure. DOGE understood that the Social Security system has no competitive alternative. Bossware vendors understand that employees cannot refuse installation. Perplexity understood that users seeking privacy in an AI tool would not expect server-side tracking invisible to their browser.
In each case, the users' inability to exit is the precondition for the breach's impact.
The architecture that does not require permission
The user-side response to mandatory-platform risk is the same response this publication has been documenting across every domain of internet freedom: architectures where the user holds the keys, the transport does not traverse the intermediary layer, and the platform's breach does not compromise the user's data because the platform never held it.
End-to-end encrypted messaging where the server sees only ciphertext. Self-hosted learning management systems where the institution controls its own data. Federated identity with selective disclosure where the credential holder decides what to share with whom. Local-inference AI where the query never leaves the user's device. Hardware authentication tokens that cannot be phished through device-code flows. Post-quantum cryptographic agility where the protocol stack evolves ahead of the threat.
None of these tools require an institution's permission to deploy. None depend on a mandatory platform's security practices. None produce a data store that an attacker can exfiltrate in a single breach.
The Canvas breach exposed 275 million records because Canvas held 275 million records in a centralized system accessible through a single vulnerability. The architecture that distributes control to the endpoints — where the student holds the key, the school holds the minimum, and the platform never accumulates the 3.65 terabytes that ShinyHunters found — does not eliminate risk. But it eliminates the structural property that made the Canvas breach possible at this scale: one door, 275 million records behind it.
Two hundred seventy-five million had no choice
The mandatory platform is the architecture of compulsion. The student uses Canvas because the university requires it. The worker installs the monitoring app because the employer requires it. The citizen has a Social Security number because the government requires it. The developer uses the IDE extension because the workflow requires it.
At every layer, the mandate creates the centralization, the centralization creates the target, and the breach creates the consequence that no individual user can prevent, mitigate, or exit.
Two hundred seventy-five million students had no choice about whether their data was held by Canvas. They had no choice about whether the Free-For-Teacher vulnerability existed. They had no choice about whether Instructure paid the ransom. They have no way to verify whether the shred logs mean anything.
The architecture that would give them a choice does not require their institution's permission. It requires the transport layer that does not route through the mandatory platform. It requires the key that the student holds. It requires the protocol that does not accumulate 3.65 terabytes in a single data store behind a single vulnerability.
The mandatory platform is the problem. The distributed architecture is the answer. The 275 million did not choose the problem. The architecture lets them choose the answer.
URnetwork is a peer-to-peer overlay for censorship-resistant transport. The URnetwork overlay distributes control to the endpoints rather than accumulating it at the platform layer. Users hold their own keys.
https://ur.io
References (16 sources)
References
- Canvas/Instructure cyberattack — Reed Smith advisory
- Instructure reaches ransom agreement with ShinyHunters — The Hacker News
- Canvas hack during finals week — CNN
- Pay or Leak: hackers target big higher ed vendor — Inside Higher Ed
- ShinyHunters escalates Canvas extortion — Infosecurity Magazine
- Canvas × ShinyHunters full intelligence report — Protos Labs
- Workplace monitoring platforms are sharing your data — Northeastern University
- Google, Meta and Microsoft getting worker data from bossware — Digital Trends
- DOGE wanted one database of every American — State of Surveillance
- Whistleblower: DOGE put SSA database on insecure cloud — CSO Online
- Perplexity AI sent your chats to Meta and Google — State of Surveillance
- TrapDoor supply chain attack — The Hacker News
- TrapDoor AI assistant poisoning — Socket.dev
- GitHub confirms breach of 3,800 internal repos — The Hacker News
- 2026 Canvas security incident — Wikipedia
- FTC Cox Media Active Listening settlement — FTC