Full Report
A data breach involving St. Petersburg College was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: ShinyHunters Compromise of St. Petersburg College via Instructure Canvas
## Executive Summary
In May 2026, St. Petersburg College was identified as a victim of a data breach orchestrated by the threat actor group ShinyHunters. The incident targeted the Instructure Canvas learning management system, resulting in the exposure of basic account details for students and staff. While no financial data was reported stolen, the breach is classified as medium severity due to the high risk of subsequent phishing and social engineering attacks.
## Incident Details
- **Discovery Date:** May 7, 2026
- **Incident Date:** May 2026
- **Affected Organization:** St. Petersburg College (via Instructure Canvas)
- **Sector:** Higher Education
- **Geography:** Florida, United States
## Timeline of Events
### Initial Access
- **Date/Time:** May 2026 (Publicly reported May 7)
- **Vector:** Likely credential stuffing or exploitation of web application vulnerabilities.
- **Details:** The threat actor group ShinyHunters gained unauthorized access to the digital infrastructure supporting the Canvas platform used by Florida educational institutions.
### Lateral Movement
- **Details:** The attackers leveraged access to the Instructure Canvas environment to access databases or administrative interfaces associated with student and staff accounts across multiple counties (Hillsborough and Pinellas).
### Data Exfiltration/Impact
- **Details:** Basic user details and account information for student and staff accounts were exfiltrated. The primary impact is the unauthorized exposure of identity-related data within the educational portal.
### Detection & Response
- **Detection:** The incident was identified following public claims by the ShinyHunters group and subsequent verification.
- **Response:** The college and relevant service providers initiated investigations; users were advised to reset passwords and monitor for suspicious activity.
## Attack Methodology
- **Initial Access:** Credential stuffing or web application vulnerability exploitation.
- **Persistence:** Not explicitly detailed; likely via compromised administrative credentials or session tokens within the cloud platform.
- **Privilege Escalation:** Potential unauthorized access to administrative interfaces.
- **Defense Evasion:** Use of underground forums for data dissemination rather than direct system disruption.
- **Credential Access:** Targeting of user databases and login interfaces.
- **Discovery:** Reconnaissance of third-party cloud-based services and educational platforms.
- **Lateral Movement:** Pivoting within the Canvas multi-tenant environment.
- **Collection:** Automated gathering of basic user account records.
- **Exfiltration:** Transfer of student/staff data to external attacker-controlled infrastructure.
- **Impact:** Information disclosure and heightened risk of secondary social engineering.
## Impact Assessment
- **Financial:** No direct financial theft reported, though potential costs include remediation and increased help-desk volume.
- **Data Breach:** Exposure of basic user details (names, account information) for students and staff.
- **Operational:** Disruption to the trust and security of the learning management ecosystem.
- **Reputational:** Medium; impacts student and staff confidence in the security of third-party educational platforms.
## Indicators of Compromise
- **Network indicators:** None provided in the source (Note: Monitor for traffic to known ShinyHunters-linked domains/IPs).
- **File indicators:** Not disclosed.
- **Behavioral indicators:** Unusual administrative logins or bulk data exports originating from the Instructure Canvas platform.
## Response Actions
- **Containment:** Audit of third-party vendor permissions and temporary suspension of compromised accounts.
- **Eradication:** Revocation of stolen credentials and patching of potential web vulnerabilities.
- **Recovery:** Implementation of mandatory password resets for the affected population.
## Lessons Learned
- **Key takeaways:** Third-party learning management systems represent a significant attack surface for educational institutions.
- **What could have been done better:** Earlier detection of credential stuffing attempts and stricter enforcement of phishing-resistant MFA across all accounts.
## Recommendations
- **MFA Implementation:** Deploy phishing-resistant multi-factor authentication (e.g., hardware keys or FIDO2) for all staff and student accounts.
- **Third-Party Risk Management:** Perform continuous monitoring of third-party software-as-a-service (SaaS) providers and audit permissions using the principle of least privilege.
- **User Training:** Conduct social engineering awareness training to help students and staff identify phishing attempts following data exposure.
- **Credential Hygiene:** Encourage the use of unique passwords through managed password solutions.