How ShinyHunters hacked the world's biggest universities

Smashing Security1h 4mMay 13, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “How ShinyHunters hacked the world's biggest universities” inside PodZeus.

AI-Generated Summary

This episode of Smashing Security dives into the massive breach of Canvas, the widely used educational platform, by the hacker group Shiny Hunters, which compromised 275 million records across nearly 9,000 institutions, including all Ivy League universities. The breach began in April 2026 when Instructure, Canvas’s parent company, detected suspicious activity but failed to fully secure the system. Despite deploying so-called 'security patches,' the hackers returned on May 7th—during final exams—defacing login pages and exposing the failure of containment. The root cause was a poorly secured 'Free for Teachers' account system, which allowed anyone with a web browser to create an account without verification. Instructure eventually shut down the program and later confirmed a secret ransom agreement with Shiny Hunters, though the payment amount and data destruction verification remain unclear. The episode also explores a sophisticated financial scam using deepfakes of a well-known economist to promote fake stock tips via Facebook and WhatsApp, leading victims to fraudulent crypto platforms that steal both money and personal data. Finally, guest Mike Nichols from Elastic discusses the transformative role of AI in cybersecurity, arguing that while attackers are using AI to automate and scale attacks, defenders can use AI agents to reduce alert fatigue, enhance detection, and improve response—provided they implement proper guardrails and human oversight. The episode concludes with a lighter note on a French academic who fabricated an entire academic award system, highlighting the growing challenge of verifying truth in the digital age.

Key Takeaways
1

The Shiny Hunters breach exploited a 'Free for Teachers' account system with no verification, allowing hackers to gain persistent access to Canvas and compromise 275 million records.

2

Instructure’s failure to properly contain the initial breach and the ineffective 'security patches' allowed hackers to return and deface systems during final exams, disrupting students’ lives.

3

The use of deepfakes and fake financial experts on social media is now a major vector for investment scams, often leading victims to fraudulent crypto platforms.

4

AI is reshaping security operations centers—not replacing them, but enabling analysts to focus on strategic decision-making by automating alert triage and analysis.

5

Defenders must implement AI with strong guardrails, human oversight, and secure-by-design principles to avoid creating new attack surfaces through autonomous agents.

…and 1 more takeaway available in PodZeus

Chapters
0:00
10 min

The Shiny Hunters Canvas Breach: A Global Educational Catastrophe

If you give anyone in the world an account on your production system with no verification, this free for teacher signal, just tick in a box saying, yeah, I'm a teacher. What you actually had was a free for anyone with a web browser, free for anyone which includes that small proportion of people who might be interested in scurrying off with terabytes of your data.

Highlight
10:00
15 min

The Anatomy of a Deepfake Financial Scam

The group was full of people posting about how they'd made money from this because their stock prices went up. These people didn't exist. They were fake profiles run by the ringleaders of the campaign who were in this WhatsApp group just to generate trust in the system.

Highlight
25:00
25 min

AI in Cybersecurity: The New Frontier of Defense and Attack

The cost of developing an attack is extremely low and the sophistication of developing an attack is low. Which means that now cyber criminals and other groups that typically didn't have that kind of sophistication of a nation state have that power now. And that makes every CISO now have to worry about being patient zero.

Highlight
50:00
17 min

The Human Element: Trust, Verification, and the Future of Security

The episode concludes with reflections on the erosion of trust in digital spaces—from fake academic awards to deepfakes and scam platforms. Mike Nichols emphasizes the need for transparent, trustworthy AI with human-in-the-loop controls. The episode ends with a lighter pick: a French academic who invented an entire fake award system, underscoring how easy it is to fabricate credibility in the digital age.

High-Impact Quotes
The cost of developing an attack is extremely low and the sophistication of developing an attack is low. Which means that now cyber criminals and other groups that typically didn't have that kind of sophistication of a nation state have that power now. And that makes every CISO now have to worry about being patient zero.
Mike Nichols48:28
Viral: 90.0
The real security crisis is no longer human users. It's the bots acting on their behalf.
Mike Nichols4:03
Viral: 88.0
If you give anyone in the world an account on your production system with no verification, this free for teacher signal, just tick in a box saying, yeah, I'm a teacher. What you actually had was a free for anyone with a web browser, free for anyone which includes that small proportion of people who might be interested in scurrying off with terabytes of your data.
Graham Cluley20:16
Viral: 85.0
Speakers

Host

Graham Cluley

Guests

Danny PalmerMike Nichols
Topics Discussed
Educational Data Breach95%AI in Cybersecurity92%Deepfake Scams90%Ransomware and Extortion88%Security Operations Centers87%Social Media Fraud85%Cryptocurrency Scams83%Zero-Trust Security80%
People & Brands

Graham Cluley

person

30xPositive

Danny Palmer

person

25xPositive

Shiny Hunters

other

18xNegative

Instructure

organization

15xNegative

Canvas

product

14xNegative

Mike Nichols

person

12xPositive

Elastic

organization

8xPositive

Vanta

organization

6xPositive

CoreView

organization

5xPositive

Florent Monteclair

person

4xNegative

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “How ShinyHunters hacked the world's biggest universities” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime