Back to Feed
BreachesMay 8, 2026

ShinyHunters got access to Canvas infrastructure from ... "Vishing". Social engineering. WHY IS...

ShinyHunters breach Canvas infrastructure via vishing social engineering attack.

Vendor Watch

Run Canvas?

Get an email when a reviewed story names Canvas, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Threat actor group ShinyHunters gained unauthorized access to Canvas infrastructure through vishing (voice-based social engineering). The attack leveraged human manipulation rather than technical exploits to compromise credentials or systems. This incident highlights the persistent threat posed by social engineering attacks against critical educational technology platforms.

Entities

ShinyHunters (threat_actor)Canvas (product)Vishing / Voice Social Engineering (technology)