Eight months. Nobody noticed

It was finals week.

A professor at Colorado State logged into Canvas to post a makeup exam. What loaded on her screen was not her course page.

Shiny Hunters had been inside Instructure’s environment for eight months by then.

In September 2025, they used Canvas as an access path into the University of Pennsylvania. Donor records. Internal memos. Most of the press called it a Penn story. Instructure treated it as a Penn problem. Neither framing was right.

Penn was just where they tested the approach.

By May 2026: 275 million records. 8,809 institutions. 50 countries. Every student medical accommodation request. Private advisor conversations. Financial aid details from eight Ivy League universities.

The entry point was not a zero-day.

It was a Free-For-Teacher account.

Free tier. Provisioned outside the institution’s identity provider. No offboarding workflow. No monitoring. Not in any directory the IT team was watching.

An account nobody was watching – for eight months.

What stood out to me was not the ransom demand.

I have spent years inside Active Directory and Entra ID environments. When I read the post-breach analysis, one thing kept pulling my attention: how long the access window was open before anyone noticed – and why.

Eight months!

The mean time to identify a breach is 181 days – about six months. The Canvas attackers sat comfortably inside that window.

The reason no system flagged them is straightforward. The accounts they compromised were not in the monitored directory. Separate tier. Separate process. Nobody had drawn a line connecting the two.

I do not know whether Instructure’s security team missed signals or simply did not have the tooling to see them. Both are entirely plausible. But the outcome is the same either way: eight months of access, 275 million records, and an organization paying a ransom to a group it had already paid once before.

This pattern is not unusual.

Unmanaged accounts. Credentials that exist in one system but not the monitored directory. I have seen this in almost every AD and Entra ID environment I have worked in.

Contractors provisioned and never offboarded. Acquisitions that brought in a parallel user base nobody fully reconciled. Guest accounts from a project that ended two years ago.

None of this is exotic. It is just very common to overlook.

The question the Canvas breach raises is not whether this could happen to your organization. It is whether you would know if it already had.

#CyberSecurity #IdentitySecurity #ActiveDirectory #DataBreach #Unmonitored