Educational infrastructure faces sustained compromise as ShinyHunters escalates Canvas platform attacks affecting millions of North American students. Real estate and healthcare sectors experience significant data exposures through third-party vulnerabilities and ransomware campaigns.
Critical 275M records May 7
Canvas Platform Suffers Multi-Wave ShinyHunters Attack
Instructure/Educational Institutions
ShinyHunters compromised Canvas learning management system affecting approximately 9,000 schools and universities across North America. Attack included defacement of login portals with ransom messages and data theft spanning students, faculty, and staff records.
What it means: Educational continuity disrupted during finals season with credential exposure creating long-term identity theft risks for student populations.
High 500K records May 8
Cushman Wakefield Hit by ShinyHunters Salesforce Breach
Cushman & Wakefield
Chicago-based commercial real estate firm suffered ransomware attack exposing over 500,000 Salesforce records containing client personal information and internal corporate data.
What it means: Commercial real estate transactions and client relationships compromised, potentially affecting property deals and tenant data security.
High Unknown records May 6
Trellix Source Code Repository Compromised
Trellix Cybersecurity
Cybersecurity firm formed from McAfee-FireEye merger disclosed attackers accessed portions of its source code repository. Full extent of customer data exposure remains under investigation.
What it means: Security tool integrity potentially compromised, raising concerns about backdoor implementations in enterprise cybersecurity infrastructure.
Significant Unknown records May 2
San Diego Community College Systems Disrupted
San Diego Community College District
Cyberattack disrupted student portal access, internet connectivity, and core systems across California's largest community college district serving over 100,000 students.
What it means: Educational services interrupted for significant student population with potential exposure of academic and financial records under investigation.
Significant 28K records Feb 9
Japan Airlines Reservation System Breached
Japan Airlines
Unauthorized access to Same Day Luggage Delivery Service reservation system exposed customer names, email addresses, phone numbers, and flight details from July 2024 reservations.
What it means: International traveler data compromised affecting North American passengers using JAL services with potential for targeted travel-based fraud.