< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

ShinyHunters exploits stale credentials to breach education and corporate data in 2026

In 2026, the most damaging data breaches shared a common root cause: outdated or poorly verified credentials. Extortion groups such as ShinyHunters used voice‑phishing (vishing) to impersonate IT support, while Icarus exploited a pilot credential that remained active for four years. These credential‑lifecycle failures gave attackers entry to a range of high‑profile targets.

Among the biggest incidents, Instructure’s Canvas learning‑management system was compromised, exposing names, email addresses, student IDs and private messages for over 30 million students and staff. After the company declined to pay a ransom, ShinyHunters returned and defaced login pages. Other large‑scale breaches cited include Charter Communications (≈40 million records), Carnival Corporation (≈6 million records), Conduent (≈25 million Texans and Oregon residents) and a supply‑chain attack on Rockstar Games. The pattern underscores systemic gaps in access‑lifecycle governance across enterprises worldwide.