Security
ShinyHunters is named in Canvas, Carnival, Medtronic and RingCentral, and Google says it was not a vendor flaw
Four breaches reported as separate corporate failures between April and August 2026 share an attributed crew. Google Threat Intelligence has said the activity is not the result of a vulnerability in vendors' products. Published victim counts for the same events differ by millions.

Between April and August 2026, four organisations with almost nothing in common disclosed data breaches: a learning management platform used by schools, a cruise operator, a medical device maker and a business telephony provider. Instructure, Carnival Corporation, Medtronic and RingCentral were covered largely as separate corporate accidents. In each case the extortion group named is ShinyHunters.
The common thread is not a shared product. Google Threat Intelligence, quoted in a breach tracker maintained by State of Surveillance, has assessed that this activity is not the result of a security vulnerability in vendors' products or infrastructure and that it continues to highlight the effectiveness of social engineering. A technical analysis published by the vendor Push Security on 8 May 2026 sets out the mechanics: voice phishing calls impersonating IT support, often citing a mandatory passkey rollout or a security compliance update; adversary in the middle phishing pages that relay credentials and multi factor codes to the legitimate identity provider as they are entered, capturing the resulting session token; and device code phishing that abuses the OAuth 2.0 device authorisation grant. Push Security's argument is that device code phishing defeats all multi factor authentication including passkeys because the attack does not target the login, it targets the authorisation layer. A third pattern, OAuth supply chain compromise, uses tokens stolen from an integration vendor to query the tenancies of everyone that vendor serves. The 2025 Salesloft and Drift compromise worked that way, and Push Security records a comparable Anodot compromise in April 2026.
The individual incidents are documented, but the numbers attached to them are not stable. Instructure, which operates Canvas, was accessed in late April 2026. UpGuard dates initial access to 29 April 2026, initial disclosure to 1 May 2026 and containment to 6 May 2026. The Hacker News reported a second wave of activity detected on 7 May 2026 involving defacement of login portals at roughly 330 institutions, and a ransom agreement the company confirmed in reporting dated 12 May 2026. The stolen volume is put at 3.65 terabytes and roughly 275 million records across close to 9,000 institutions, covering usernames, email addresses, course names, enrolment information and messages, with course content, submissions and credentials said not to have been compromised. Instructure has stated it reached an agreement with the unauthorised actor and that the data was returned to it along with digital confirmation of destruction, a claim the company makes about itself and which no third party can verify. The State of Surveillance tracker notes the company paid despite standing FBI advice against it and that companies in this position cannot verify whether stolen data was actually destroyed or already copied elsewhere.
Carnival is the clearest example of the counting problem. Have I Been Pwned added a Carnival breach on 24 April 2026 covering 7.5 million unique email addresses within 8.7 million records, and attributes the data to the Mariner Society loyalty programme run by Holland America, a Carnival brand. UpGuard records a different figure, 5,995,277 people, drawn from Carnival's filing with the Maine Attorney General, for a breach it dates to 10 April 2026 and a disclosure in May 2026. Security Boulevard's summary reconciles the spread: roughly 6 million individuals notified by Carnival, 8.7 million records claimed by the attackers, and about 7.5 million loyalty accounts identified by Have I Been Pwned. These are not the same measurement. Carnival has acknowledged, per that summary, a social engineering attack against a single employee account that opened a path into its IT systems.
Medtronic's timeline is tight. The company has said it became aware of unusual activity on certain corporate IT systems on 15 April 2026, with unauthorised access running from 13 to 19 April 2026. BleepingComputer reported that ShinyHunters listed Medtronic on its dark web portal on 18 April 2026 with a ransom deadline of 21 April 2026, that the listing was later removed and the data was not exposed online, and that customer notifications went out around 2 July 2026. Roughly 9 million records are involved, including names, contact details, dates of birth, Social Security numbers and health related information. Medtronic states that all its devices remain safe to use and are not affected by the incident, which is the company's own assessment. Medtronic has not disclosed how the intruder got in, and this masthead could not verify the widely repeated claim that it filed a Form 8-K on 24 April 2026.
RingCentral is the most recent. The Register reports the breach was disclosed on 28 July 2026, that the attackers set an extortion deadline of 30 July 2026, and that the data was dumped publicly on 3 August 2026 after RingCentral did not pay. The confirmed scope is about 1.6 million unique email addresses, with names, physical addresses and phone numbers. ShinyHunters claims far more: 623 gigabytes, 30 million rows of customer information, more than 1 million Social Security numbers, and more than 22 million rows of client notes containing confidential doctor and patient conversations. Those are the attackers' claims and are unverified. RingCentral says it has not seen any new unauthorised activity since taking remediation steps. The Register reports that entry was gained by voice phishing an employee into handing over a password.
What remains unresolved is whether these are one campaign or a brand. ShinyHunters is described by Push Security as the product of a merger of Scattered Spider, Lapsus$ and ShinyHunters within the Com, a broader community of English speaking cybercriminals. Attribution to a name in that setting does not establish that the same people ran all four operations. What the evidence does support is narrower and more useful to defenders: in the three cases where an entry vector has been disclosed, Instructure, Carnival and RingCentral, it was the credential and authorisation layer, and on Google's assessment no vendor patch would have closed it.
Sources
Every factual claim above rests on the 9 published sources below. They are listed so you can check the reporting rather than take it on trust.
- Push SecurityAnalyzing the Instructure breach
- The Hacker NewsInstructure reaches ransom agreement after Canvas data theft
- Have I Been PwnedCarnival breach
- BleepingComputerMedtronic notifies customers impacted by ShinyHunters data breach
- The Register1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
- State of SurveillanceShinyHunters 2026 breach tracker: Salesforce, Carnival, Canvas campaign
- UpGuardThe biggest data breaches in US history
- Security Boulevard2026 data breaches and cybersecurity incidents explained
- Tech.coData breaches: an updated list


