Every era's defining breach is the one ordinary people can feel. In May 2026 it arrived through the school gate: Instructure — maker of Canvas, the learning platform that is simply where school happens for a vast share of the world's students — was breached by ShinyHunters, who claimed a haul of 3.65 terabytes spanning roughly 275 million users across nearly nine thousand institutions. Student names and IDs, coursework, private messages between teachers and students — the accumulated digital residue of a generation's education. Under a pay-or-leak countdown, Instructure reportedly paid.
The scale earned the incident an instant place in the record books — and its own encyclopedia entry — but the demographic is what made it land. Breach fatigue is real until it's your child's name in the dataset. Parents who had never read a security story read this one; school boards that had never asked a vendor about token hygiene suddenly had questions. Education technology had spent fifteen years centralising into a handful of platforms on the promise that scale meant safety. May priced the other side of that bargain: scale means one door to everything.
And the campaign fit the year's pattern like a glove. The same crew whose OAuth-token harvesting defined 2025 had simply moved along the shelf of trusted platforms — CRM last year, classrooms this spring, HR software a month later. Different data, identical logic: go where everyone already is.
Eight terabytes from Big Tech's workshop
On May 12, Foxconn acknowledged an attack on its North American operations after the Nitrogen ransomware crew claimed 8 TB of schematics, project details, and customer documents tied to Apple, Dell, Google, and Nvidia. The world's electronics are largely built by one company's factories — which makes that company's file servers a proxy breach of everyone it builds for. Supply-chain risk, in its most literal, physical form.
The hackers and the fuel tanks
US officials disclosed that suspected Iranian actors had breached systems monitoring fuel storage tanks at gas stations across several states — automatic tank gauges left on the public internet with no password protection. No explosions, no shortages; the point was the reach. A decade of warnings about exposed industrial controls, validated at the neighbourhood petrol pump — criticality and defensibility, once again, set by entirely different budgets.
From stealing data to moving money
No Indian name led May's global lists — the month's India story was quieter and arguably worse. Analysts tracking the subcontinent described attackers shifting from database theft toward transaction manipulation: not copying the ledger but editing it, with Indian financial institutions reporting six- and seven-figure fraud attempts built on the hybrid approach. Against the backdrop of a country logging thousands of incidents a day — more than 2.2 million between 2021 and mid-2025 — the evolution mattered more than any single breach: theft you discover on a leak site; manipulation you discover in your balance.
⏳ Time capsule — May 2026
- The month's incident lists read like a who's-who of the untouchable: OpenAI, Trellix, Grafana, Vimeo — AI labs and security vendors included.
- Qilin gave Sysco — the world's largest food distributor — a ransom deadline of May 12, adding groceries to the year's hostage list.
- Taiwan High Speed Rail and NYC Health + Hospitals kept the "critical services" column full.
- School WhatsApp groups worldwide discovered the phrase "data fiduciary" — and used it at parent-teacher meetings.
The breach parents remember
Three months on, "Canvas" is to 2026 what "Equifax" was to 2017 — the incident civilians cite, the one that made a generation of families ask where their children's data lives. The ShinyHunters through-line ran straight from this classroom haul into June's PeopleSoft extortion campaign and July's platform raids, one trusted-shelf platform at a time — the arc our current editions now cover as live news. The fuel-tank disclosure did its quieter work too, pushing exposed industrial controls back up national agendas. And India's transaction-manipulation turn previewed the fraud conversation every bank on the subcontinent is now having: the difference between losing your data and losing the number it protects.