Every era's defining breach is the one ordinary people can feel. In May 2026 it arrived through the school gate: Instructure — maker of Canvas, the learning platform that is simply where school happens for a vast share of the world's students — was breached by ShinyHunters, who claimed a haul of 3.65 terabytes spanning roughly 275 million users across nearly nine thousand institutions. Student names and IDs, coursework, private messages between teachers and students — the accumulated digital residue of a generation's education. Under a pay-or-leak countdown, Instructure reportedly paid.
The scale earned the incident an instant place in the record books — and its own encyclopedia entry — but the demographic is what made it land. Breach fatigue is real until it's your child's name in the dataset. Parents who had never read a security story read this one; school boards that had never asked a vendor about token hygiene suddenly had questions. Education technology had spent fifteen years centralising into a handful of platforms on the promise that scale meant safety. May priced the other side of that bargain: scale means one door to everything.
And the campaign fit the year's pattern like a glove. The same crew whose OAuth-token harvesting defined 2025 had simply moved along the shelf of trusted platforms — CRM last year, classrooms this spring, HR software a month later. Different data, identical logic: go where everyone already is.
Eight terabytes from Big Tech's workshop
On May 12, Foxconn acknowledged an attack on its North American operations after the Nitrogen ransomware crew claimed 8 TB of schematics, project details, and customer documents tied to Apple, Dell, Google, and Nvidia. The world's electronics are largely built by one company's factories — which makes that company's file servers a proxy breach of everyone it builds for. Supply-chain risk, in its most literal, physical form.
The hackers and the fuel tanks
US officials disclosed that suspected Iranian actors had breached systems monitoring fuel storage tanks at gas stations across several states — automatic tank gauges left on the public internet with no password protection. No explosions, no shortages; the point was the reach. A decade of warnings about exposed industrial controls, validated at the neighbourhood petrol pump — criticality and defensibility, once again, set by entirely different budgets.
From stealing data to moving money
No Indian name led May's global lists — the month's India story was quieter and arguably worse. Analysts tracking the subcontinent described attackers shifting from database theft toward transaction manipulation: not copying the ledger but editing it, with Indian financial institutions reporting six- and seven-figure fraud attempts built on the hybrid approach. Against the backdrop of a country logging thousands of incidents a day — more than 2.2 million between 2021 and mid-2025 — the evolution mattered more than any single breach: theft you discover on a leak site; manipulation you discover in your balance.
Gemini's agentic turn, Anthropic's record round
May was the month the frontier race became a capital-markets story. Google held I/O on 19 and 20 May at Mountain View and gave the event over almost entirely to agents: Gemini 3.5 Flash reached general availability, and Gemini Omni arrived as a model built to generate video and other media from mixed inputs. OpenAI's month was one of distribution rather than debut, making GPT-5.5 Instant the default for every ChatGPT user on 5 May, some weeks after the model itself had shipped. The largest number belonged to Anthropic: Fortune reported that the company closed a Series H round on 28 May at a post-money valuation of $965 billion, raising $65 billion — described as the largest private financing on record, and ahead of the mark OpenAI had set. Confirmation of intent followed within days, as Anthropic submitted a confidential draft registration statement to the SEC on 1 June.
Twenty-six deals for the new endpoint
The month's endpoint news was written in term sheets rather than telemetry. SecurityWeek counted twenty-six cybersecurity acquisitions announced across May, and the pattern running through them was consistent: incumbents buying the ground the endpoint has quietly been moving onto. Akamai said on 14 May that it intended to acquire LayerX, a secure enterprise browser firm, for roughly $205 million — an acknowledgement that most enterprise work, and most staff contact with generative AI tools, now happens inside a browser tab rather than an installed application. Cisco moved for Astrix Security, which inventories the machine credentials — API keys, service accounts, OAuth tokens — that autonomous agents run on; terms were not disclosed, and published estimates of the price varied widely. Check Point took the team and intellectual property of Deepchecks, and Cyera bought Genie Security, an endpoint data-protection startup only months old. Capstone Partners placed roughly thirty per cent of the year's dealmaking to date on vendors either securing or powered by AI.
⏳ Time capsule — May 2026
- The month's incident lists read like a who's-who of the untouchable: OpenAI, Trellix, Grafana, Vimeo — AI labs and security vendors included.
- Qilin gave Sysco — the world's largest food distributor — a ransom deadline of May 12, adding groceries to the year's hostage list.
- Taiwan High Speed Rail and NYC Health + Hospitals kept the "critical services" column full.
- School WhatsApp groups worldwide discovered the phrase "data fiduciary" — and used it at parent-teacher meetings.
The breach parents remember
Three months on, "Canvas" is to 2026 what "Equifax" was to 2017 — the incident civilians cite, the one that made a generation of families ask where their children's data lives. The ShinyHunters through-line ran straight from this classroom haul into June's PeopleSoft extortion campaign and July's platform raids, one trusted-shelf platform at a time — the arc our current editions now cover as live news. The fuel-tank disclosure did its quieter work too, pushing exposed industrial controls back up national agendas. And India's transaction-manipulation turn previewed the fraud conversation every bank on the subcontinent is now having: the difference between losing your data and losing the number it protects.