Share this emailCopy the public link or share it on your favorite channel.
May 7, 2026

3 Bell Ringer Ideas for Class

Background
This week the cybercriminal group ShinyHunters publicly claimed a breach of Instructure (Canvas's parent company), affecting up to 9,000 institutions and as many as 275 million users. Exposed data includes names, school email addresses, student ID numbers, and course messages. The story is still developing, which makes it a strong hook for a quick warm-up. Three options below, ranging from 5 to 10 minutes. Pick one that fits your lesson today.
1. What got out, what didn't (5 minutes) Topic: data classification and harm potential
  • Put two lists on the board. Exposed: names, school emails, student IDs, course messages. Not exposed (per Instructure): passwords, dates of birth, government identifiers, financial information.
  • Students pick one item from the exposed list and write two sentences on what someone could do with it that would be hard to undo.
  • One-minute partner share.
  • Wrap-up: "Just names and emails" is misleading. Different data has different harm potential, especially in context (school name plus class roster plus messages tells a story that an email alone does not).
2. Threat actor research in 7 minutes (10 minutes) Topic: open-source intelligence (OSINT) on threat actors
  • Send students to two URLs: the Wikipedia page for ShinyHunters and one news article you trust. Put both links in the chat or on the board to keep students from searching.
  • 7 minutes to answer four questions: When did ShinyHunters first appear, and what does the name come from? What motivates them (financial, political, espionage, other)? Name two other major breaches they have claimed. What tactics do they typically use to get in?
  • 3 minutes share-out.
  • Wrap-up: Two ideas worth landing. (1) Threat actors have histories you can research. (2) Public claims may not match technical reality. Google and Mandiant track parts of this campaign as UNC6040 and UNC6240, and "ShinyHunters" is partly a brand name different actors use for pressure. Attribution requires forensic evidence, not just a claim.
3. How big is Canvas, and why does it matter? (10 minutes) Topic: scale, identity attack surface, and vendor concentration risk
Two parts: students find numbers first, then translate them into security thinking.
Part 1, 3 minutes. Send students to Instructure's website and one news article. They answer:
  • How many active Canvas users does Instructure claim worldwide?
  • How many institutions use Canvas?
  • What types of information does Canvas store about each user?
Part 2, 4 minutes. Apply those numbers to security questions:
  • If Canvas has more than 30 million users, how many sets of credentials does an attacker get to choose from?
  • If more than 8,000 institutions are customers, how many administrator accounts have privileged access somewhere on the platform?
  • Why does compromising Instructure once hurt more than compromising 8,000 individual schools separately?
Part 3, 3 minutes. Discussion.
  • Wrap-up: Scale is not just "more of the same." A breach at one school exposes one school. A breach at the company running the gradebook for thousands of schools exposes them all at once. That's a different category of risk, called vendor concentration risk or supply chain risk. Every one of those 30 million users is also an account someone could take over. The scope of exposure and the identity attack surface are linked: bigger user base, bigger pool of credentials worth stealing, bigger reason for an attacker to invest in finding a way in.
facebook twitter instagram youtube 
Unsubscribe | Manage your subscription

DARK Enterprises Inc. is a non-profit dedicated to developing, supporting, and stewarding excellent cybersecurity education at the secondary level. We provide leadership, resources, training, and partnerships in support of assuring the U.S. has a robust and reliable talent pipeline in cybersecurity.