Why Stolen Messages Can Be More Dangerous Than Stolen Passwords
When news broke that the prolific cybercrime and data extortion group ShinyHunters had breached Instructure, the company behind the Canvas…
Why Stolen Messages Can Be More Dangerous Than Stolen Passwords

When news broke that the prolific cybercrime and data extortion group ShinyHunters had breached Instructure, the company behind the Canvas learning management system, the early headlines focused on the numbers: potentially 275 million records across nearly 9,000 schools worldwide. Names, email addresses, student ID numbers. It was, by any measure, a large breach.
But buried inside the ShinyHunters extortion notice was a detail that deserves more attention than it has received.
The group claimed to have stolen billions of private messages between students and teachers.
Not passwords. Not Social Security numbers. Not financial account details. Conversations.
That distinction matters more than most post-breach coverage suggests, and understanding why changes how security teams should think about what data they actually need to protect.
The Data Breach Metric That Misleads Us
The cybersecurity industry has trained itself to evaluate breaches by a fairly standard hierarchy of harm. Exposed passwords are serious because they enable account takeover. Exposed financial data is serious because it enables fraud. Exposed government identifiers — Social Security numbers, passport data — are serious because the damage can last decades. These are real risks and they deserve the attention they get.
What this hierarchy undervalues is context. Raw PII fields like names and email addresses are, on their own, relatively low-value to a sophisticated attacker. The email address you share when signing up for a service is often publicly available in a dozen other places. What is not publicly available is what you said in a private message to your professor last Tuesday about a missed deadline, a family emergency or an academic struggle.
That kind of context transforms a generic phishing email into something far more dangerous: a message that feels real, because in important ways it is.

Contextually Rich Data: A Social Engineering Goldmine
Social engineering attacks succeed because they reduce skepticism. A phishing email asking you to click a link feels suspicious precisely because it lacks any real knowledge of you. The attacker doesn’t know your name, your institution, who you communicate with, what you discuss or when.
Strip away that ignorance and the calculus changes entirely. An attacker who has read private messages between a student and an instructor knows the student’s real name, their school, their course load, the name of their professor, the subject of their last conversation and the approximate emotional state the student was in when they sent it. A follow-up phishing message that references any of those details would be nearly indistinguishable from a legitimate institutional communication.
This is not hypothetical. Spear phishing, the targeted variant of phishing that uses personal context to manufacture credibility, is already among the most effective attack vectors in the threat landscape. The Instructure breach hands attackers the raw material to conduct spear phishing at scale, against a population that skews young, that trusts institutional communications and that may not have been briefed on breach-related risks.
That is a material threat, and it will not be neutralized when Instructure finishes patching the vulnerability ShinyHunters exploited.
This Attack Pattern Is Accelerating
The Instructure incident is not an isolated data point. The education sector has absorbed a series of significant breaches in recent months, with ShinyHunters alone linked to separate incidents at Harvard and the University of Pennsylvania, as well as Princeton, and an earlier attack on Infinite Campus, a widely used K-12 student information system. PowerSchool, which manages student records for K-12 districts across North America, disclosed a breach earlier this year that exposed the data of tens of millions of students and teachers.

What these incidents share is not just the sector. They share the attack profile: cloud-hosted platforms that aggregate communication and record-keeping data for large numbers of users, with API-connected third-party ecosystems that expand the available attack surface. The conversation data that makes education platforms operationally valuable to students and teachers is the same data that makes them attractive targets.
That dynamic is not unique to education. Any cloud platform that stores rich communication data — collaboration tools, CRM systems, customer support platforms, project management applications — carries a version of the same exposure. The Instructure breach is a sector-specific manifestation of a broad and growing problem.
What “Knowing Your Data” Actually Means
The conventional response to a breach of this type is to focus on the vulnerability that was exploited and the controls that failed to detect the exfiltration in progress. Both of those things matter. But the more durable lesson from incidents like this one is about data posture: what data your organization holds, where it lives, who can access it and whether all of it needs to exist at all.
Security teams often operate without a complete picture of where sensitive data resides in their SaaS environments. That is not a criticism; it reflects the reality of how quickly modern application stacks grow and how rarely data inventories keep pace with them. But you cannot protect what you cannot see, and you cannot minimize the blast radius of a breach you have not anticipated.
Effective data posture management starts with discovery, surfaces every data store across cloud and SaaS environments and classifies what it finds by sensitivity and risk. It distinguishes between a database of email addresses and a database of private communications with rich personal context, because those two assets do not carry the same risk weight and should not be governed the same way.
From there, access governance determines who should be able to reach that data in the first place. An application that stores billions of historical private messages as a byproduct of its primary function does not necessarily need to make those messages accessible in bulk to the systems and integrations built on top of it. Least-privilege access principles apply to data stores just as they apply to user accounts. Where communication data is retained because it is genuinely necessary, DLP controls can monitor and restrict how that data moves, flagging unusual access patterns or bulk extraction attempts before an incident becomes a breach.
ShinyHunters reportedly claimed that Instructure’s Salesforce environment was also compromised in the same attack. That detail, if confirmed, would mean a single attacker pivoted between two distinct data environments through a connected ecosystem. It is a reminder that a platform’s data security posture includes every integration it trusts.
The Data You Forget About Is the Data That Gets Used Against You
The Instructure breach will generate weeks of coverage focused on the scale of the numbers and the audacity of the extortion demand. What it should generate, for security teams across every sector, is a more precise question: What does our organization store that an attacker could use to manufacture trust?
In the modern threat landscape, the most dangerous asset in a breach is often not the data you thought to protect. It is the data that accumulated quietly, at scale, inside a platform you depended on — stored because retention was easier than deletion, accessible because access governance lagged behind adoption, and invisible to your security tools because no one had mapped it.
The Instructure breach exposed billions of messages. Most of them were probably unremarkable. But an attacker who holds the context of even a small fraction of those conversations holds the keys to attacks that no password reset will fix.
Forcepoint Data Security Cloud gives security teams continuous visibility into sensitive data across cloud and SaaS environments, with AI-native classification and unified policy enforcement to minimize exposure before incidents occur. Learn more at forcepoint.com.
메타데이터
- post_id
- da0706c575f2
- slug
- why-stolen-messages-can-be-more-dangerous-than-stolen-passwords-da0706c575f2
- url
- https://medium.com/forcepoint-security/why-stolen-messages-can-be-more-dangerous-than-stolen-passwords-da0706c575f2
- canonical_url
- https://medium.com/forcepoint-security/why-stolen-messages-can-be-more-dangerous-than-stolen-passwords-da0706c575f2
- author_url
- https://medium.com/@forcepoint-security
- status
- ok
- fetched_at
- 2026-06-14 11:28:49