Instructure pays ransom to Canvas hackers

TL;DR

Instructure paid an undisclosed ransom to the ShinyHunters cybercriminal group after they hacked Canvas twice in a week and a half. The company confirmed data recovery and destruction, with ongoing investigations.

Instructure has paid a ransom to the cybercriminal group ShinyHunters following two breaches of its Canvas learning management system in less than two weeks, affecting approximately 275 million users across over 8,800 institutions.

The company, which supplies LMS services to 41 percent of North American higher education institutions, confirmed in an update on May 11 that it paid an undisclosed amount to the hackers, who had threatened to leak user data if demands were not met by May 12. The ransom deal resulted in the return of compromised data and confirmation of data destruction, according to Instructure.

ShinyHunters claimed responsibility for the breaches, which disrupted Canvas services and threatened to leak personal information, including names, email addresses, student IDs, and private messages among users. The group had previously linked these attacks to breaches at universities such as Harvard, Princeton, and the University of Pennsylvania.

Why It Matters

This incident underscores the ongoing cybersecurity risks facing educational technology providers, especially those managing sensitive student and institutional data. The decision to pay the ransom raises questions about the effectiveness of current cybersecurity defenses and the potential encouragement of ransom-based extortion.

For students, faculty, and administrators, the breach highlights vulnerabilities in data security protocols, potentially exposing personal and academic information. The incident may also influence future policies on cybersecurity incident response and ransom negotiations in the education sector.

Cybersecurity Geek Computer Science Software Engineer T-Shirt

Cybersecurity Geek Computer Science Software Engineer T-Shirt

Computer engineer gifts for men who like gifts for computer geeks and computer security outfits. Cyber security gifts…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

Over the past week and a half, Canvas experienced two cyberattacks by ShinyHunters, a hacking group known for targeting high-profile institutions and demanding ransom payments. The first breach led to service disruptions and threatened data leaks, prompting some universities to postpone exams. The hackers issued demands with a deadline of May 12, warning of data leaks and digital issues if ignored.

Instructure initially responded by addressing security concerns and restoring services by May 5. However, the hackers resumed their attacks later in the week, leading to renewed disruptions and public messages from the group. The company’s decision to pay the ransom came just before the deadline, aiming to prevent data leaks and further damage.

“Last week, we made a call to get the facts right before speaking publicly. That instinct isn’t wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates.”

— Instructure CEO Steve Daly

“All Canvas environments are available.”

— Instructure statement

The Cyber Attack Survival Manual: Tools for Surviving Everything from Identity Theft to the Digital Apocalypse

The Cyber Attack Survival Manual: Tools for Surviving Everything from Identity Theft to the Digital Apocalypse

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It remains unclear how much the ransom was for, as Instructure has not disclosed financial details. It is also uncertain whether the data leak has been entirely prevented or if residual vulnerabilities remain. The long-term impact on user trust and future security policies is still developing.

SOC analyst Starter Kit

SOC analyst Starter Kit

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Instructure is continuing its forensic investigation and working with security vendors to strengthen its defenses. The company plans to review its incident response strategies and improve communication protocols. Further updates are expected as the investigation progresses and additional security measures are implemented.

SANDISK 32GB Ultra Flair USB 3.0 Flash Drive - SDCZ73-032G-G46

SANDISK 32GB Ultra Flair USB 3.0 Flash Drive – SDCZ73-032G-G46

High-speed USB 3.0 performance of up to 150MB/s(1) [(1) Write to drive up to 15x faster than standard…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Did Instructure confirm the amount paid in ransom?

No, the company has not disclosed the ransom amount paid to ShinyHunters.

Are all Canvas users now secure after the ransom payment?

While Instructure reports that all environments are now available, the full security status and potential residual vulnerabilities remain under review.

Will the hackers leak the data they recovered?

Instructure claims to have received confirmation of data destruction, but the risk of leaks cannot be entirely ruled out until further assessments are completed.

Why did Instructure decide to pay the ransom?

The company stated that paying the ransom was intended to prevent data leaks and further disruptions, especially given the threat of sensitive user information being publicly released.

You May Also Like

The policy menu. There’s no single answer. There’s a menu — and choosing is a values choice in disguise.

Thorsten Meyer AI frames AI distribution policy as a choice among efficiency, security, agency and fairness, with key facts still unsettled.

China’s retail sales grow at slowest pace since COVID pandemic

China’s retail sales in April increased by only 0.2%, marking the slowest growth since the COVID pandemic began, highlighting ongoing demand issues.

This curved path helps prevent bullets from hitting each other’s primers during production

A new curved path in manufacturing helps prevent bullets from hitting each other’s primers, enhancing safety and efficiency in ammunition assembly.

The rails. Why European agentic commerce is co-defined by two converging regimes.

Europe’s agentic commerce is shaped by two converging regulatory regimes—PSD3/PSR and the AI Act—creating a complex, statutory infrastructure distinct from the US model.