Experts Skeptical of Canvas Hackers' Claim to Delete Stolen Student Data
Instructure, the education technology company behind Canvas, recently announced an agreement with the ShinyHunters cybercrime group following a massive data breach affecting approximately 275 million students, teachers, and staff. The company assured users that stolen private chats and email addresses were destroyed, citing digital confirmation from the attackers. However, cybersecurity experts and threat intelligence analysts strongly dispute this claim. Specialists from Recorded Future and the Halcyon Ransomware Research Center argue that ransomware groups rarely delete data permanently, often recycling it for future extortion or phishing campaigns. They describe Instructure's assurance as part of a 'Ransomware Trust Paradox,' where criminals maintain a facade of integrity to ensure future payments while likely retaining copies of the data. Experts predict targeted phishing attacks against the educational community in the coming year using the leaked information. Although Instructure did not explicitly confirm a ransom payment, industry insiders estimate the settlement ranged between $5 million and $30 million. This incident highlights the difficult operational decisions institutions face during critical periods like finals week, despite FBI recommendations against paying ransoms.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection