Experts Warn Canvas Deal with Hackers Invites Future Extortion
Cybersecurity experts have criticized Instructure, the company behind the Canvas learning platform, for reaching an agreement with the ShinyHunters hacking group following a massive data breach. The incident compromised personal information of approximately 275 million users across 9,000 educational institutions in countries including the US, Australia, Canada, and New Zealand. While Instructure claims the deal resulted in the return and destruction of stolen data, reports suggest a ransom of around US$10 million may have been paid. Experts warn that paying ransoms marks organizations as easy targets, potentially adding them to criminal 'sucker lists' for future extortion attempts. Australia’s National Cyber Security Coordinator emphasized that cybercriminals cannot be trusted, noting that payments do not guarantee data recovery or prevent leaks. Furthermore, verifying the complete deletion of copied data is nearly impossible. The breach has already triggered multiple lawsuits against Instructure’s owner, KKR. Authorities and academics argue that such payments reinforce criminal business models and increase the risk of subsequent attacks by both original perpetrators and copycats, urging organizations to resist negotiation despite the immediate pressure.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection