Hong Kong Privacy Watchdog Condemns Ransom Payments After Canvas Cyberattack
Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) has strongly advised against paying ransoms to hackers following a significant cyberattack on the education management platform Canvas. The breach compromised the personal data of approximately 72,000 students and staff across seven local institutions, including names, email addresses, and student IDs. Privacy Commissioner Ada Chung condemned the potential payment of ransoms, arguing that such practices fund illegal activities and do not guarantee data safety. She warned that yielding to extortion could signal vulnerability to other cybercriminals. The incident is part of a broader global attack orchestrated by the hacker group ShinyHunters, which affected nearly 9,000 educational institutions worldwide and involved 3.5 terabytes of data from 275 million users. While Instructure, the developer of Canvas, confirmed an agreement with the hackers, it remains unclear if a ransom was paid. ShinyHunters claimed to have deleted the stolen data. Currently, there is no evidence of public data leaks. The PCPD advises organizations using Canvas to enhance system protections and remove sensitive information while Instructure completes its incident review.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection