Instructure Claims Hackers Returned Stolen Canvas Data After Extortion Standoff
Instructure, the developer of the widely used educational platform Canvas, announced an agreement with the cybercriminal group ShinyHunters following a significant data theft and extortion attempt. The attackers had threatened to leak sensitive data from over 8,800 school systems, affecting approximately 275 million records. The standoff escalated when ShinyHunters defaced login pages and injected extortion messages, forcing Instructure to temporarily take Canvas offline, which disrupted academic activities nationwide. Although Instructure did not explicitly confirm paying a ransom, the company stated that the stolen data was returned and verified as destroyed, with assurances that no customers would face further extortion. CEO Steve Daly apologized for inconsistent communication during the crisis. The incident has drawn scrutiny from US lawmakers, with the House Homeland Security Committee requesting a briefing on Instructure's incident response capabilities and security measures. Federal agencies like CISA are aware of the situation and offering voluntary support. The breach exposed usernames and enrollment information, though course content and credentials reportedly remained secure.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection