Instructure Pays Hackers to Delete Stolen Canvas Data
Instructure, the developer of the widely used Canvas learning management system, has confirmed it reached an agreement with cybercriminals who stole 3.5 terabytes of student and university data. The company stated that its primary motivation was protecting the privacy of students and education staff. Under the undisclosed terms, the stolen data was returned to Instructure, and the company received digital confirmation that the information was destroyed. Additionally, the hackers agreed not to extort any affected customers, covering all institutions involved without requiring individual engagement. However, this decision contradicts advice from global law enforcement agencies, which warn that paying ransom fuels further attacks and offers no guarantee of data deletion. Reports highlight previous instances, such as the LockBit ransomware case, where criminals accepted payments but retained data for resale. Despite these risks, Instructure argued that taking every possible step within their control was necessary to provide peace of mind to their customers. The incident underscores the ongoing challenges educational technology providers face in securing sensitive user information against sophisticated cyber threats.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection