Instructure Pays Ransom to Hackers in Massive Education Data Breach
Instructure, the parent company of the online learning platform Canvas, has reached an agreement with the cybercriminal gang ShinyHunters following a massive data breach affecting approximately 275 million users globally. The attack compromised personal data from 8,809 educational institutions, including over 120 in Australia such as the University of Melbourne and various state education departments. While Instructure did not explicitly confirm a ransom payment, it stated that stolen data was returned along with digital proof of deletion. Cybersecurity experts estimate the ransom likely ranged in the high single-digit millions of dollars, against an initial demand of $13 million. The breached data includes student IDs, names, email addresses, and private messages, though financial information and passwords were reportedly untouched. Former Australian cyber tsar Alastair MacGibbon criticized the move, suggesting the agreement implies a paid ransom and warning that criminal assurances regarding data deletion are often unreliable. This incident represents one of the largest breaches in the education sector, raising significant concerns about data privacy and the justification of paying ransoms to cybercriminals.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection