Instructure Pays Ransom to ShinyHunters After Global Canvas Data Breach
Ed-tech giant Instructure paid a ransom to the ShinyHunters cybercrime group following two major breaches of its Canvas learning platform. The attacks disrupted services for thousands of educational institutions globally, including in Australia, the US, and Europe, affecting millions of students during critical exam periods. While Instructure secured the return and destruction of 3.5 terabytes of stolen data, the incident sparked a US Congressional investigation and highlighted severe vulnerabilities in educational infrastructure. Authorities advised against paying ransoms, but Instructure prioritized data recovery despite the controversy.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
Hong Kong Privacy Watchdog Warns Against Paying Ransoms After Canvas Hack
Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) has strongly advised against paying ransoms to hackers following a significant cyberattack on the education management platform Canvas. The breach compromised the personal data of approximately 72,000 students and staff across seven local institutions, including names, email addresses, and student IDs. Privacy Commissioner Ada Chung condemned the practice of paying ransoms, arguing that it funds illegal activities, does not guarantee data safety, and may encourage further attacks. The incident is part of a larger global assault on Canvas developer Instructure, affecting nearly 9,000 educational institutions and 275 million users worldwide. Instructure confirmed an agreement with the hacker group ShinyHunters, which claimed to have deleted the stolen data, though neither party confirmed if a ransom was paid. Currently, there is no evidence of public data leaks. The PCPD urges organizations using Canvas to enhance their cybersecurity measures and remove sensitive information from the platform while Instructure completes its review of the incident over the coming weeks.
Hong Kong Free Press HKFPExperts Skeptical of Canvas Hacker's Claim to Delete Stolen Student Data
Instructure, the company behind the educational platform Canvas, recently announced an agreement with the cybercriminal group ShinyHunters following a massive data breach affecting approximately 275 million students, teachers, and staff. Instructure assured affected institutions that the attackers had provided digital confirmation of data destruction and that no further extortion would occur. However, cybersecurity experts and threat intelligence analysts strongly dispute these claims. Specialists from Recorded Future and the Halcyon Ransomware Research Center argue that ransomware groups rarely delete stolen data, often recycling it for future campaigns despite promises to the contrary. ShinyHunters, in particular, has a documented history of reselling previously claimed-deleted data. Analysts predict that the leaked information, including names, email addresses, and chat contexts, will likely fuel targeted phishing attacks against the education sector over the next year. While Instructure did not explicitly confirm paying a ransom, industry estimates suggest the payment ranged between $5 million and $30 million. This incident highlights the difficult operational decisions organizations face during critical periods like finals week, balancing FBI advice against paying ransoms with the immediate need to restore services and protect users.
www.theregister.com - ArticlesInstructure Reaches Agreement with Hackers After Double Breach of Canvas Platform
Instructure, the developer of the widely used Canvas educational software, announced it has reached an agreement with the ShinyHunters cybercrime group following two significant security breaches. The hackers initially claimed to have stolen personal data belonging to 275 million students and staff members in late April 2026. To pressure Instructure into paying a ransom, the group breached the system again in early May, defacing login pages across thousands of school websites. As part of the undisclosed financial settlement, the hackers provided evidence that the stolen data was destroyed and promised not to extort customers further. However, Instructure acknowledged there are no absolute guarantees when negotiating with cybercriminals. The removal of the stolen data listing from the hackers' leak site suggests a ransom was likely paid, despite FBI advisories urging victims against such payments. This incident mirrors a similar breach at competitor PowerSchool, where paying ransoms failed to prevent subsequent extortion by other groups. Instructure continues to investigate the distinct security events while facing scrutiny over its cybersecurity leadership and the potential resignation of CEO Steve Daly.
TechCrunchCanvas Owner Instructure Reaches Agreement with Hackers to Secure Stolen Data
Instructure, the company behind the Canvas learning management platform, announced it has reached an unspecified agreement with the ShinyHunters hacking group following a significant data breach. The hackers, who claimed responsibility for the attack last week, had threatened to leak 3.5 terabytes of student data if ransom demands were not met. Instructure stated that the stolen data has been returned and destroyed, and the agreement ensures no customers will be extorted as a result of the incident. Although the company did not explicitly confirm a ransom payment, the nature of the settlement strongly suggests financial compensation was made to prevent public data leakage. The breach was initially executed by exploiting Free-For-Teacher accounts, leading to their temporary suspension. Most Canvas systems have since been restored, and Instructure is conducting forensic analysis while planning to share further details in an upcoming webinar. This incident highlights ongoing cybersecurity challenges in the education technology sector and the controversial practice of negotiating with cybercriminals to protect user privacy.
The VergeInstructure Pays Ransom After Canvas Breach as Congress Launches Investigation
Education technology firm Instructure confirmed it paid a ransom to the ShinyHunters cybercriminal group following two breaches of its Canvas platform. The company stated the agreement ensured the return of stolen data and its digital destruction, aiming to prevent further extortion of its customers, which include thousands of schools and universities. The hackers had previously claimed to steal sensitive information from 9,000 customers, including names and student IDs, threatening to leak it if demands were not met. The decision to pay coincided with the announcement that the House Homeland Security Committee would investigate the incident. Committee Chairman Andrew Garbarino criticized Instructure’s initial containment claims and response capabilities, requesting a detailed briefing on the intrusions and data exposure. Meanwhile, the FBI warned students against direct payments to hackers and advised awaiting institutional guidance. Cybersecurity firms Crowdstrike and others are conducting forensic analyses to harden Instructure’s environment. The ShinyHunters leak site was subsequently taken offline, suggesting potential law enforcement action. This event highlights significant cybersecurity vulnerabilities within the educational technology sector.
The Record from Recorded Future NewsCanvas Maker Instructure Pays Hackers to Delete Stolen Student Data
Instructure, the company behind the popular Canvas learning management system, has confirmed it reached an agreement with the Shiny Hunters cybercriminal group following a major data breach. The attack, discovered in late April 2026, disrupted services for approximately 9,000 educational institutions across the US, Canada, Australia, and the UK, significantly impacting student exams. Although Instructure did not explicitly confirm a monetary payment, the agreement involves the return of stolen data and digital confirmation of its destruction, alongside a promise that no customers will be extorted. This decision contradicts standard advice from global law enforcement agencies, which warn that paying ransoms fuels further criminal activity and offers no guarantee of data deletion. The breach involved the theft of 3.5 terabytes of sensitive student and university information. Instructure stated that protecting user data was its primary motivation, aiming to provide peace of mind despite the inherent uncertainties of dealing with cyber criminals. The incident highlights the ongoing challenges educational sectors face against sophisticated extortion groups like Shiny Hunters, who have previously targeted major corporations such as Jaguar Land Rover and Gucci.
BBC NewsInstructure Strikes Deal with Hackers to Return Stolen Canvas Data
Instructure, the educational technology company behind the widely used Canvas learning management system, has reached an agreement with cybercriminals who breached its platform. Under the terms of this deal, the hackers have agreed to return all stolen data and destroy any remaining copies. However, Instructure has not disclosed the specific concessions or payments made in exchange for these actions, raising questions about the nature of the negotiation. The breach impacted thousands of schools and universities globally that rely on Canvas for their digital infrastructure. This incident highlights the growing challenge organizations face when dealing with ransomware and data theft, where negotiating with threat actors becomes a controversial but sometimes necessary step to mitigate damage. The lack of transparency regarding the exchange has drawn attention from security experts and stakeholders concerned about the precedents set by such agreements. While the immediate threat of data exposure may be reduced, the long-term implications for user privacy and corporate security protocols remain significant concerns for the education sector.
TechmemeInstructure Negotiates with Hackers for Return of Stolen Canvas Data
Instructure, the educational technology company behind the widely used Canvas learning management system, has entered into an agreement with cybercriminals to recover stolen data. The breach affects thousands of schools and universities globally that rely on the platform for their digital infrastructure. While the deal has been struck, Instructure has deliberately withheld specific details regarding the concessions made to the hackers. The company did not disclose whether a ransom was paid or what other terms were agreed upon in exchange for the return of the sensitive information. This incident highlights the growing vulnerability of educational institutions to cyberattacks and the complex ethical and operational dilemmas faced by service providers when dealing with extortion attempts. The lack of transparency regarding the exchange raises questions about the nature of the negotiation and the potential precedents set for future cybersecurity incidents in the education sector. Stakeholders, including students and faculty members whose data may have been compromised, remain concerned about the security of their personal information and the long-term implications of this breach on the trustworthiness of the Canvas platform.
NYT > TechnologyAdelaide University Students Criticize Communication After Global Canvas Data Breach
Adelaide University has restored access to its cloud-based learning platform, Canvas, following a global data breach orchestrated by the hacking group ShinyHunters. The incident disrupted services for thousands of educational institutions worldwide, including Flinders University and various schools in Queensland. While the university confirmed that some personal information was accessed, it stated that sensitive data such as passwords and financial details remained secure. However, students have strongly criticized the institution's handling of the crisis, citing poor communication and a lack of timely updates. Many students reported learning about the breach through social media or news articles rather than official channels. This technical failure has exacerbated existing frustrations related to the recent merger between the University of Adelaide and the University of South Australia. Students described the outage as highly disruptive to assessments and course submissions, causing significant stress and confusion. The incident has raised broader concerns about the security risks associated with relying on single third-party providers for critical educational infrastructure. As services return to normal, calls for tightened security measures and improved transparency from university administration continue to grow among the student body.
Just InAustralian Universities Regain Canvas Access Amid Hacker Deadline
Several Australian universities, including the University of Sydney and the University of Melbourne, have restored access to the Canvas online learning platform following a significant cyberattack by the ShinyHunters group. The breach, which occurred last week, disrupted classes and exams for thousands of students globally by forcing system shutdowns. While some institutions are back online, others, such as Swinburne University and various public schools, remain affected, with restoration efforts ongoing. The hackers have set a deadline of May 12 for institutions to negotiate a settlement, threatening to leak compromised data if demands are not met. Instructure, the US-based developer of Canvas, confirmed that names, student IDs, and messages were accessed but stated there is no evidence of financial or government identifier theft. Australian authorities, including the National Office of Cyber Security and the Australian Signals Directorate, are coordinating the response. They strongly advise against paying ransoms, warning that payment offers no guarantee of data safety and may lead to further extortion attempts. Officials urge users to remain vigilant against phishing attempts using stolen information.
Just InShinyHunters Hackers Breach Instructure Again After Massive Data Heist
The cybercrime group ShinyHunters has successfully breached the security systems of American ed-tech giant Instructure for a second time, despite the company's implementation of new protective measures for student data. The attackers left a message on Canvas, a widely used educational platform, criticizing Instructure for ignoring previous warnings and failing to fix all vulnerabilities. This incident follows an earlier breach earlier in the week that impacted millions of students globally, including those at seven Dutch universities. ShinyHunters had initially set a ransom deadline of May 8, which has now been extended to May 12, urging institutions to engage cyber advisory firms to negotiate. In response to the ongoing threat, Instructure replaced the hackers' message with a scheduled maintenance notice and reported that Canvas is available to most users. Meanwhile, Amsterdam’s VU University decoupled its links to the system as a precaution. ShinyHunters, known for targeting telecom provider Odido earlier this year, continues to pose a significant threat to digital infrastructure, highlighting persistent security challenges in the education technology sector.
DutchNews.nlStudents Hit by Ransom Messages Amid Global Canvas Learning System Hack
Hundreds of thousands of students across Australia and globally faced disruptions to their studies after the cloud-based learning management system Canvas was hacked. The breach, attributed to the notorious cybercriminal group ShinyHunters, occurred on May 2 and led to widespread access issues for universities, TAFEs, and public schools. Some users encountered ransom messages demanding negotiations with Instructure, the US-based developer of Canvas. The attack significantly impacted educational institutions in Australian states including Queensland, Tasmania, New South Wales, and South Australia, preventing students from accessing coursework or submitting assessments during critical exam periods. While Instructure reported that services were largely restored by May 7, the full extent of the data compromise remains under investigation. Australia’s National Cyber Security Coordinator assured the public that no personal identification or financial information had been compromised so far. Authorities urged citizens to avoid engaging with threat actors or searching for leaked data on the dark web. The incident highlights the vulnerability of digital education infrastructure to sophisticated cyberattacks, causing significant frustration for students and staff alike as they navigate the aftermath of the security breach.
Just In