Instructure strikes deal with hackers who breached it twice

Instructure strikes deal with hackers who breached it twice

Instructure, the developer behind the widely-used educational platform Canvas, announced on Tuesday that they have forged a settlement with the hackers responsible for two significant breaches of their systems. These intrusions not only compromised a vast trove of student and staff information but also caused disruptions for thousands of educational institutions reliant on their software. The cybercrime group ShinyHunters claimed responsibility for the initial breach on April 29, asserting they had stolen data belonging to approximately 275 million individuals, including personal details of students and staff. This breach affected Canvas, which is utilized by nearly 9,000 schools to manage student information and coursework. Last week, the hackers targeted Instructure again, this time defacing the login pages of Canvas on various school websites as a tactic to compel the company into meeting their ransom demands. Instructure later confirmed on their incident page that, as part of the settlement, the hackers had provided assurance that the stolen data had been destroyed, and Canvas users would no longer face extortion attempts from them. Despite acknowledging that negotiating with cybercriminals carries inherent risks, Instructure emphasized that customers should not be engaged in discussions with the hackers. The financial specifics of the agreement were not disclosed, and Instructure did not comment on how much, if anything, was paid to the hackers. A spokesperson for Instructure, Brian Watkins, did not respond to inquiries regarding the terms of the settlement. According to a post by ShinyHunters on their leak site—now removed—there was a threat to publish the stolen data unless Instructure complied with their demands. However, the removal of the listing suggests a possible ransom payment may have occurred. In a statement to TechCrunch, a ShinyHunters representative claimed, "The data is deleted, gone. The company and its customers will not further be targeted or contacted for payment by us." Yet, the motivations behind Instructure's decision to settle remain unclear. Authorities, including the U.S. government, have consistently advised against paying ransoms to cybercriminals, as this can reinforce their illegal activities. Security experts have cautioned that victims cannot fully trust hackers' claims—some may retain stolen data even after promising its destruction to continue their extortion efforts. The incident at Instructure mirrors a past attack on PowerSchool, another provider of educational software, which suffered a breach affecting 70 million students and staff in 2024. PowerSchool opted to pay the ransom, but later, some customers were extorted by another group that possessed data that had not been deleted. The FBI acknowledged last week that they were aware of the disruptions affecting schools and educational entities across the United States, although they did not mention Canvas specifically. Their advisory reiterated that victims should refrain from making payments or responding to cybercriminal demands. The stolen data from Instructure reportedly includes students' names, email addresses, and messages exchanged between teachers and students, encompassing both private and personal information. Instructure has indicated that they are continuing to investigate the breaches, highlighting that the two incidents were separate events involving different systems. Questions remain regarding the oversight of cybersecurity at Instructure, particularly concerning whether CEO Steve Daly will step down following these breaches.

Sources : TechCrunch

Published On : May 12, 2026, 13:50

AI
Hugging Face CEO Calls for Action Following AI Security Breach

In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...

Business Insider | Jul 25, 2026, 20:30
Hugging Face CEO Calls for Action Following AI Security Breach
Startups
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations

Warner Bros. Discovery has initiated legal proceedings against Amazon, accusing the tech giant of unlawful interference ...

TechCrunch | Jul 25, 2026, 21:25
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations
Cybersecurity
Hugging Face's CEO Demands Transparency Following OpenAI Cyber Incident

In a recent turn of events, OpenAI acknowledged a serious breach involving one of its models that affected the AI platfo...

TechCrunch | Jul 26, 2026, 17:10
Hugging Face's CEO Demands Transparency Following OpenAI Cyber Incident
Startups
Revolutionizing Startup Living: Inside London's Unique Lift House

In East London, a group of six young entrepreneurs is redefining the concept of collaborative living for tech founders. ...

TechCrunch | Jul 26, 2026, 17:10
Revolutionizing Startup Living: Inside London's Unique Lift House
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
View All News