Instructure Pays Ransom After Cyberattack on Canvas
Instructure, the company behind the popular learning management system Canvas, has paid a ransom to cybercriminals. This decision came after the system faced two separate hacks within just over a week.
On Monday evening, Instructure announced that the ransom agreement has led to the return of compromised data for about 275 million users from over 8,800 educational institutions. This learning management system is widely used, accounting for 41% of higher education institutions in North America.
In its update, Instructure stated that they had received confirmation from the hackers that the stolen data had been destroyed. Additionally, they assured that none of Instructure’s customers would be pressured for money as a result of this breach. The company emphasized that the agreement protects all affected clients and that individual institutions should not interact with the group responsible, known as ShinyHunters.
“While we can’t be completely certain when dealing with cybercriminals, we believed taking this step was essential for our customers’ peace of mind,” said Instructure. They are continuing to work with cybersecurity experts to analyze the situation and enhance their security measures, promising to provide updates on their progress.
While the company did not disclose how much was paid, the agreement came just before a ransom deadline set by ShinyHunters. This group has also been linked to recent breaches at prestigious institutions such as the University of Pennsylvania and Ivy League schools like Princeton and Harvard.
The hackers’ earlier breach of Canvas led to significant service interruptions. They threatened to leak user data, including names, email addresses, and student ID numbers, unless the ransom was paid. In their ransom letter, the hackers claimed that there were billions of private messages between students and staff that contained sensitive information.
Despite the warning, Instructure initially chose not to comply. Even after applying security fixes, users found themselves unable to access their accounts again shortly after the initial breach, facing messages from the hackers urging them to negotiate.
ShinyHunters claimed that Instructure had ignored their attempts to communicate. They expressed frustration at the company’s lack of engagement, stating that their demands were reasonable and that the impacts of the breach on students and institutions were significant.
As a result of the ongoing disruptions, many universities postponed exams and assignment deadlines while awaiting a resolution from Instructure. Over the weekend, Instructure’s CEO Steve Daly recognized the need for better communication, admitting that the company’s focus on facts left users without updates when they needed them most.
By Monday afternoon, Instructure reported that all Canvas services were restored and indicated they had initiated contact with the hackers following their latest breach.
