Instructure Struck a Deal With the Canvas Hackers. It Won't Say If It Paid.
Want more insights like this?
Instructure has reached an agreement with the hackers behind the Canvas breach — and neither side will say whether money changed hands. It detected unauthorized activity on April 29; a second intrusion on May 7 defaced login portals with an extortion note, knocking Canvas offline and disrupting exams at an estimated 9,000 institutions in the US, Canada, Australia and the UK.
ShinyHunters, which claimed the attack, said it stole 3.5 terabytes and threatened to publish it. Instructure says the data was returned, that it has shred logs confirming destruction, and that no customer will be extorted — the deal covers everyone affected, so no student or institution needs to engage the hackers.
By Instructure's account the stolen data is usernames, email addresses, course names, enrollment information and messages, with course content, submissions and credentials untouched. At Mississippi State, student Aubrey Palmer saw the note appear moments after finishing an exam essay, and the university postponed some exams so students could recover lost work.
Law enforcement agencies worldwide advise against paying — when the National Crime Agency hacked LockBit, police found data victims had already paid to have deleted. It's also not Instructure's first time: the ransom note read "Shiny Hunters has breached Instructure (again)", and the company disclosed a separate breach in September 2025.
Source: BBC