<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Instructure Struck a Deal With the Canvas Hackers. It Won't Say If It Paid.

Instructure reached an agreement with the group behind the Canvas breach after exams were disrupted at some 9,000 institutions. Neither side will say whether money changed hands.
Content Team

Instructure has reached an agreement with the hackers behind the Canvas breach — and neither side will say whether money changed hands. It detected unauthorized activity on April 29; a second intrusion on May 7 defaced login portals with an extortion note, knocking Canvas offline and disrupting exams at an estimated 9,000 institutions in the US, Canada, Australia and the UK.

ShinyHunters, which claimed the attack, said it stole 3.5 terabytes and threatened to publish it. Instructure says the data was returned, that it has shred logs confirming destruction, and that no customer will be extorted — the deal covers everyone affected, so no student or institution needs to engage the hackers.

By Instructure's account the stolen data is usernames, email addresses, course names, enrollment information and messages, with course content, submissions and credentials untouched. At Mississippi State, student Aubrey Palmer saw the note appear moments after finishing an exam essay, and the university postponed some exams so students could recover lost work.

Law enforcement agencies worldwide advise against paying — when the National Crime Agency hacked LockBit, police found data victims had already paid to have deleted. It's also not Instructure's first time: the ransom note read "Shiny Hunters has breached Instructure (again)", and the company disclosed a separate breach in September 2025.

Source: BBC

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo