<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Canvas Maker Strikes Deal With Hackers to Delete Stolen Student Data

Instructure strikes a deal with hackers to delete 3.65TB of student data stolen in the Canvas breach, which disrupted exams at 9,000 institutions.
Content Team

Instructure, the company behind Canvas learning software, has reached an agreement with the criminals behind a breach it detected on April 29. A second intrusion on May 7 knocked Canvas offline, disrupting around 9,000 institutions across the US, Canada, Australia and the UK. Neither Instructure nor the hackers will say whether money changed hands.

The Shiny Hunters group threatened to publish the data — 3.65 terabytes covering some 275 million users, by its own claim — unless a bitcoin ransom was paid. Usernames, email addresses, course names, enrollment information and messages were taken. Course content, submissions and credentials were not.

Students sitting exams were hit hardest. At Mississippi State University, a ransom note appeared on screens just as students finished a 2,900-word essay, leaving them unsure whether their work had saved; the university postponed some exams so they could recover it.

Instructure says the data was returned, that it received digital confirmation of destruction, and that no student or institution needs to negotiate separately. But dealing with extortionists goes against law enforcement advice and guarantees nothing — when the National Crime Agency hacked LockBit, police found data that victims had already paid to have deleted.

Shiny Hunters claims it had breached Canvas twice before. Instructure separately disclosed a breach in September 2025.

Source: BBC

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo