275 million people and nearly 9,000 schools were impacted when Canvas, an educational platform, was hacked.

Now, a deal has been reached between the business and the hackers. The hackers saying the data will be erased, but cyber security experts say if it really will be is uncertain.

It is an uncertainty even the company that owns Canvas has admitted.

“It’s a goodwill gesture to try to make the public feel better about what’s going on but it’s unenforceable legally. They don’t even have a tie to a human being who has an identity,” said Josh Braskie, the CEO of Simply IT.

The group ShinyHunters has claimed responsibility for the breach.

Braskie says this attack was no surprise, and it isn’t the first time the platform was targeted. He pointed to last year when the same group targeted University of Pennsylvania.

“The infrastructure they took ahold of was owned by Canvas, so it was an early indicator they had some serious problems in their infrastructure they were easily able to take advantage of,” he said.

He says it has led to repeated attacks. The company that owns Canvas says it has reached an agreement, but the terms have not been disclosed.

Faith Miller is one of millions of people who were impacted.

“The fact that so much of it is unknown, like who the hackers are and what they really wanted. It makes me nervous just about how easily a group can wipe out all of the country’s Canvas records,” said Miller.

Braskie believes many companies downplay the impact when breaches like this happen.

“I’m most nervous of people having full access to who I am, where I go to school, my student ID,” said Miller.

Braskie says these attacks are becoming more common, especially when so many people rely on the same platform.

“It cuts costs and makes things more available, but it also makes it much easier for hackers and things to have one source to attack and get lots of information,” said Braski.

Braski recommends programs that monitor your data, so you know if something has been compromised.

He says detecting it early is your best bet at managing a breach.