{"id":637868,"date":"2026-05-12T04:29:10","date_gmt":"2026-05-12T04:29:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/637868\/"},"modified":"2026-05-12T04:29:10","modified_gmt":"2026-05-12T04:29:10","slug":"instructure-pays-ransom-to-canvas-hackers","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/637868\/","title":{"rendered":"Instructure Pays Ransom to Canvas Hackers"},"content":{"rendered":"<p>Instructure has paid a ransom to a gang of cybercriminals that have twice hacked the company\u2019s learning management system, Canvas, over the past week and a half. <\/p>\n<p>According to <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.instructure.com\/incident_update\" target=\"_blank\">an update published by the education-technology company Monday night<\/a>, the deal means that the hackers have returned the compromised data of some 275\u00a0million users across more than 8,800 institutions. <\/p>\n<p>The company\u2014whose LMS is used to deliver courses by 41\u00a0percent of higher education institutions in North America\u2014said it \u201creceived digital confirmation of data destruction (shred logs)\u201d and assurance \u201cthat no Instructure customers will be extorted as a result of this incident, publicly or otherwise.\u201d It added that the agreement \u201ccovers all impacted Instructure customers\u201d and that individual customers have \u201cno need\u201d to engage with ShinyHunters, the extortionist group that has breached and temporarily disabled Canvas twice so far this month. <\/p>\n<p>\u201cWhile there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,\u201d the company wrote. \u201cWe continue to work with expert vendors to support our forensic analysis, further harden our environment, and conduct a comprehensive review of the data involved. We will continue to provide updates as that work progresses.\u201d <\/p>\n<p>Although the company did not disclose the deal\u2019s monetary value, it was reached one day before the May 12 ransom deadline imposed by ShinyHunters. The group is also linked to recent data breaches at the University of Pennsylvania and Princeton and Harvard Universities. <\/p>\n<p>ShinyHunters\u2019 infiltration of Canvas caused major service disruptions. The group warned Instructure to pay up if it didn\u2019t want all that user data\u2014which included names, email addresses and student ID numbers\u2014leaked. <\/p>\n<p>\u201cSeveral billions of private messages among students and teachers and students and other students involved, containing personal conversations and other [personal identifying information],\u201d ShinyHunters wrote in a ransom letter published <a href=\"https:\/\/www.ransomware.live\/id\/SW5zdHJ1Y3R1cmUgSG9sZGluZ3MsIEluYy4gKENhbnZhIExNUywgaW5zdHJ1Y3R1cmUuY29tKUBzaGlueWh1bnRlcnM\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">May 3 by the website Ransomware.live<\/a>, which tracks and monitors ransomware groups\u2019 victims and their activity. The hackers told Instructure \u201cto reach out by 6 May 2026 before we leak along with several annoying [digital] problems that\u2019ll come your way.\u201d It warned the company to \u201cmake the right decision\u201d to avoid becoming \u201cthe next headline.\u201d <\/p>\n<p>Although Instructure appeared to ignore those demands, it addressed the security issues, and Canvas was fully operational by last Tuesday, May 5. <\/p>\n<p>But that didn\u2019t stop the hackers from ginning up even bigger headlines later in the week. By Thursday, Canvas users\u2014many preparing for final exams and finishing end-of-semester assignments\u2014<a href=\"https:\/\/www.insidehighered.com\/news\/quick-takes\/2026\/05\/07\/hackers-target-canvas-again\" rel=\"nofollow noopener\" target=\"_blank\">couldn\u2019t access their accounts again<\/a>. Instead, all they could see was a message from the hackers. <\/p>\n<p>\u201cShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some \u2018security patches,\u2019\u201d read the message. \u201cIf any schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement.&#8221; They gave institutions and Instructure a deadline of May 12.<\/p>\n<p>According to ShinyHunters, Instructure ignored their original ransom demands. <\/p>\n<p>\u201cInstructure has not even bothered speaking to us to understand the situation or to even negotiate with us to prevent the release of this data. Our demand was not even as high as you might think it is,\u201d read one version of the cybergang\u2019s ransom letter <a href=\"https:\/\/www.ransomlook.io\/group\/shinyhunters\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">posted on RansomLook<\/a>, a website that tracks cybercrime activity. \u201cThe Company seemingly does not care about all the students affected and the institutions impacted by this data breach.\u201d <\/p>\n<p>In response, many <a href=\"https:\/\/www.insidehighered.com\/news\/tech-innovation\/teaching-learning\/2026\/05\/08\/universities-suspend-final-exams-after-canvas\" rel=\"nofollow noopener\" target=\"_blank\">universities postponed exams<\/a> and final project due dates as they waited for Canvas to resolve the issue. And over the weekend, Instructure CEO Steve Daly pledged to handle the hack differently the second time around. <\/p>\n<p>\u201cLast week, we made a call to get the facts right before speaking publicly. That instinct isn\u2019t wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates,\u201d he wrote in an update on the company\u2019s website. \u201cYou\u2019ve been clear about that, and it\u2019s fair feedback. We will change that moving forward.\u201d<\/p>\n<p>Apparently, Instructure also opened up communication with the hackers. By Monday afternoon, it <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.instructure.com\/incident_update#INSTstatus\" target=\"_blank\">reported on its website<\/a> that \u201call Canvas environments are available.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Instructure has paid a ransom to a gang of cybercriminals that have twice hacked the company\u2019s learning management&hellip;\n","protected":false},"author":2,"featured_media":637869,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[23,4553,526,2250,4552,134,3,21,19,22,20,25,24],"class_list":["post-637868","post","type-post","status-publish","format-standard","has-post-thumbnail","category-united-states","tag-america","tag-career","tag-education","tag-events","tag-higher","tag-jobs","tag-news","tag-united-states","tag-united-states-of-america","tag-unitedstates","tag-unitedstatesofamerica","tag-us","tag-usa"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/637868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=637868"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/637868\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/637869"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=637868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=637868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=637868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}