‘Agreement’ with hackers resolves data breach on Canvas learning platform


This recording was made using enhanced software.

Full story

Instructure, the education technology company behind the online learning platform Canvas, has reached an “agreement” with the hackers who took its systems offline last week, disrupting final exams and causing alarms about the exposure of students’ personal data across the country.

In a statement, Instructure said the hacker group, which it referred to as “the unauthorized actor,” returned the data it stole during its ransomware attack, destroyed its own stolen copy and promised not to extort the company’s customers.

QR code for SAN app download

Download the SAN app today to stay up-to-date with Unbiased. Straight Facts™.

Point phone camera here

“While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” the company wrote. “We continue to work with expert vendors to support our forensic analysis, further harden our environment, and conduct a comprehensive review of the data involved. We will continue to provide updates as that work progresses.”

The statement comes after the decentralized cybercrime group known as ShinyHunters took credit on April 29 for the hack of Canvas, a platform used by more than 30 million people from more than 8,000 schools to manage grades, assignments and communications between educators and students.

The hackers claim to have stolen more than 3.6 terabytes of data that included personal information on 275 million people from 8,809 school systems during the attack. Instructure said following the breach that students’ names, email addresses, student ID numbers and communications from the platform had been stolen.

ShinyHunters later defaced Canvas login portals last Thursday with a warning that the stolen data would be leaked if Instructure did not pay a ransom.

The defacement and disruption came as students were preparing for finals. Although the service was restored later that day, numerous schools were forced to reschedule exams.

While Instructure did not explicitly say money was exchanged, the agreement suggests that a ransom was part of the deal. ShinyHunters’ leak site has also removed its listing about Instructure.

“The data is deleted, gone,” a representative for ShinyHunters said in a statement to TechCrunch. “The company and it’s [sic] customers will not further be targeted or contacted for payment by us.”

The FBI has long advised against paying ransoms to hackers.

“Paying a ransom doesn’t guarantee you or your organization will get any data back,” the FBI says. “It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity.”

Instructure said a webinar that will provide students and educators with further information about the hacks is expected to take place Wednesday.


Round out your reading

Tags: , ,

SAN provides
Unbiased. Straight Facts.

Don't just take our word for it.


Certified balanced reporting

According to media bias experts at AllSides

AllSides Certified Balanced May 2025

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Why this story matters

A ransomware attack on Canvas, the learning platform used by more than 30 million students and educators at over 8,000 schools, resulted in the confirmed theft of personal data including names, email addresses, student ID numbers and platform communications.

Personal data was confirmed stolen

Instructure confirmed that students' names, email addresses, student ID numbers and platform communications were taken during the attack, affecting people across more than 8,800 school systems.

Ransom outcome is unverified

Instructure said the hackers returned and destroyed the stolen data, but the company acknowledged there is "never complete certainty when dealing with cyber criminals" and did not confirm whether money changed hands.

Exams were disrupted

The attack forced numerous schools to reschedule final exams after Canvas login portals were defaced and service was taken offline during finals preparation.

SAN provides
Unbiased. Straight Facts.

Don't just take our word for it.


Certified balanced reporting

According to media bias experts at AllSides

AllSides Certified Balanced May 2025

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Timeline

Timeline