World

Instructure reaches agreement with Shiny Hunters following global Canvas data breach

Law enforcement agencies warn that paying cyber extortionists contradicts standard security protocols and offers no guarantee of data destruction.

Author
Adrian Cole
Political Correspondent
Published
Draft
Source: BBC World · original
Canvas hack: company pays criminals to delete students' stolen data
The learning management system provider states it has secured a deal to prevent the publication of 3.5 terabytes of stolen student data, though the financial terms remain unconfirmed.

Instructure, the developer of the Canvas learning management system, has reached an agreement with the Shiny Hunters extortion group following a cyber-attack that disrupted examinations at approximately 9,000 institutions across the US, Canada, Australia, and the UK. The hackers threatened to publish 3.5 terabytes of stolen student and university data, causing significant operational disruption to academic activities globally. While neither party has explicitly confirmed a financial transaction, Instructure stated that the hackers have deleted the data and promised not to extort further victims.

The company's decision to negotiate with cyber criminals stands in direct contrast to global law enforcement advice, which warns that such payments can fuel future attacks and offer no guarantee of data destruction. In previous cases, such as the LockBit ransomware group incident investigated by the National Crime Agency, criminals accepted ransom payments but lied about destroying data, keeping it for resale. Instructure acknowledged this risk in a statement, noting there is never complete certainty when dealing with cyber criminals, but emphasised that protecting student and staff data was its primary motivation.

The breach was discovered on 29 April and claimed by the Shiny Hunters group, which has previously targeted organisations including Jaguar Land Rover and Gucci. This English-speaking extortion group, believed to consist of young hackers, has claimed to have breached Instructure twice before the April 2026 attack. The group operates by forcing victims to send money in bitcoin after a negotiation through an encrypted chat service, a tactic that often leaves institutions in a difficult position regarding public disclosure.

Students at institutions such as Mississippi State University reported significant disruption, with some losing access to exams mid-session. Aubrey Palmer, a meteorology student at the university, described the confusion in the exam room when a ransom message appeared on screens, threatening to release stolen data unless a ransom was paid. In response to the incident, Mississippi State University later announced that some exams would be postponed to allow students to recover any lost work, highlighting the immediate impact of the service outage on academic integrity.

Instructure did not set out the specific terms of the agreement but stated that it meant the hackers would not publish the stolen information. The company maintained a high level of transparency regarding the attack, providing regular updates on its website, which may be partly due to the highly visible nature of the disruption affecting students directly. This approach contrasts with the typical silence surrounding ransom payments, as Instructure publicly acknowledged the stress and disruption caused to its user base.

Despite the agreement, the long-term implications for institutional security remain a concern for policy observers. The reliance on negotiations with extortion groups sets a precedent that could encourage further attacks if perceived as a viable strategy for criminal groups. As Instructure aims to provide peace of mind to its customers, the broader question of how to balance immediate data protection with long-term security strategy remains unresolved.

Continue reading

More from World

Read next: Damascus court sentences Assad and Najib to death for crimes against humanity
Read next: Trump Issues Mixed Signals on Iran Strategy Amidst Ongoing Regional Strikes
Read next: Turkey Parliament Approves Conditional Pardon for PKK Militants