Instructure Reaches Agreement with Hackers Following Data Breaches
Instructure, the company behind the widely used school information portal Canvas, announced on Tuesday that it has "reached an agreement" with cybercriminals who breached its systems twice. These attacks led to the theft of a substantial amount of student and staff data and disrupted thousands of schools reliant on Canvas software.
The Data Breach and Hackers Involved
ShinyHunters, a financially motivated cybercrime group, claimed responsibility for the April 29 data breach. The group stated it had stolen personal information of 275 million individuals, including students and staff. Canvas, utilized by nearly 9,000 schools for managing student data and coursework, was the primary target of the attack.
Last week, ShinyHunters executed a second breach, defacing Canvas login pages on school websites to pressure Instructure into paying a ransom.
The Agreement and Its Implications
Instructure disclosed on its incident page late Monday that, as part of the agreement, the hackers provided evidence that the stolen data was destroyed. The company also assured that Canvas customers would not face extortion from the hackers.
While the company admitted there is "never complete certainty" when dealing with cybercriminals, it emphasized that customers should not have to interact with the hackers directly. However, Instructure did not disclose the financial terms of the agreement or the exact amount paid to the hackers. Instructure spokesperson Brian Watkins declined to comment further beyond the company’s official statement.
ShinyHunters’ Response and Threats
ShinyHunters had previously threatened to publish the stolen data on their leak site if Instructure did not comply with their demands. As of Tuesday, the listing had been removed, suggesting that a ransom may have been paid. A representative from ShinyHunters told TechCrunch, "The data is deleted, gone. The company and its customers will not further be targeted or contacted for payment by us."
Government and Security Experts’ Warnings
The decision by Instructure to pay the ransom has raised questions. Governments, including the United States, have consistently urged victims of cybercrime not to pay ransoms, as doing so encourages further attacks. Security experts also caution against trusting cybercriminals who claim to delete stolen data, as some have been found retaining data to continue extortion attempts later.
Comparisons to Other Cyberattacks
The Instructure breach bears similarities to a cyberattack on PowerSchool in 2024. PowerSchool, another provider of school information software, suffered a massive data breach affecting 70 million students and staff. Despite paying the hackers to retrieve the stolen data, some of its customers were later extorted by another crime group that had retained data from the breach.
FBI Statement and Stolen Data Details
Last week, the FBI issued a statement acknowledging disruptions to schools and educational institutions across the United States. While it did not explicitly name Canvas, the agency advised victims not to send payments or respond to cybercriminal demands.
According to TechCrunch, the stolen data includes students’ names, personal email addresses, and private messages between teachers and students. This data contains sensitive and personal information.
Instructure’s Acknowledgment and Ongoing Investigation
On its website, Instructure confirmed that its systems had been breached twice within a year. The company described the two breaches as "distinct events" involving separate systems. It also stated that it is continuing to investigate the incidents and validate its findings.
Uncertainty surrounds who at Instructure is responsible for overseeing cybersecurity. When contacted, the company declined to comment on whether its CEO, Steve Daly, plans to resign following these breaches.
Call for Information
Are you a Canvas administrator or school affected by the breach? Have you received an extortion demand from the hackers? We want to hear from you. To securely contact this reporter, reach out via Signal at username zackwhittaker.1337.
Updated with response from Instructure.

